Help: Can a 3rd party developer input malware?

If I give access to a third party developer to access the theme, code editor and the checkout scripts etc… could they do the job and also insert malware ?

Does Shopify have any protection against this?
How do you know that they haven’t inserted something malicious?

Thanks-is there a way to check? It’s not an application, they are adding code for analytics…