file archivers such as winrar and 7-zip are known to be exploitable.
what is the securest way to unzip downloads?
You don't really know what's inside until you unzipped it...
I don't know of any utility that will do that for you ( that's not to say that there isn't one ).
I use this method for any downloaded zip:-
Upload to Virustotal and grab the checksum from there .
Calculate the checksum locally for your download and compare the two .
Run an on-demand scanner on the download if you like .
If all looks good I use 7-zip to extract the contents.
I don't know exactly how secure this method actually is , but it hasn't let me down so far .