Anyone was allowed to decompile plugins on BukkitDev to confirm that they were safe - there was always the added security of knowing that it had been approved by a moderator. Allowing the community to review plugins that have not been approved yet is essentially permitting the download of possibly malicious files. With the generally young age of the Minecraft community in mind, I can’t really see this as being as secure as it can be.
A system of “raising flags” may also add to the ‘burning out’ of the reviewers on the Sponge team. Instead of doing a ‘clean review’ it may come to a point where the reviewers will only rely on the flags from the community.
The problem with a diff-based review process is that you are assuming the previous moderator/author was infallible with their review. Mistakes happen, and backdoors may potentially pass more than one review in this sort of system. This may also accelerate the process of reviewers ‘burning out’ as I mentioned above.