the person downloading such a component is responsible for "looking over it" before using it.
I'm sorry, but since when?
Since the license disclaimed responsibility.
You absolutely should not be tasking every single user of major projects with the responsibility of doing a code review on the whole thing before installing it.
And yet that is the current, prevailing situation. There is no warranty, so you are responsible, full stop. But this is true for closed commercial software as well. If they are exploited and consequently send you malware, it's your problem.
There needs to be a clear distinction between "fly-by-night thing that some rando uploaded" and "library that a million people depend on".
There hasn't been since we moved away from the cathedral model, but you couldn't trust the cathedrals either.
But now we have both (including the potential for "soundalikes") installed by the same means with no distinctions made by the install method.
The serious things get integrated into distributions and you can get them that way. If you choose to get them another way in order to get a newer version or a fork, you are taking an additional risk. Again, this is how the bazaar model has always worked. This is not new.