A browser extension is a tiny program you invite to sit inside your browser and watch. The useful ones block ads or save passwords. The dangerous ones read every page you open, including your bank statement and your private messages, and quietly send it somewhere you would never approve.

The tricky part is that both kinds look identical in the store. A five-star rating and a friendly icon tell you almost nothing about what an extension does once it is installed.

Key takeaways

  • Extensions can read and change everything on the pages you visit, so each one is a real trust decision.
  • The most common mistake is installing add-ons you no longer use and forgetting they are there.
  • A safe-looking extension can be sold to a new owner or hijacked in an update and turn malicious later.
  • Check the permissions it requests, the reviews, and how recently it was updated before installing.
  • Audit your extensions every few months and remove anything you do not actively rely on.

Mistake one: treating extensions as harmless little tools

When you install an extension, the browser often warns that it can “read and change all your data on the websites you visit.” People click Add without a second thought. That permission is enormous.

browser toolbar with several extension icons
Each extension icon in your toolbar is a program that can see the pages you open.

It means the extension can see the contents of every page: your webmail, your online banking, forms you fill in, and text you type. A trustworthy developer never abuses that. A shady one harvests it. The permission itself is normal for something like an ad blocker, which genuinely needs to read pages to work, so the request alone is not the red flag. The developer behind it is.

When I clean up a friend’s laptop, the browser is almost always the messiest part. Ten extensions installed, two remembered, eight forgotten. Every forgotten one is a standing risk for zero benefit.

Mistake two: installing without checking who made it

Before you add anything, spend two minutes vetting it. This is the difference between a helpful tool and a spy.

Check Good sign Warning sign
Reviews and users Thousands of users, detailed reviews Few users or reviews that all sound the same
Last updated Updated within the last year No update in years, or a very recent owner change
Permissions Matches what the tool does A calculator asking to read all your browsing
Developer A known company or named person No website, no contact, no track record

The permissions check is the sharpest tool you have. Ask whether the access makes sense for the job. A weather widget has no reason to read every page you visit. A note-taking clipper reasonably needs to, so judge it on its developer and reviews instead.

Watch out

A safe extension today can turn hostile tomorrow. Popular add-ons get bought by other companies, and a routine update can flip a helpful tool into an ad-injector or data harvester overnight. This is exactly why a periodic audit beats a one-time check.

Mistake three: never cleaning house

Extensions accumulate. You install one for a project, another because a website suggested it, a third that came bundled with something else. Months later they are all still running, still reading your pages, still capable of being hijacked.

Open your extensions list and be ruthless. In Chrome and Edge, click the puzzle-piece icon, then Manage extensions. In Firefox, open the menu and choose Add-ons and themes. Remove anything you do not remember installing or have not used in a month.

Turn off what you rarely need

For extensions you use occasionally, use the toggle to disable rather than remove. A disabled extension cannot read your pages until you switch it back on. That is a nice middle ground for a tool you want twice a year but do not want watching the other 363 days.

Mistake four: getting extensions from random websites

Only install from the official store for your browser: the Chrome Web Store, the Edge or Firefox add-on sites, or Safari’s Extensions gallery. An extension offered by a pop-up, an email, or a random download page has skipped every safety check the official stores run.

Official stores are not perfect, and bad extensions do slip through, but they remove reported ones and they vet permissions. A file handed to you outside that system has none of those guardrails. If a website insists you install its special extension to continue, that pressure is itself the warning.

Tip

Keep a small number of extensions from names you recognize rather than many from strangers. Fewer add-ons means a smaller attack surface and a faster browser. Pair this habit with tuned browser security settings and you close most of the everyday browsing risks at once.

Mistake five: ignoring what extensions see on shared networks

A rogue extension is even more dangerous when you are on an open network, because it can quietly funnel what it reads while you sip your coffee. Combine tidy extensions with careful habits when you connect away from home. Our guide to staying safe on public Wi-Fi covers the network side, and both together are part of the broader device security basics we point everyone to first.

None of this means extensions are bad. A good ad blocker or password manager extension genuinely improves your day. The goal is to keep the good ones and shed the rest.

Your afternoon checklist

  • Open your browser’s extension manager and list everything installed.
  • Remove any extension you do not recognize or have not used in a month.
  • Disable, rather than delete, tools you only need occasionally.
  • For each keeper, check that its permissions match what it actually does.
  • Confirm each one was updated recently and comes from a known developer.
  • Only install new extensions from your browser’s official store.
  • Set a reminder to repeat this audit in three months.

Think of your extensions like house guests: a few trusted ones are welcome, but you would not hand a stranger a key and forget they have it. A short clean-up today removes silent watchers you never meant to keep. The FTC’s advice on recognizing and removing malware is a good companion read if anything you find looks worse than a forgotten toolbar.