The risk is that whenever installing software (and a plugin runs software code inside the main program) then if the creator was malicious bad things can happen. Same rule applies whenever installing any program, only most don't warn you.
As a rule of thumb, if a calibre plugin comes from the builtin index, it is safe.
iOSRA is well-known and trusted here, anyway.