That's not incompatible. They do a lot for security, even if malware still manages to get there. One would assume that the most popular apps get more attention.
The APK is a thin shell that downloads even more code to execute, from the internet. So, what you download and inspect isn't what's executed, and what you execute now might be different in 5 minutes.
The Play Store has all kind of automated and manual processes to detect malware and vulnerabilities. It's why I don't enable side-loading on my phone.