Can't you see for yourself that it is 50/50 - it can be or not, so it is as
much "maybe malware" as "maybe goodware".
It is not because there are only two possibilities, that "it is 50/50". For
example, http://www.privmetrics.org/wp-content/uploads/2015/06/wisec2015.pdf
says:
Our analysis shows that 60% of the paid apps are connected to trackers that
collect personal information compared to 85%–95% in free apps. We further
show that approximately 20% of the paid apps are connected to more than three
trackers. With tracking being pervasive in both free and paid apps, we then
quantify the aggregated privacy leakages associated with individual users.
Using the data of user installed apps of over 300 smartphone users, we show
that 50% of the users are exposed to more than 25 trackers which can result
in significant leakages of privacy.
The reported numbers, which are only dealing with tracking (no other type of
malware), are necessarily lower bounds: proprietary apps that were not proven
to be connected to trackers may be connected to (currently undiscovered)
trackers.
To find out you must test it or even reverse engineer it.
Exactly. And that is unfair. With an access to the source code it is orders
of magnitude easier to study. Discovering trackers is possible. Discovering
a backdoor that is not frequently used is basically impossible without an
access to the source code. Users deserve to know what the software they run
does. They deserve free software.