

Haven’t used Kubuntu so can’t help you with that.
Regarding installing application from 3rd parties, there is no guaranteed way to know that what you’re installing is clean.
That being said, I would argue basic evaluations (how long has the project been around, does it get mentioned a lot in articles and forums, are there a lot of star and activity on the guthub page?) should be good enough for regular operational security.
One other general tip, try using Gemini (the LLM by Google) for real-time support and explanations around Kubuntu. I find it helpful for guidance on complex applications (ones that are far more niche than Kubuntu).
Sounds like a mostly minor bugfix release, albeit the following sounds serious:
Though its clearly not universal.