That "higher bar" is a curation service that has verified fake password managers, crypto swindling apps and illegally cloned FOSS software. Any sane security model would defer to the user's preference regardless of where the API is called.
It's not that complicated, really - client-side API controls are not a server-side problem. You are fundamentally not fixing the issue by forcing everyone through App Store review.