The safest way to download a Mac app is via the Mac App Store. But if you choose to download an app from outside that safe harbor, there is a way to look inside the .pkg file after you download it but before you double-click it to start the install.
Suspicious Package, from Mothers Ruin Software (got to love that name), is a QuickLook plugin. After it’s installed, you single-click on the suspicious .pkg, then hit the space bar.
To get a sense of what sorts of info Suspicious Package makes available, read the FAQ. Terrific idea.
Oh, and it’s free.