Security is a spectrum not an on off switch.
The question is whats the risk profile/benefit.
The ppa like many other is hosted on launchpad.net owned by canonical.
If Canonical is compromised you are probably boned any way you slice it. If the developer is compromised you are probably boned. This leaves the fact that the devs account on launchpad could be taken over and used as an attack vector which quite frankly seems like the lessor risk.
You have already undertaken the greater risk that the dev or whomever inherits/acquires access to their account is or becomes malicious or incompetent especially given that is not now or will it be audited unless it becomes an official part of the Ubuntu repos.
This means that if the bookworm software in version 17 starts to come with a crypto miner you will only become aware of this if it hits hacker news and you happen to read the story whereas were it part of the Ubuntu repos Canonical would be apt to publish this warning via official channels.
If you have 835 packages you have 835 potential sources of issues but if they are all vetted by canonical then you have 1 source of fixes/warnings. If you add 17 ppas you now have 18 channels and 17 may be less diligent than canonical is. This situation isn't much improved if you have 17 github repos that you periodically pull from unless you have both the skill and the time to audit the result in depth.