All of this may be true, but each one of these things is one tiny programming mistake away from complete and irrevocable collapse. The track record for this category is poor.
For new projects, yes. New projects should be treated with caution, especially if from unknown entities or entities with a poor security track record. But Uniswap V2 is almost 3 years old at this point, and Uniswap V3 is almost 2 years old. The contracts were audited before they were deployed. They're open source. They've got billions of dollars in the contracts. If they could be hacked, they would have been hacked by now.
Almost 3 years old! There's a great joke in the movie _LA Story_ about this kind of thing.
Heartbleed, Shellshock, Log4Shell, Spectre... there are plenty of examples of serious flaws found in software far more mature than these smart contracts. Audits and testing only confirm the presence of bugs, not their absence.