Please read the full thread before you do... The original scripts had multiple SQL injection vulnerability's, and there was even some talk about backdoors and phone-home parts in the script (i never read the code, so i cannot verify this)
backdoors depending on how many files they got could be hard to find if you don't know what your looking for.
To find backdoors, you're right: somebody has to digg deep and really understand the inner workings of the script in order to properly fix everything.
Use it wisely, keep in mind: SQL injection, backdoor, phone-home . I just cloned it, didn't fix a single error!