Download the EXE only from the official GitHub Releases page and compare its SHA-256 checksum. The current executable is not Authenticode-signed, so Windows SmartScreen may identify the publisher as unknown.
Do not run cleanup unattended. Review paths and risk levels, keep yellow and red items unselected unless you understand the impact, and maintain a current backup.
Report security issues privately to info@vi-it.de. Do not include private project files, credentials, tokens or personal paths.