If truly are suspicous then you can run it through a .NET decompiler such as dotPeek. I looked through it like an hour ago and I didnt find anything weird. However, I think the .net executabe only handles updating. I'm pretty sure that most if it is some kind of javascript frontend (looking at %localappdata%/Plutonium/assets) it doesnt seem obfuscated, so you could look there aswell.

pesto
@pesto