I beleive the most harmful threat would be backdoors. Backdoors are created in order to speed up development and hotfixes, which is a benefit to developers and will be reluctant to remove so they can have an easier job in the future, also to meet deadlines a faster solution is needed. Usually, developers are not the one in charge of security concerns, so it is treated as an afterthought. A way to prevent such threats would be to properly tag such shortcuts and remove before pushing the code into production.