instead of implementing dumb factors like plugin popularity
Considering that the uploading of custom files is not available, they have to host all the plugins, mods and modpacks themselves, but Aternos is free and it just doesn't have the resources to do this. And this introduces the suggest feature. As stated above, it's impossible for Aternos to support all the plugins available in Spigot/Bukkit, so users can just suggest the plugins they want and the system will decide if it's ok to be added or not.
if they're so lazy to control and remove malicious plugins
They are not lazy, it is just too hard to make a system that is able to detect code that could prevent the automatic server shutdown.
Minehut has different possibilities since their system works completely different under the hood. While Minehut is more like a classic Minecraft network (with a proxy and such stuff), on Aternos each Minecraft server stays on its own. Players are directly connected to the server, instead of a proxy. Both designs have their pros and cons.
im pretty sure it wouldn't go unoticed if a plugin would somehow make its way to spigot with malicious code in it
I'm sorry but this just doesn't make sense. Yes, it wouldn't go unnoticed, but if file uploading was a thing, you wouldn't be limited to plugins from Spigot/Bukkit, you could add literally every .jar file you could put your hands on. Do you really think there isn't a plugin/mod somewhere that bypasses Aternos limitations?