Step 1: User clicks ad that says they can download this app super easily and improve their phone's battery performance.
Step 2: User clicks and navigates to a side-load page/alternate store.
Step 2a: Pop-up appears - please adjust your settings to enable access to this app
Step 3: User does so and now downloads malware.
Step 4: Gets upset and blames Apple or calls up their more tech informed Hacker-News-using family member and asks how to fix it.
(this genuinely happens with my mother and chrome extensions - she somehow CANNOT avoid those "search engine takeover" extensions no matter how much I try to educate her on how to avoid it)
What if the permission enablement was made more difficult? Perhaps like how you get to access Android developer tools only after tapping the build number a bunch of times. Or even, making it something you have to run from a CLI while connected to a computer.
My point is, there are many options that preserve safety for the vast majority of users without making it a total non-starter to use alternative app stores.
Few years ago before Apple implemeted Night Shift, F.lux used to use an ability for non-paid developer accounts to compile and run an app on their phone to distribute. They provided a source code for a small program that serve as a shim to F.lux. User need to compile this code with Xcode and put it on their phone.
People followed tutorial videos downloading Xcode, making a developer account, figure out how to get signing profile works, etc. just to get F.lux installed on their phone. Searching for "Flux iOS 9" on YouTube yields some video with over 100k views. In some community there are people who are willing to do it for you (by VNC into user's machine) at $10 per installation.
If the ability to side load an app is not enabled by default, how would novice users accidentally install apps they may not have intended to?