I mean. The situation is actually very simple. WordPress.com has a “business/pro” plan that lets you install plugins. Lower level plans do not allow that. (WordPress.com was initially just a big multisite with everyone’s blogs running off the same WP instance. That would only work securely if you disable custom code.)
So this paid business plan is just normal WordPress hosting where you get plugins and advanced features like SSH access.
WordPress.com also has a re-skinned admin experience that is more modern looking than wp-admin.
Within the past couple years, WordPress.com extended that modern skin to the plugins page. It’s (as far as I know) data from the core plugin repo, just with a more modern look/experience. In fact, the WordPress.com code for this is totally open source.
I’m not 100% sure how that’s not fair use — any WP host could do that to the plugin page of WP that they install. Other hosts just tend to be more hands off.