I understand the security concern which is always an important consideration. I also think by taking steps to properly harden the server, follow the recommended WHMCS security steps (moving the cron folder, config file permissions, etc) and even using a WAF and/or service like cWatch, many of these issues become non issues or minimal. Sure they cost a little bit extra but well worth it.
Part of my last response is a push for @Tyson and @jono who need more help on the development side. It's sort of a case of 'spend money to make money' and advance the software faster. Quality control and bugs can still be monitored and caught through testing and different software applications available even when working with bigger teams. Blesta itself didn't start in 2013 either. I didn't use v2.x so I'm not sure when the company actually formed. Trust me, I didn't want to go through the process of manually moving (WHMCS importer doesn't work) but in our case, it had to be done.