That's kinda what Zapstore is trying to solve with web of trust.
Discussion
Aye. Technical a bunch of sites/apps already have WoT, even for my nostr:npub17jl3ldd6305rnacvwvchx03snauqsg4nz8mruq0emj9thdpglr2sst825x, it's basically comments but with a differentiating tag in the published event to indicate that it's a general review or a security review and so on.
Idea here is, along with web of trust and general user posts, the site/app would also categorize posts with such tags and collects them to average out a security score, with different sites/apps selecting npubs that they consider as trustworthy. (Users can switch to see who they trust and disregard the site's trust, of course).
With that, companies would start doing a bit of probono work on a few games or apps, so they'd build up a reputation and market themselves as well, resulting in developers paying for their service to have them review their stuff and publish it.
If zapstore will get to it before I do, nice, if not then whenever I do (not anytime soon) I'd send it over for review and get his input since he'd probably want such a system too.