The point is that every layer helps. It's bad security practice to build a single layer of defense and call it a day. People always find a way through.
If a JS script can bypass all of this then you have a bigger problem, the malware developers can easily already have a dummpy app already in the app-store that is signed by Apple, the installer signature is the last thing you should worry about in this case (better disable JS now)