@johannes It might not be relevant for CVE/MITRE per se. But the rather loose "organisation" of the PHP group makes it rather hard to actually get hold of someone responsible. And letting Rasmus delegate everything does not really scale
Having an entity that people actually can get hold of and that has a more formal structure makes it easier to get hold of. Not in a legal sense but in a plain "Whom can I talk to" sense.
But that'S just my 0.02 €