The real risk is a fake login page
Almost everyone who loses something on a market like this loses it to a copy of the login screen, not to the market itself. That is good news, because it is the one part completely in your hands. Copy addresses from a source you trust, never type them from memory, and check them every session.
The check that takes five seconds
Before your password goes anywhere, read the onion printed on the login screen and compare it with your address bar. Nexus shows it in the anti-phishing image and in the header. A clone can imitate the design perfectly but cannot serve the correct address in both spots while sending you somewhere else.
Account hygiene
A username you have never used elsewhere so the account cannot be tied to an old identity. A long unique password from a local manager. The recovery phrase on paper, never typed into a web form. PGP two-factor switched on. Ten minutes once, protection for the life of the account.
Let escrow do its job
Nexus holds payment in a 2 of 3 multisig contract until you confirm the order arrived. Finalizing early releases the money before the goods land and removes your dispute path at the same time. On a vendor you have not tested, never do it.
Keep balances small
Deposit for the order in front of you and withdraw the rest to your own wallet. Whatever sits on a market is exposed to whatever happens to that market. For anything you want kept private, pay in Monero, which leaves no public trail behind.