Could be one or one thousand. Frankly, the exact number doesn't matter.
I'm assuming people are using the AUR to install programs that are sufficiently complex and the idea one can trivially audit a complex program and all of its dependencies is foolish. The foolishness of that expectation scales with the number of complex programs installed.
The idea that users should "just check the source code every single time" has never been, nor will it ever be, a reasonable solution to supply chain attacks.