Why is Google allowed to remove purchases from our Play Store accounts without telling us?
(www.androidpolice.com)
That's why Android apps must be signed. Tools can show an app's certificate hash and if two app versions' hashes match, they're equally trustworthy / from the same source. I think APKMirror does this and it's actually quite trusthworthy.