I don't know everything, but I do know they've let their HTTPS cert expire a few times [1], and they apparently delay package updates from upstream for like 1wk for "stability" reasons... which doesn't really add any stability, and just slows down releases.
[1]: https://www.reddit.com/r/linux/comments/wr2dps/manjaro_let_t...