Browser extensions run with far more access to your browsing than most people realize — a malicious or poorly maintained one can read everything you type and see every page you visit. Extension stores catch a lot of bad actors, but not all of them, and a legitimate extension can also turn harmful after being sold to a new owner. Here's how to actually vet one.

Why extensions are riskier than regular apps

To do their job, many extensions need broad permissions — reading and changing content on every page you visit, for instance, is a normal requirement for an ad blocker or password manager. That same permission level, in the wrong hands, can log every page you visit, capture form data, or inject unwanted content. Because extensions often auto-update silently, an extension that was safe when you installed it can change behavior later without you reinstalling anything.

Before installing: what to actually check

Warning signs an installed extension may have gone bad

How to audit what you already have installed

Open your browser's extension management page (in Chrome: chrome://extensions, in Firefox: about:addons) and review every extension currently installed, including ones you forgot about. For each one, ask: do I still use this, and do its permissions still make sense for what it does? Remove anything you don't actively use — an unused extension is unnecessary risk with zero benefit, since it still runs and holds its permissions even when you're not actively interacting with it.

A safer default habit

If in doubt about a specific extension, favor the smaller, more specific one over the feature-packed alternative — broader functionality almost always means broader access to your browsing.

Quick extension safety checklist