AUR comes with a warning that its up to you to check what you install from there.
Next up, "millions of malicious packages still not taken down on internet"
I've installed stuff from the aur before but most of the times I prefer to skip the middleman and just navigate to the project website. A premade pkgbuild is not convenient enough to take the risk of typoquatting or the tactical npm or pip dependency.
The pacman wrappers you mention are crazy, though.
Perfect demonstration!
(It's a bit vulnerable to it on first install, but so is 'just navigate to the project website [and click download]'.)
embedding-shape•53m ago
`rua` and other similar CLIs make it really easy to review the packages before installing them from AUR too, and if you are doing banking on the same computer, you really have no excuse not to review the software you depend on. Keeping the amount of packages low, only use what you need, also makes this a whole lot simpler when it's time to upgrade.