As a maintainer, the biggest major issue is that I don't want their money.
Even before you get to the broader ecosystem, I wouldn't want daily standups, weekly 1:1s, on-call rotations, weekly business reviews, monthly business reviews, quarterly reports, "emergency" all-hands meetings, mandatory compliance training, constant IT churn, zero-based budgeting, fighting for headcount, constant interviewing, fighting for management buy-in (and against active attempts at management sabotage), managing up, managing down, peer reviews, performance reviews, promotion boards...
I also don't want to spend six months negotiating a contract, sign an NDA, disclose tax records to prove I have other clients, maintain liability insurance, and etc., for one week's worth of work, during which I must track every fraction of an hour and itemize everything I do, followed by two months of dealing with some archaic billing system and another three months wondering if accounts payable will ever actually send the money.
I just want to apply my decades of domain experience in a community of deserved trust and feel like someone actually gives a damn.
And as soon as it's merged, an issue would be opened: it is critical that you immediately push a release and tag it as an emergency security fix so that everyone upgrades ASAP.
That's not how it works. Rather, very nice people will insert themselves into already established projects and start siphoning the money to themselves, their friends, their businesses and so forth. You have a problem with that? Then you are toxic and probably several different "-ist", and should be removed from contributing.