That was just one comment, and they did not elaborate. They also said
they "kept the overall design straightforward and clean" and "we have
worked hard to produce well documented, readable and elegant code. With
that we try to make the barrier for security audit and code review as low
as possible." Perhaps DNSSEC is inherently messy, but they did their best?
Of course, it would be best not to take their word, and look at their code
instead. (I wasn't able to access their code repository for whatever
reason.)