Although not so much now, I've used APKMirror for many years without any problems at all.
The site is an offshoot of Android Police (one of my first three go-to sites) who specialise in apps. I have copied over their security policy at the end, but please also read their FAQ's on the site.
There is a risk on ANY download site (which also includes the Play Store), and don't forget that Play Protect will still be scanning the APK. Not advising you what to do, but just expressing my opinion. Anyway, for anyone's interest here is their policy:
Security: What measures do you take to make sure all uploaded APKs are real and created by the respective developers?
All APKMirror.com uploads are verified prior to publishing.
We make sure that the cryptographic signatures for new versions of all previously published apps match the original ones, which means we know if uploaded APKs were signed by the real devs or someone pretending to be them.
Note: APKMirror.com has been protected from the Janus vulnerability in Android from day one.
a. For new apps that have never been uploaded to APKMirror.com, we try to match the signatures to other existing apps by the same developer. If there’s a match, it means that the same key was used to sign a previously known legitimate app, therefore validating the new upload.
b. If we see no matches, we try to obtain and compare to a version of the same app from the Play Store or another verified location. If it’s a beta, we will try to get into it. If we can’t, we will attempt to contact the developer.
c. If we’re unable to verify the legitimacy of a new APK, we will simply not publish it.
01-17-2019 04:18 PM