It does not display the moon itself - just the phase, i.e. a circle, part of which is filled yellow. Weather widget displays the moon much better.
I've checked the source code - it uses an application to calculate phase, and yes, possibly for something else/malicious - but if you're so paranoidal, use LittleSnitch.
Diana mini
widget displays the moon's age/phase graphically
Version: 0.9.2