Earlier quoted context omitted.
That sounds shady. Thank you for the warning. How does one determine that? Also not found on F-droid. Hard pass.
F-Droid has the same potential tampering issue: apps there are signed by the F-Droid key, not the developer’s key. An F-Droid compromise could backdoor every app.
For anyone: Why don't they cross-sign with their key+dev key?