Plugins go through the validation and approval process before they are visible on the plugins database. Regardless of how you install a plugin though - whether that’s through the Moodle interface, FTP upload, or GIT - you should always heed the considerations for production sites.
When you install a plugin via the Moodle interface, you will see a validation checklist.
If it’s a potential problem for you though, you can disable the installation and upgrade of plugins via the Moodle interface by adding this to your config.php file:
$CFG->disableupdateautodeploy = true;