The seven questions that filter out most junk
Start with the publisher: does the download come from the vendor's real domain, or from a download portal that repacks installers with its own additions? Then ask how the developer earns money — an open-source project with sponsors has an explainable model, while a "free" closed-source cleaner with no visible income usually has a hidden one. Check whether the binary is signed: right-click the file > Properties > Digital Signatures, and treat an unsigned installer from an unknown vendor as guilty until proven otherwise.
Continue with reputation and upkeep: what do independent sources say — not the testimonials on the vendor's own site, but a VirusTotal scan of the exact file and what real users report after months of use? Does the tool have an uninstaller that actually removes itself, or does it leave a service, a scheduled task and a folder in AppData? And is it alive at all — a changelog with a 2026 date means someone fixes bugs; the last entry from 2019 means nobody ever will.
Six tells that expose an installer trap
The installer itself answers questions too, if you know where to look. These six tells are the standard fingerprint of bundleware — one is a yellow flag, three together are a closed door:
- Express or Recommended install is the only big button, and Custom/Advanced hides behind a small grey link — the bundle lives on the default path
- Pre-checked boxes for a browser, a toolbar, a "partner antivirus" or a system cleaner you never asked for
- The download is a tiny stub installer that fetches the real payload later — whatever it fetches, you approved it blind
- A tool that should be per-user (a PDF reader, a media player) demands administrator rights at launch
- The privacy policy reads like marketing and its data section quietly mentions "trusted third-party partners"
- The vendor's site has a Download button every three paragraphs and no changelog anywhere
The last question — and the shortcut that skips most of this
Question thirteen is the one people skip: do you actually need it? Windows already compresses archives, mounts ISOs, edits photos and kills startup entries, and half the utilities people install duplicate functions the OS ships with. Before downloading, spend one minute checking whether the task is already covered — it usually is.
When the answer is yes, install the smart way: winget verifies the package hash against a maintained manifest before running anything, which closes the repack and tamper holes in one move. Combine that with a portable version when one is offered — no installer, no autoruns, no leftovers — and the thirteen-question habit shrinks to about ninety seconds of actual checking. And a habit you can run in ninety seconds is a habit you will actually keep.
Questions and Answers
How can I tell if free software is safe to install?
Check four things before running anything: the vendor's real domain, a digital signature on the file, a recent changelog and a clean VirusTotal scan. Those four filters catch nearly all bundleware.
Is installing through winget safer than downloading manually?
Generally yes: winget pulls the installer from the vendor's own address but checks its hash against a curated manifest first, which neutralizes repacked or tampered downloads.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]