Yes, it’s definitely risky, especially if you're handling payments and other sensitive things.
If it's a project you really care about, it's usually not a good idea.
If you don't know how to manage a VPS, you might not be able to tell if someone changes files or messes with things.
They...