Nah, virustotal does that stuff all the time. Two detections is low out of all the malware scanners it used. I usually just use malwarebytes.
The software author should take a look if this is the case, for to change the packager's configuration (no encryption [if some algorithms in the programs are important, to protect them with through implementation, not packager ], or if the binary is small to not compress, or to adjust other params, etc), or to change of packager, or to contact with the antivirus company.
However, I have password managers, access banking websites, etc so I’m cautious of exes from smaller developers.
I wasn’t able to easily find the real identity of OP but the binary is code signed by a registered company it seems.