Let's Talk About the Browser Extensions You Forgot You Installed...
A quick experiment
Open your browser’s extensions page right now (in Chrome it’s under Settings, in Firefox it’s Add-ons). Take a look at the list. If you’re anything like us, there’s at least one extension in there you installed for a single task two years ago and never touched again. A PDF converter. A grammar checker. Something that promised to find you coupon codes back when you were in your finance-maxing era.
Most of them are harmless. Some of them can see every page you visit, including the ones where you type in a client’s card number or log into your work portal.
What “access to all websites” really means
When you install a browser extension, it asks for permissions. A lot of extensions, even simple-looking ones, ask for something like “read and change all your data on the websites you visit.” That permission isn’t unusual, plenty of legitimate tools need it to work. Password managers need it. Ad blockers need it.
But the permission itself doesn’t know the difference between you scrolling a news site and you filling out an invoice with a client’s billing address. If an extension has that access, it technically can see both.
Now, this definitely does not mean every extension you have installed is spying on you. Most developers build the thing, it works fine, and nothing bad ever happens. The risk is more about what could happen over time: an extension gets sold to a new owner, a developer’s account gets compromised, or an old project stops getting maintained and picks up a vulnerability that nobody will fix. Forgetting an old extension could potentially expose you to malicious actors.
Why this matters more for home offices
If you work from an office with shared IT support, someone else is usually keeping an eye on what gets installed on work machines. At home, it’s just you and your browser, and the line between “personal browsing” and “handling client data” often lives on the exact same tab.
Browser extensions aren’t inherently dangerous or bad to have. The problem is that most of us install them casually, for personal reasons, on the same browser we use to send invoices, log into client accounts, or perform other sensitive work tasks on.
What you can do about it
You don’t need to swear off extensions or start researching every developer’s background. Just one annual cleanup should handle most of the risk!
- Open your extensions list and look at everything installed. If you don’t recognize it or haven’t used it in months, be safe and remove it.
- For the ones you keep, check what permissions they’re asking for. If a simple tool (say, a screenshot app) is asking to read data on every site you visit, that’s maybe worth a second look.
- Only install extensions from sources you trust, and skip ones with very few reviews or no clear developer information.
- If you use a lot of extensions for personal stuff, using browser profiles could be a much better asset for you than the settings above.
Give client work its own browser profile
Most browsers let you create separate profiles, each with its own extensions, bookmarks, and logins, without needing separate software or accounts. Chrome, Firefox, and Edge all have this built in under the profile or “add person” menu.
Set up one profile for client work and invoicing, kept clean with only the extensions you actually need for that. Use a second profile for everything else, personal email, shopping, whatever extensions you like to collect. It takes a few minutes to set up and none of it requires new software or tools!
This one change does more than a permissions audit ever will, because it means even if something sketchy ends up in your personal profile, it has no access to the tab where you’re handling client payments.
The big takeaway from this advice
You don’t have to become suspicious of every tool you install. Extensions can legitimately make browsers much more useful, and most of them do exactly what they say. The point is just to know what has access to your browser, clear out what you don’t use, and keep client-facing work in its own lane. Keeping that in mind can greatly reduce risk and leave you using your browser extensions with more peace of mind.