Verify the file signature (often listed as 3891 or 58e1 for this version) to ensure it hasn't been tampered with.
Enable "Install from Unknown Sources" in your device settings only for the duration of the installation.
Often considered the safest option as they verify the integrity of files before hosting them.