Why no to packagekit? How insecure is it?

KDE Plasma has its own graphical software manager called Discover which can be used on Fedora, Ubuntu… to install, remove and upgrade the whole system with its apps. It uses packagekit as an abstraction layer to interact with different package managers like apt, dnf, yum, pacman… It’s also used by GNOME software on different distributions.

The real problem is coming from Arch devs who refuse to fix packagekit backend for their system. They really hate the idea of giving users any way to manage update/install/remove their systems using graphical interfaces, while it’s used for years by other distributions.