Earlier quoted context omitted.
'allow third party code' means code which is not signed. Once you tick that any unsigned code can run, not only the app you downloaded. Makes exploitation significantly easier. It would be better if Android forced you to explicitly select which code could run, but too hard for most users.
Then you "untick" it until the next time you need to install something. This is what I do on lineageOS. I don't regularly install new apps. Side rant: This marketer-driven "install an app for everything" is a threat to the open internet and privacy. Usually the only reason is to extract more personal info. Already, young people barely use a web browser. That appears to be the future. Now get off my lawn or I'll start…
Android could undoubtedly be stronger in this regard, and in permission control, firewall, ad blocking etc, but it's not going to happen.
Apps wouldn't be so bad if they were actually sandboxed properly, but yeah, they suck.
I was interested in Copperhead OS as an alternative, but it seems to have fallen into a greed induced mess.