Sometimes I need to quickly look at a paid plugin for educational purposes, so I browse GPL directories like https://nodub.com/, but for production, I still obtain licenses from the authors for updates and tickets. How do you address security: is local antivirus/static analysis scanning sufficient, or do you additionally run each archive through a separate container?