They have
one full-time OpenSSL developer.
Given that up to "two thirds" of web servers on the internet use OpenSSL, this is, in my personal opinion, if not despicable, then at least decidedly hypocritical, given the number of people openly deriding openssl code (which is not great at all; but maybe people and companies using openssl should start giving cold hard cash to the openssl foundation, right now.)
http://online.wsj.com/news/articles/SB10001424052702303873604579491350251315132?mg=reno64-wsj; also see http://www.forbes.com/sites/kashmirhill/2014/04/10/whats-really-scary-about-heartbleed/
Donations page: https://www.openssl.org/support/donations.html
Tax deductibility isn't a big reason why I donate to things, but I still thought it was a bit weird that the "OpenSSL Software Foundation" was incorporated as a for-profit company.