It's an easy way to get packages distributed across Arch. It's especially useful for new software because getting approved for mainline Arch repos is a pain.
The issue is the fact that it was created before widespread adoption of Arch and thus security is a bit lackluster.
When you use it, the first thing you'll see is "read all the PKGBUILDs before installing!!!" written all over the place, PKGBUILD being the bash script that gets the package into your system. And when Arch was that scary and unapprochable distro used by the nerdiest of nerds, everybody did exactly that and it wasn't an issue.
Nowadays a lot of people who are a bit less than consious about their decisions hop on Arch and use stuff like AUR without thinking what exactly they are doing. The results are all over the news outlets.
Maybe it'll lead to AUR creating stricter policies for maintainers, sad, but I doubt it can exist in it's current state otherwise.