Why is code locked down, extremely ?

As a Joomla 3 user (not developer) I harnessed the power of opensource and all was easy to change but, that is not what I am finding with Elgg. Just to make simple adjustments to width or color changes, I see people being informed they  "should create a custom plugin for that". I assume this is a way to get more plugins developed by knowledgeable coders as well limit support to non coders like myself. I also saw one developer wants $1,000 for this complete Elgg them solution.

I am stuck on Elgg version 5.2.1 since Hostgator does not provide MySql 8 that is needed for Elgg 6.2

With that said, I am very impressed by how easy Elgg 5 is in installing and configuring available plugins. Creating custom pages and groups, etc with the enhancement of CKeditor html code inclusion. As someone whom is very old with failing health, I don't have it in me to become a full blown php / javascript developer just to make minor changes to Elgg. If you have read this far, I Thank You as there is a point to my rambling.  

I have 2 questions: 

1. Are Elgg Version 5 plug-ins contained on a website somewhere off of github for download once they are de-predicated by developers ?

2. Why no iframe in CKeditor by default ? (Really ?) I can manually upgrade myself the CKeditor toolbar options to include <iframe src="..." /><iframe> but, I see that Elgg considers "iframes" as a security risk. There are many sites who will not load pages to an embeded or iframe on a remote website like Facebook and Rumble (them providing security for their systems) but, Millions of websites allow embedded inclusion using "iframes". Is it because of the code that is parsed by Composer to a remote server for each Elgg build ?