In most cases the script already installs a pre-compiled binary that can be anything, they wouldn't need to make the script itself malicious if they were bad actors.
I'll die on the hill that curl | bash is fine if you're installing software that self updates - very common for package managers like other comments already illustrated.
If you don't trust the authors, don't install it (duh).
I don't think you can. But if it's open source and popular, there might be a chance it will have a maintained fork should that happen.
Freemium feature creep might be a sign things are changing for the worst, as in, if more and more features are being added to the premium plan and the free version is stagnating; to the point the target public of the premium version is creeping to average users instead of aiming at commercial or power users.
This is such an underutilized and neglected behavior.
The very least a config parser should do is to log a warning.