This is sad but not super surprising. Historically, if you had money and wanted a reasonable UI and cleaner integrations, you bought PGP (now from Symantec). GPG was always for people unwilling to pay.
For the record I donated. I'm just pointing out that writing something that's bundled and distributed as part of something else means nobody thinks about your project, or in many cases even realizes they're using it.
Parts of its source code are viewable and reviewable, associated with key cryptographic functions. Much of what PGP builds is structure around that, and most of that isn't open in any sense of the word.
Phil Zimmerman (who's long since left the building) does understand the value of source review, and the team who supported PGP continued that legacy. But it was quite limited in scope.
That said, PGP also did work with other implementations, including GPG, to resolve compatibility issues -- I'm aware of a few of those personally myself.
His point stands though. GPG never caught on as a commercial product or something that people would pay for. Both are Open Source, that's not the issue.
For the record I donated. I'm just pointing out that writing something that's bundled and distributed as part of something else means nobody thinks about your project, or in many cases even realizes they're using it.