I removed that frei0r plugin for the next version since it is not used and can scare people.
Our frei0r plugins (as well as MLT and Shotcut) are built every night from source in a new virtual machine that gets everything installed from either msys2 (also automated in the same manner) or built from source code. This file is then uploaded directly to Amazon S3. Then, for releases, the files are downloaded on a Linux machine, copied to a Windows machine where they are scanned using Microsoft Defender, and uploaded to GitHub from the Linux machine. Not that Linux is perfectly guarded against viruses, it is significantly lower risk. After uploading to GitHub, FossHub directly downloads from GitHub and does their virus scan.