i'm probably wrong because i dont know exactly what im talking about, but a system like this could probably be used to easily and automatically slip backdoors into every server unless it had strict moderation.
This would be the case.
I would only trust Badspot, and by extension Rotondo and Kompressor, to update the game safely.
There's only two reasons for that.
1, Badspot has never put anything malicious in an update in the roughly-a-decade he's been updating, and...
2, Badspot would be sabotaging his income to distribute viruses/backdoors, so wouldn't do it. (This was the only reason to trust him/Blockland when I bought the game).
Anyone else would not provide those reasons to trust them, and they're the most important reasons when buying/updating anything.