You get what you paid for. Please don't blame, bully or in any way personally attack the authors - they are not obliged to make changes to their (insecure) code that has been provided as-is.
Trail of Bits is charging hefty sums for audits. I suppose they could provide some patches.
This argument doesn't hold because paid cryptography libraries aren't any better and equally provide their code as-is.