You install a coupon extension before buying a new router from an Australian retailer. It promises to find codes automatically, asks to “read and change all your data on all websites”, then sits beside your address bar for months. You forget it is there, but it can still see pages you visit, forms you fill, and in some cases the checkout pages where you enter personal details.
Or you add a “free” video downloader, PDF converter, dark mode tool, AI summariser, shopping helper, or tab manager because it solves one small annoyance. That does not make it malicious. Plenty of browser extensions are useful. The problem is that many extensions are tiny pieces of software with broad access to your browsing life, maintained by people you may never identify, sometimes sold or abandoned without you noticing.
The permission that should make you pause
The biggest red flag is not a scary-looking icon or a long privacy policy. It is a permission request that does not match the job.
If a weather extension wants your location, that can make sense. If a spelling extension wants to read text fields, that can make sense too, although it still deserves scrutiny. But if a simple colour picker, calculator, wallpaper tool, or new-tab clock wants access to every site you visit, the trade-off is poor.
Watch for permissions phrased like:
- Read and change all your data on all websites: this is the broad one. It can be necessary for content blockers, password managers, accessibility tools, web clippers, translation tools, and some developer tools because they have to inspect or change pages as they load. It is usually hard to justify for clocks, themes, calculators, wallpapers, simple note pads, QR tools, or basic price trackers.
- Access data for every site: similar concern. Ask why the extension cannot work only on selected sites, such as one shopping site, one work app, or one learning portal.
- Read browsing history: useful for some tab managers and history search tools, unnecessary for most shopping, PDF, theme, or media helpers.
- Manage downloads: reasonable for a download manager, suspicious for a coupon, theme, or vague “speed booster”.
- Change search settings or new tab page: common with low-value extensions that monetise through search traffic.
- Read clipboard data: risky because the clipboard may contain passwords, recovery codes, addresses, PayID details, invoice numbers, tax file number fragments, or banking references.
The practical test is simple: could this extension do its advertised job with narrower access? If yes, do not grant broad access unless you have a strong reason to trust it.
Extension types that often carry poor trade-offs
This is not a blacklist. The same category can include good and bad examples. The safer approach is to recognise patterns where the benefit is often small and the access requested is often large.
Coupon and shopping assistants
These can be tempting in Australia because online retailers frequently use promo fields, sales events, marketplace listings, click-and-collect options, loyalty pricing, and member discounts. The catch is that shopping assistants often need to see retailer pages to function, and some want access across all sites so they can detect where you are shopping.
The trade-off is clearest at checkout. An extension may be present while you compare appliances, order school supplies, book flights, buy medicine, enter your delivery address, or sign in to a supermarket, pharmacy, department store, telco, or electronics retailer account. A coupon tool may genuinely need access to checkout pages on selected stores. It usually does not need to run while you use internet banking, webmail, myGov, Medicare, Services Australia, the ATO, or your NBN provider’s account portal.
Free proxy and “unlock any site” extensions
Browser proxy extensions are often misunderstood. Many affect browser traffic only, not every app on your laptop or phone. Some free proxy tools make money in ways that are not obvious from the install button.
For streaming and overseas catalogues, be realistic: licensing rights vary by country, and services can restrict access based on account region, payment method, location signals, and their own rules. No extension can honestly guarantee that every catalogue will work forever. If an extension markets itself as a magic bypass for everything, treat that as a quality warning.
A safer default is to avoid free, unknown proxy extensions entirely. If you need privacy on public Wi-Fi, use trusted network tools at the device level and keep expectations modest: encryption and network privacy are different from guaranteed access to every service.
Video downloaders and media helpers
Some media extensions are legitimate, for example for your own files, workplace training portals, school resources, or sites that allow downloads. Others push into copyright or platform-rule trouble, or ask for sweeping access because they try to detect media across every page.
The lawful smart approach is to use built-in download options where available, keep offline copies only when the service allows it, and avoid extensions that promise access to restricted streams, paid content, or accounts you do not control.
PDF converters, office tools, and file helpers
Extensions that convert, merge, compress, or annotate files can be useful. They can also become a quiet data leak if they upload documents to a remote service. That matters if the file contains ATO notices, BAS paperwork, invoices, medical letters, rental applications, school forms, insurance claims, client contracts, identity documents, or bank statements.
The safer default is to prefer browser-native PDF features, your operating system’s print-to-PDF tools, or reputable offline apps for sensitive documents. If an extension needs to upload files to work, assume the file leaves your device unless the developer clearly explains otherwise.
AI summarisers and writing assistants
AI browser helpers can be genuinely handy for long webpages and email drafts. The issue is scope. A summariser that reads the current page only when you click it is a different risk from one that can read every page automatically. A writing assistant that sees all text fields may process private messages, work documents, forms, support chats, and internal tools.
Use them deliberately. Turn off automatic reading where possible. Avoid using them on internet banking, Centrelink, Medicare, My Aged Care, ATO, health, legal, HR, school, telco complaint, energy account, or confidential work pages. If your employer has data-handling rules, follow those before installing a browser helper on a work profile.
Safer defaults that actually help
The best extension setup is boring: fewer extensions, narrower permissions, and regular clean-outs. That is much more reliable than trying to memorise which brands are currently fashionable.
- Install from official stores, but do not treat that as approval: Chrome Web Store, Microsoft Edge Add-ons, Firefox Add-ons, and Safari extensions provide some screening, but store presence is not a guarantee of long-term safety.
- Prefer well-known, single-purpose extensions: an extension that does one clear job is easier to assess than a bundle promising search, coupons, tabs, deals, AI, proxy access, and speed boosts.
- Match access to the job: a password manager may need to recognise login fields across many sites. A dark mode extension may need to change page appearance across many sites if you want it everywhere. A web clipper may need access when you save a page. A simple unit converter, dictionary, recipe saver, or parcel tracker usually should not need every page by default.
- Use “on click” or selected-site access: where your browser allows it, change site access from “all sites” to “when clicked”, “on click”, or only the sites where you need it.
- Remove extensions you have not used recently: an unused extension still has update and ownership risk.
- Check the developer, not just the name: clones can use similar names and icons. Look for a credible publisher, clear website, useful documentation, and sensible support history.
- Be wary after ownership changes: a trusted extension can change hands. If an update suddenly asks for broader permissions, pause before accepting.
How to audit your browser in ten minutes
Open your browser’s extensions page and go one by one. In Chrome, select the three-dot menu, then Extensions, then Manage Extensions, or type chrome://extensions in the address bar. Open Details for each extension. Under Site access, change “On all sites” to “On click” or “On specific sites” where available, then add only the sites that genuinely need it.
In Microsoft Edge, select the three-dot menu, then Extensions, then Manage extensions, or type edge://extensions. Open Details for each extension and review Site access. Change “On all sites” to “On click” or “On specific sites” where Edge offers the option.
In Firefox, select the menu button, then Add-ons and themes, then Extensions, or type about:addons. Open each extension and review Permissions. Firefox does not expose the same per-extension site-access controls for every add-on, so remove extensions that ask for more access than their job needs, disable them when not in use, or use a separate profile for higher-risk browsing.
In Safari on Mac, open Safari, then Settings, then Extensions. Select each extension and review its website access. Where Safari offers website permissions, set access to Ask, Deny, or Allow for selected websites rather than allowing access everywhere. Also check whether the extension is enabled in Private Browsing.
For each extension, ask four questions:
- Do I still use it? If not, remove it.
- Does it need access to every site? If not, restrict it or remove it.
- Would I be comfortable using it while logged into banking, email, myGov, Medicare, Services Australia, the ATO, my telco, my energy provider, my insurer, or work systems? If not, do not let it run there.
- Would the same job be safer with a built-in browser feature? Modern browsers already handle password alerts, PDF viewing, translation, reader mode, tracking prevention, tab groups, and basic privacy controls better than many add-ons.
Do this on your main computer first, then your work profile if policy allows, then any shared family computer. Shared devices often collect years of old extensions from homework, streaming, online shopping, printer setup pages, parcel tracking, NBN troubleshooting, and one-off form filling. Removing one at a time is fine. You do not need a dramatic reset.
What is mostly wishful thinking
“It has lots of installs, so it must be safe” is weak reasoning. Popular extensions can still request too much access, change over time, or be maintained poorly.
“The privacy policy says they care about privacy” is not enough. Policies matter, but permissions and behaviour matter more. If the extension does not need broad access, a friendly policy does not make broad access sensible.
“I only use it on harmless sites” may not hold if the extension runs across all sites. Unless you restrict site access, it may be present while you check a bank balance, update a Medicare claim, read an ATO message, manage an NBN appointment, or lodge a telco support request.
“Incognito or private mode fixes it” is also incomplete. Many browsers disable extensions in private windows by default, but users can re-enable them. Private browsing mainly reduces local history, not the power of an extension you explicitly allow.
“Antivirus will catch bad extensions” is not something to rely on. Security tools may detect known threats, but they are not a substitute for limiting browser permissions in the first place.
Practical Recap
- Keep extensions few, boring, and clearly useful.
- Treat “read and change all data on all websites” as a serious permission, not routine admin.
- Give broad access only to extension jobs that genuinely need it, such as reputable password managers, content blockers, accessibility tools, web clippers, translators, and developer tools.
- Avoid unknown free proxy, coupon, downloader, and file-converter extensions on sensitive browsing.
- Use selected-site or on-click access where available.
- Remove anything you no longer use, especially if it asks for broad access.



