Very nice idea. As an ISV with a freemium open-source extension, I would happily pay for an official security review that I could present to our users. Our extension is secure by design but having a 3rd-party expert (e. g. Google or Firefox reviewer) confirm this and get a "Reviewed" badge would be great. The drawback is that this could slow down extension updates, as you do not want to loose this badge with the next update. But that is manageable.