Well you have to distingush between trojan and security flaws.
All code is double checked for trojans and indeed the face we realease the code as source and thousands of people may look at it sould be enough guarantee tha no spyware is in, you will know from sure form public forum and lists.
On security flaws: I personally run hunderd of sites with no problem.
When a security flaw is discovered a patch is released very soon and made avaialbe.
Be sure to run always the latest version if you want to be protected.
The history.txt file reveal if security problem are fixed (we do not disclose too much details for security reasons)
Manu