And if they use a standalone installer, they have yet another application
they have to look after to stay secure.
If they put up with the burden to add the repository, verify the
repository signing key and install it with the distributions package
management system, the updates will come in like any other security patch.
ISV packaging will lead to even more code duplication with libraries like
libpng etc.
IIRC openSUSEs One Click Install provides a way to the casual user to add
repositories and install software with one click.