Distribution of safari web extensions outside of the store

It appears that safari web extensions can only go through the app store. In order to distribute it outside, is it sufficient to use a valid Developer ID cert or does it need to be notarized? I understand that users would have to click Allow Unsigned Extensions. Do they have to do this every single time even if a valid cert is used to sign the app?

Here's a forum post with a reply for an Apple employee: https://developer.apple.com/forums/thread/659029

In my experience, the user has to click "Allow Unsigned Extensions" every time they open Safari.

Also in my experience, distributing web extensions this way is far from optimal.

Distribution of safari web extensions outside of the store
 
 
Q