So continuing this way GPG is worthless in general. Most of the keys you can't verify in person so there is no trust whatsoever. In this case Sonatype is verifying key for you. They will check if your key belongs to you and you are in control of your organization. Otherwise package would not be accepted.
I may be wrong but source and javadoc are requirements. Maybe there are some old packages without it, but new ones should be complete.