What do you expect them to do, download .tar.gz, extra, read every line of code and them make; make install?
Or just make; make install? How is that any different?
You can usually get PGP signed hashes for tarballs distributed by serious entities. If someone is distributing software and provides no way to check that it is genuine, you shouldn't run it...