That’s the case with so much of this sort of thing. You also see it in cases like open sourcing proprietary software. You need to pay someone competent to do a thorough audit or you end up with headlines about so and so releasing PII or otherwise confidential information.
I think it could be a great charity btw. Get donations from public, talk companies into releasing their old software, hire auditors for them and maybe developers to get the result running without all the proprietary third-party components.
Personally I’d rather see maintainers getting better compensated for creating new and widely useful software in cases where they don’t have a corporate sponsor. Most abandoned proprietary software is just old.
I’d love that too, of course. But some old things are great for their historical value – personally, I would be thrilled to see Winamp released properly, for example.