With package packed as rpm, you can look what it contains.

People do not `review' rpm packages, let alone review the scripts they
execute.  You are just as vulnerable.

True.  But you at least have the option.  Not so with binaries.

