Well, Void is not that large, but they quickly patch security issues, especially due to being a rolling release. OpenBSD, not Linux or rolling release though, is not a huge OS either, but they are patching - if there is a security issue - quickly. Similarly Slackware - if we want to come back again to a Linux distro.
In other words: No, the size of its dev team does not necessarily mean that they are behind with patching security issues. it depends on the commitment and skills of devs, and the community.