I'm frustrated because adding this page made us a target whereas we weren't one before. I agree we would have eventually become a target regardless, but hopefully this would be because we have a well-known product.
I encourage you to harden your heart. A reward/recognition page is a small price to pay for avoiding an embarassing compromise.
If you really want to quash the general issue, pay some 3rd party to do some real csrf/xss/sql injection pen testing against your sight at the cadence that is appropriate for your dev cycle. If you move slow and deliberately, annual or semi-annual assessments can help you intercept the disclosures. If you're more agile, you'll need to consider something more embedded in your life cycle.
A few other thoughts:
1) Develop your copy pasta for your accept, reject and duplicate submissions. Write in a firm but appreciative tone.
2) For email from anklebiting submitters, refer to your policy. Your policy should say whatever you need it to say. If people want to dispute things, always express appreciation for their effort, but point to "the policy" as the reason things can't be the way they want them.
3) prepare for crazy people. Vuln reward/recognition programs really seem to bring out the old school bbs conspiracy theorists.