@elinkabelzinka Its been a while since it happened, but I will try my best to recall the events. Get your snacks and blankets, because it's story time.
So around a year or 2-3 ago, there was an incident where it was discovered/announced that the people running the old vrmodels site were part of some group, akisoba llc, who claimed to be working with a number of creators from gumroad to "protect their work", as they like to call it.
Their idea to "protect the creators' work" was to embed the unity packages that were hosted on their server with malware like discord token loggers, key loggers and modified SDK scripts containing malicious code to overwrite existing scripts in a unity project.
Around the time that happened, the old vrmodels was becoming a dumpster fire that people were abandoning and some refugees were going over to the newly created sanctuary.moe website. As it turned out, the person(s) running the sanctuary.moe site was also a part of the akisoba group, or another malicious hacker acting on their own.
There was an uproar about that, and eventually sanctuary moe was shut down.
Someone created a unity plugin called Safe Import designed to check unitypackages for any akisoba, vrmodels and sanctuary-related malicious scripts during the import process. The github page for the plugin no longer seems to be available, (nevermind, I found it) but this one containing text files that were to be used with it still exists. https://github.com/Purple420/Hashes-of-Safe-Scripts/tree/main/Unsafe Files
Some of the refugees from sanctuary decided to create a private discord server to share and trade assets on, but eventually the person who ran the sanctuary site found out about the server and invaded, and during that time they displayed their ability to hack the discord accounts of several of the members in real time. The admin of that discord server decided to nuke it shortly after.
And I was there to see it all. That being said, I'd be wary of vrc garden. I wouldn't even trust the new management of the vrmodels site.
Also, advertisements on an asset leaking site? What dumbass is going to pay to have an ad placed on there?