Extract URLs from documentation, configuration and code, with their protocol and position.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Extract URLs from documentation, configuration and code, with their protocol and position.