Like I said, it was just an example. I don't have the time or knowledge to review an entire custom ISO and after that another ISO from the Gapps provider that I choose. I'm sure there are some tricks to cut down the review process time but anyway.
It's a trade-off. I'm installing custom software to improve security, but at the same time, can I trust that this solution won't be a source of malware?
I hope this didn't came out as accusatory, I was just trying to show another aspect of using custom ROMs.