Absolutely.
The Arch User Repository is a way for anyone to easily distribite software.
Hence it has never been secure, and rather than claim it is, you mostly see people and documentation warn you about this, and to be careful if using it.
Any schmuck can make whatever they want available via the AUR. That's how even the tiniest niche project can often be installed via the AUR. But you trade in some security for that convenience.

To be clear, when projects distribute their software via the aur, someone else can't just issue an update using their package name.
This person appended "fix" and "patched" to appear in searches next to legitimate packages, and seem worth installing instead.