GuideHQ

How do I know whether a browser extension is safe to keep?

The dangerous extension is usually not one you installed by mistake. It is one you installed deliberately, trusted for years, and which was sold or compromised and then updated itself. How to judge one before installing, and how to audit what you already have.

Difficulty
intermediate
Time
25 min
Read
8 min
Safety
caution

Short answer

Judge an extension on three things: what permissions it asks for, who publishes it, and whether you still use it. Anything that can read and change data on every site you visit needs to justify that, and most do not. Extensions update themselves silently and ownership can change without notice, so one that has been fine for years is not proven safe — it is unaudited. Go through the list twice a year, remove what you are not using, and keep the total small.

A browser extension is a program you have installed inside the one application that sees your bank, your email, your work and your shopping. Most are written by decent people and do exactly what they say. The problem is structural rather than moral: extensions update themselves in the background without asking, a popular one has real commercial value to whoever wants to buy it, and a developer account can be phished like any other. The result is a well-documented pattern in which a genuinely useful extension with a large user base changes hands or is compromised, and a later version starts injecting adverts, redirecting searches or collecting browsing data — from people who checked it carefully when they installed it years earlier. Nothing about the extension's appearance changes. This guide is about how to reduce that exposure without giving up the tools you actually use.

Safety

An extension with permission to read and change data on all websites can see everything you do in the browser, including banking pages, email and anything you type into a form. That permission is normal and necessary for some genuine tools, which is exactly why it is dangerous when the tool changes hands or is compromised. Treat the extension list as a list of things that can read your online life, and keep it as short as you can live with.

Step by step

  1. Understand what permissions actually mean, because everything follows from this.When an extension is installed the browser states what it can access, and the important distinction is between an extension that works on specific sites and one that can read and change data on all sites. The second can see every page you load and everything you type into one. Some tools genuinely need that — a password manager, an ad blocker — and for those it is the price of the function. For a shopping voucher finder or a theme, it is not.
  2. Apply the proportionality test before installing anything.Ask what the extension does and what the least access is that would let it do that. A tool that converts a page to a PDF needs access when you click it, not permanently. Several browsers let you restrict an extension to run only when clicked or only on named sites, and where that setting exists it is the single most valuable one on this page.
  3. Check the publisher rather than the star rating.Look for a developer with a real presence: their own website, a support address on a domain they own, a published privacy policy, and ideally source code you or someone else could inspect. Reviews are easily manufactured and user counts say nothing about who owns it now. An extension whose listed developer is a name with no other existence anywhere is the one to be careful about.
  4. Prefer the small number of well-known tools to the long tail.For each job — password management, ad blocking, note clipping — there are usually two or three widely used options with real organisations behind them and many people watching them. Choosing from that set rather than from the twelfth search result removes most of the risk with no loss of function.
  5. Audit what you already have, and be ruthless.Open the browser's extension page and go through every entry. Remove anything you do not remember installing, anything you have not used in months, and anything whose job you could do without. Each removal is a permanent reduction in exposure and costs nothing. Most people's lists are two or three times longer than the set they actually use.
  6. Look specifically for the ones you no longer recognise.An extension whose name means nothing to you, whose icon you have never noticed, or which appeared when you installed some other program is the highest priority for removal. Some are installed alongside downloaded software, which is why the catalogue's guide on downloading software safely matters here.
  7. Re-check the ones you trust, because that is where the risk actually is.For each extension you are keeping, look at its store listing again: has the developer name changed, has the privacy policy changed, are recent reviews complaining about behaviour that did not used to happen. A sudden run of reviews saying it started opening tabs or changing search results is the pattern to watch for, and it usually appears in the reviews before anywhere else.
  8. Watch for a permission increase after an update.Browsers ask again when an update needs more access than before, and that prompt is a genuine signal rather than an interruption. An extension that suddenly wants access to all sites when it previously wanted access to one has changed what it is. Read that prompt rather than clicking through it.
  9. Use the browser's own safety check.The major browsers now flag extensions that have been removed from their store, found to violate policy, or identified as malicious, and they will tell you rather than removing them silently. Look at that panel when you audit, and act on what it says immediately.
  10. Keep work and personal separate.A separate browser profile — or a different browser — for banking and anything sensitive, with no extensions at all, is a simple and effective arrangement. Extensions in one profile cannot see pages loaded in another. The catalogue's guide on separate user accounts covers the wider version of the same idea.

Common mistakes

  • Treating an extension you have had for years as proven safe — It updates itself silently and can change hands without notice. Age proves it was safe once; it says nothing about the version running now.
  • Granting access to all sites without asking why — That permission covers your bank, your email and every form you fill in. Some tools need it and most do not, and the browser will usually let you narrow it.
  • Installing an extension to solve a one-off problem and leaving it — A tool used once and kept forever is permanent exposure for no benefit. Remove it when the job is done.
  • Judging by user numbers and star ratings — Both are attractive to buy precisely because they inspire confidence, and both can be manufactured. Judge the publisher and the permissions.
  • Installing extensions from outside the browser's own store — The store is where the review, the removals and the safety flagging happen. A file downloaded from a website has none of that, and it is a standard route for something genuinely malicious.

If it doesn't work

Adverts started appearing on sites that never had them

Cause: An extension injecting them — Fix: Disable all extensions, confirm the adverts stop, then re-enable them one at a time until they return. The catalogue's guide on pop-ups and browser hijacks covers the full cleanup, including the homepage and search settings an extension will also have changed.

Searches are redirected to a different search engine

Cause: An extension or an installed program has changed the default — Fix: Remove the extension, then reset the search engine and homepage explicitly — removing the extension does not always restore them. Check installed programs too, because some of this arrives as software rather than as an extension.

An extension you have used for years suddenly behaves differently

Cause: It changed hands or was compromised, and updated itself — Fix: Remove it now rather than investigating. Then change the passwords for anything sensitive you used in that browser, because an extension with full site access could read those pages. Look for a replacement from a publisher you can identify.

The browser says an extension has been disabled for safety

Cause: It was removed from the store or flagged as malicious — Fix: Do not re-enable it or look for it elsewhere. Remove it, and treat the accounts you used in that browser as potentially exposed if it had wide permissions.

The browser is slow and you have many extensions

Cause: Each one runs on every page — Fix: Extensions are a common cause of a slow browser, quite apart from any security question. The catalogue has a guide on that specifically, and the audit above usually fixes both problems at once.

An extension asks for more permissions after an update

Cause: Its function changed, or its ownership did — Fix: Decline and look at the store listing before accepting. A genuine new feature will be described in the update notes; an unexplained increase is a reason to remove it.

Questions people ask

Are ad blockers safe?

The two or three long-established ones with open source code and large communities are among the most scrutinised extensions there are, and they are widely recommended, including as a defence against malicious adverts. The category also attracts imitators with similar names, which is where the risk is. Pick a well-known one deliberately rather than the first search result.

Do extensions work in private browsing?

Only if you specifically allow each one, and by default most are disabled there. That is worth knowing in both directions: it is a small safety benefit, and it explains why an ad blocker stops working in a private window.

Is it safer on a phone?

Mobile browsers mostly do not support extensions at all, which removes this whole category of risk. Where a mobile browser does support them, the same reasoning applies.

How many is too many?

There is no number, but a useful test is whether you can name what each one does and when you last used it. If you cannot, it should not be there. Most people function well on three or four.

What about extensions my employer installs?

Managed extensions are pushed by an organisation's policy and cannot be removed by you. That is normal on a work machine and is one of several reasons not to use a work browser for personal accounts.

What to do next

Sources

  • Google Chrome and Mozilla add-on developer policies and published safety-check behaviour for removed or malicious extensions
  • NCSC guidance on software supply-chain risk and on limiting what installed software can access

Written and maintained by the GuideHQ editorial team. More in Technology.