Typically companies will just link to the app store to download and not have the install file on their site. However, the link on the developing companies page should send you to the valid version of the app.

However, what if the company itself released the shady app? It is always best to research what you are installing on your device first and check the app permissions.

The same applies to other app stores, though Google can seem to experience more issues with theirs due to it being more open to publishers.