To be clear, I am not attacking or accusing you of anything - I am just having a conversation about trust in an environment where the vast majority of big players have demonstrated that they shouldn't be trusted.
It all comes down to trust, I think, not source code. How many of the "open source only" proponents have read and analyzed the source code? How many of them have verified that the shipping product is exactly the same as the source? Almost nobody, I suspect.
A relatively small number of people actually work on open source, even with the biggest, most popular projects. The number of eyeballs on the source is a lot smaller than you might expect.
> the vast majority of big players have demonstrated that they shouldn't be trusted
While I appreciate your point about the business model, your statement that your extensions are not malware is not verifiable.