Debian is also maintained by a bazillion people who contribute individual packages. These people who contribute the packages could have their own agendas, and deliberately create backdoors. Does that happen? I don't know, but the possibility is there. I'd submit that based on their development model, Debian isn't the most secure