I think he's saying (sorry if I'm picking you up wrongly, Petr) that if your code hasn't been through HQ's checks and balances then you're not trusted. That means nearly all optional plugins. I don't find this surprising... not all developers are motivated to take that sort of time. It's even worse if those plugins then include other libraries from unverified sources.
I am not a security expert.
I am not a security expert.