It's not proper in that it is not properly signed. Gatekeeper complains that it cannot be opened because it is from an unidentified developer.
What kind of security risk is this for me?
What kind of security risk is this for me?
Also, the "security risk" doesn't get a whole lot smaller when the app is signed. Only widely known malware apps will get their certificates revoked in time.
The new "notarization" is slightly more thorough but the risk is still up to you and the app permissions for non-appstore non-sandboxed apps are indeed quite open. Malicious or not, an app that is not sandboxed can steal or damage your data anywhere in the filesystem.
So again - all up to you to decide.
But there is little stopping a signed app from becoming malicious, so from a security standpoint, being signed doesn't ALWAYS mean being "safe".