Everything rests on the credibility of the developer and the hope that someone reviewed code.
That's correct. But in the same way you added Electrum along with core, I will add bitaddress because it has a long history of being pretty well done and if was clearly reviewed (probably by many more than I'd think).
Of course, the fact I trust one software doesn't mean you have to trust it too.