Yep. And this has been the case for over a decade.
They might do some sampling, but they're definitely not checking everything.
The first app I published in 2012 had a backend, but the Apple team never logged in with the provided credentials, or even tried anything.