Browser extensions that pay for their keep

July 2, 2026 · 3 min read
Browser extensions that pay for their keep

Browser extensions occupy an odd position: enormously useful, and the largest unexamined security hole on most people's computers. An extension with broad permissions can read every page you visit, including your bank and your email. That is worth a moment's thought before installing the fifth one.

The categories that genuinely earn their place

  • A password manager. The single highest-value extension there is. Filling unique credentials automatically is what makes unique credentials sustainable, and credential reuse is how one trivial breach becomes a compromised bank account.
  • Content blocking. Pages load faster, use less data and less battery. A reputable blocker is also a meaningful security measure, since malicious advertising is a real delivery mechanism.
  • Read-later. The tool that fixes tab hoarding, by giving articles somewhere to go that is not a tab.
  • A tab manager. Suspending inactive tabs to reclaim memory, or saving and restoring named sets of tabs as project workspaces.
  • Screenshot and annotation. Full-page capture including the part below the fold, with arrows and text. Faster than the alternative for anything you need to send to someone.
  • A dedicated dictionary or translation tool, if you read in more than one language. Select and define, without leaving the page.
The permission question"Read and change all your data on all websites" is the permission most extensions request and few genuinely need. If a tool that reformats one specific site wants access to every site, that is a reason to look for an alternative.

The security rules worth following

Audit quarterly. Open the extensions page and remove anything you have not consciously used. Most people have four or five they have entirely forgotten, and a forgotten extension is the most dangerous kind — it can be sold, transferred to a new owner and updated with something malicious, and you will not notice.

Be suspicious of ownership changes. This is the standard attack in the extension ecosystem: a popular, legitimate tool gets bought, and an update adds tracking or injects content. Popularity at install time is no guarantee of behaviour a year later.

Prefer fewer, broader tools over many narrow ones. Every extension is an additional party with access to your browsing, so consolidating reduces exposure even when the individual tools are all fine.

Check the developer and the update history. A named developer with a real website and recent updates is a meaningfully better bet than an anonymous listing with a large install count.

What to skip

Coupon and cashback extensions, which work by monitoring your shopping and rewriting affiliate links, and are paid for with your browsing history. Anything promising to speed up your computer, which is a category that has never once been legitimate. And any extension whose function you could achieve with a bookmark or a keyboard shortcut — which, on inspection, is more of them than you would expect.

Profiles instead of extensions

One structural fix worth knowing: browser profiles. Keeping a separate profile for banking and admin, with no extensions installed at all, removes the entire risk surface for the sites where it matters most. Everything else — work, research, shopping — runs in your normal profile with whatever extensions you like. It takes two minutes to set up and it is more effective than any amount of careful extension vetting.

The short versionSix extensions you use daily, audited every quarter, with the sensitive browsing in a clean profile. That is a better position than most people are in.