"PPAs" are just ubuntu-hosted Apt repos.
I've yet to find a server-focussed package that is both not sufficiently up-to-date in the main or back ports repos and there isn't a vendor repo for it.
Sure, adding a 1 line text file in `/etc/apt/sources.list.d` and a gpg keyring to `/etc/apt/trusted.gpg.d` is probably slightly more work than running `apt-add-repository`, but if that's what defines how you pick a server distro, I'd like to very much never work with you please.
AIUI installed packages get to run scripts with superuser privileges. This to me says "Danger Will Robinson!".
Some are definitely operated by smart people e.g. Ondřej Surý offers his PHP packages for Ubuntu via a PPA (and via a regular apt repo for Debian).
As for the packages: they're literally just regular .deb packages, which means they're installed as root, which means yes they could do anything.
Of course you can also examine/extract them just like with a regular repo, but it's definitely an issue of trust for most people.
I trust that e.g the Varnish project, or Percona or the aforementioned Ondřej Surý are not putting shifty shit in their packages. I can't trust JimmyB on Launchpad the same way.
* http://jdebp.eu./Softwares/package-repositories.html#Debian
The rest of the problem still exists, though. Only one package manager that I know of even tries to address it, by having pre/post-install/upgrade/remove actions use a specialist declarative language for things like making directories and dedicated user accounts. But even that has a loophole that allows arbitrary scripts to be executed from within that language.
* https://freebsd.org/cgi/man.cgi?query=pkg-create#PLIST_FORMA...
* http://man.openbsd.org/pkg_create#PACKING-LIST_DETAILS
The loophole exists because the provided language simply isn't sufficient for everyday needs. It's quite hard to come up with one that is, whilst not being as worrysome as general-purpose shell script, too.