To be honest, we have ZERO assurances that what we get from Cydia is not a "cove of malicious" code. That is why Apple locks down the device and why we jailbreak - they want to keep potentially bad stuff away from our devices while we want to open them up and take risks on our own with OUR property. Thus, the neverending battle...
I do know that saurik, Optimo (manager of the Big Boss repo) and the other "default" Cydia repositories check the tweaks to ensure they aren't malicious. I don't know enough about coding to know whether they catch everything (or are looking for everything). I do know that they are well-respected in the jailbreak "community" and are people I've relied upon for true information since I've been jailbreaking (since around 2011). So, I trust they know what they are doing and if a tweak is on the default repositories, I will trust it as being a safe tweak. Not necessarily safe in that it will run well on my device or that it will work as promised - but safe in that I believe it will not deliberately and maliciously, by design, cause harm to any of my devices.
Caveat: I have never read anywhere that the tweak you have (Cleaner) causes any harm to anyone. I have never read anything bad about it. I did read a thread from about a year ago where a commenter said the upgrade re-directed them to the AppStore. I am not saying I feel the tweak you have is malicious or bad. Nor am I saying I do not trust the developer of the tweak. I do not think the developer means harm - I just think he has a coding problem (because of the AppStore redirect).
Since we can never know what is in the code, what I do is rely on the community to aid in policing. If ever someone released a tweak that was harmful or did harmful things, the community of jailbreakers would catch it. They're just suspicious that way in that people always check these things out. And, history has shown the community WILL catch people if they try something. There was a tweak that attempted to redirect ad revenue. The community caught the developer out, notifed the repo (in this case, it was Big Boss) and the tweak was pulled from the repo. Oh, and that developer's name is mud in the jailbreak community. So, yes, the jailbreakers look out for each other.
As an aside, please keep in mind that what we install on our devices is no different than programs you choose to decide to put on your computer, be it a Mac or a Windows PC. There are no guarantees that what you download is "safe" to use and won't mess up your system.
Which brings me to my main point - education and research. I never put a tweak onto any of my devices until I have researched the heck out of it. If it's a longstanding tweak such as Activator (by petrich), I don't have to research as much since that tweak has been around forever and the "community" has had plenty of opportunity to observe it "in action" on iDevices. So, I'll usually get the more well-known tweaks right away. Note that this will include new tweaks by developers of such well-known tweaks. They are "trusted," so I don't feel as uncomfortable.
If it's a brand new tweak, I still do the research, part of which is waiting to see how the tweak works on other's devices. I keep up with a bunch of jail break sites (and some sub-reddits) for news and releases, so I get an idea of how the tweak works and what it does. After observing (and lots of Googling), I make the decision.
Oh, and all of this ONLY applies to non-piracy repositories. I have never loaded a piracy repo - mainly because I don't trust them to not have bad and malicious code in the tweaks they offer. Well, and the obvious reason that I believe piracy is bad (cause it's stealing). I do have other, non-default repos loaded, but only because (1) the tweak is not on the default Cydia repos (for whatever reason) and (2) I have done my due diligence to ensure the repo (and the repo developer) are "safe."
So, yes, as you can see, I have thought about it. But, my decision is to trust in the community. When I chose to jailbreak, I know I accepted more "risk' to my device. Again, for me, it's all about research and due diligence.
I hope this answered some of your questions.
Marilyn