What you're actually saying is that network effects are strong. Those network effects are the only reason Wordpress is still so commonly-used.
But, that has very little to do with the work described in the OP. Maybe EmDash will fail to gain sufficient traction to have their own network effects, but in the meantime, doing moderation on plugins in their marketplace is still important work. Automated moderation to prevent abuse and malware is useful, and is orthogonal to the social proof you're talking about.
Thats not what I'm saying at all. I really like a lot about EmDash and would love for a different default CMS to overtake WordPress.
What I am saying is that there are different levels of types trust when it comes to incorporating outside code into your project (in the form of packages/plugins/extensions):
1. Being able to quickly understand what the code does and what effect it will have (screenshots are pretty big here for CMS plugins)
2. Being able to examine the code before installation
3. Seeing feedback from others on the quality of the code and how well it meets the objectives
4 Limiting what the code can do once you install it
Right now the EmDash plugin catalog really only does #4. I don't see any screenshots of the UI of these plugins, there is no link to the repo, there is no indication if a plugin is used by 100 people or no one, and there is no feedback from anyone who has used it.
The bottom line is that there are several layers of trust that outside code has to pass before you even install it and consider what permissions to grant it. Ignoring that makes it very difficult for someone to start trying out different plugins. And it also makes me hesitant to develop a plugin, because it seems like it has very little chance of standing out from all the rest, even if it becomes popular.