I suppose you should "trust" what's up on the Apple Store but I do get some things from other places:
When you’re downloading a PKG file from a reliable source, you really have nothing to worry about, but you might still need to grab them from other sources now and again. With Suspicious Package, you can open up any PKG file in Quick Look (select the file and press the Space bar) to peek inside and get a better understanding of what you’re installing. Most of us won’t need this too often, but it’s nice to keep around for those moments when you have to install something a little shady. Of course, there’s a little irony that Suspicious Package is a PKG file itself, but it looks good to us.
http://lifehacker.com/suspicious-package-i...-you-1724160487