I don’t recommend using the web app over the native app for zero clicks minimization as anything potentially malicious were to happen on the server serving the web app it’s bound to be disaster.
But you are right on the rest, It is not easy to not fall on zero clicks (if at all actually) or even, ever evolving sophisticated phishing attacks.