My distro either does not have the things I use from flatpak or have them with some deficiency (like older version or compiled features).
I can still get rpms for some, like Teams, but that also comes with bundled libraries and the Teams flatpak does have very tight restrictions so if I am concerned for the rest of my system flatpak is more secure.
For some other things on that list there are no rpms however.
So yes, you are more exposed to the maintainers behaving well, but you are also more insulated than just running things without any sandboxing.