That is, you admit that most aur users delegate that function to other eyes instead of auditing the external code they are installing. A user repository outside of the official distribution repository is not a secure means of installing packages on the system, which may have root access to the system and the source code may change with each package update. Do you think that every time there is an update to a package that is not widely used, others will audit the source code for you? For that reason I stopped using Aur and by extension Arch, as their software catalog outside of aur is small.
I used to recommend Ubuntu. Now that immutable distributions exist, I prefer to recommend openSUSE Aeon or Fedora Silverblue to new users. However, check this website before installing Linux.
https://endof10.org/