So it basically comes down to the initial downloading of an app right? If that’s signed correctly with the developer’s keys, then it can’t be replaced with a malicious version later no matter the “app store” you use right? (Excluding f-droid b/c of wonky signing policies)
So for most users Google Play is the right answer, but there are tradeoffs to consider.
Obtainium seems to be a powerful option here if you’re comfortable finding the source location yourself (only risk remaining is that the dev keys themselves are compromised which also would risk the other app stores?). This seems most like a desktop, download software from source, but with a nice consolidated updater.
Idk for me it feels like getting most software through Obtainium would be ideal and fallback to Google Play for apps that aren’t listed anywhere else. I’d only do this with a fully anonymous Google account tho (is this even possible anymore?)