Provide firefox as flatpak

Well the way I see it there are currently two options (please correct me if I am wrong) when wanting to use Firefox with all codecs:

  1. Install Firefox from flathub with the required codecs
  2. Keep native rpm-ostree firefox but install codecs from rpm-fusion

Reading how the sandboxing of the flathub firefox might actually create security issues, I wonder if adding and using rpm-fusion wouldn’t create security concerns as well (not official, community driven, closed source code,…)?