How We Score Browser Extensions
Every extension on this site gets a safety grade out of 100, built from five dimensions. The rubric is versioned — when weights change, we re-score everything and say so.
The five dimensions
- Publisher & Identity (20 points) — Who actually publishes this extension? Is there a registered company or a named developer behind it? Is the publisher verified on the store? How old is the listing, and is there a real way to contact them?
- Permissions & Access (25 points) — What can the extension actually do? Based on its manifest, we inspect the permissions and host access it requests — whether it can read and change data on every site, access your browsing history, tabs, cookies or downloads — and whether that scope is proportionate to what the extension claims to do.
- Data & Privacy (20 points) — What does the extension collect and where does it send it? Clear GDPR/CCPA commitments, the store's declared data-use disclosures, and whether you can delete your data. Whether it shares or sells data is shown as a direct quote from its own policy — we surface it but don't fold it into the score, because classifying dense legal wording fairly is too error-prone.
- Maintenance & Ownership (15 points) — Is the extension still actively maintained? When was it last updated, is it on the current manifest version, and has ownership changed hands — a known route for a trusted extension to quietly turn malicious. Assessed from public store and listing signals.
- Community Reputation (20 points) — Store ratings and review counts, verified reports from readers, and repeated complaint patterns. Some platforms block automated collection, so we only count what we can actually verify.
Grades
- A (80–100) — strong safety signals on what we measured
- B (60–79) — generally safe with caveats
- C (40–59) — meaningful concerns; read the review before installing
- D (20–39) — serious concerns
- F (0–19) — avoid
Important: the score is the percentage earned on the dimensions we have actually verified — not all five. Every grade carries an "N/5" coverage chip; a grade based on fewer than 4 of 5 dimensions is provisional and will change as more dimensions are assessed. An "A · 2/5" means "clean on publisher identity and permissions so far", not "fully vetted".
The evidence rule
A score component does not exist on this site unless it is attached to at least one piece of documented evidence: a policy excerpt, a public source URL, a screenshot, or a record in our reports database. If we have no evidence, the section says "Not yet assessed" — we never fill gaps with guesses.
How we collect evidence
Every score on this site today is collected automatically from public records — the extension's own manifest and the permissions it declares, its Chrome Web Store, Edge Add-ons or Firefox AMO listing, the publisher's identity and verification status, and each vendor's own published privacy policy — and refreshed on a schedule. Publisher identity, permissions & access, data & privacy, maintenance & ownership and community reputation are all scored from these public sources.
Permissions & access is read straight from the extension's manifest — the same declaration the browser shows you at install time. Every permission point on an extension's page links to the exact permission or host-access entry we inspected; if the manifest doesn't declare something, we don't assume it. This reflects what the extension can do by declaration, not a behavioural test of the running code.
Maintenance & ownership is the hardest dimension to evidence from public records, so where we can't verify it from the listing or independent reports it stays "Not yet assessed" and the grade stays provisional. We don't run the extension or monitor its live traffic — we report only what the public record can verify, and we never claim a result we did not actually document.
Signals we show but don't score
Some checks are useful facts but not part of the 100-point score, so we display them separately on an extension's page: technical signals (the publisher's own website HTTPS, security headers, malware blocklists) and an impersonation check that flags listings using a well-known extension's name but published by a different developer. A new listing or a missing header doesn't make an extension unsafe — so these inform, but never decide, the grade.
What we exclude
We do not grade extensions for companion/NSFW services, trading or investment bots, or extensions that claim to diagnose or prescribe. These categories carry risks our rubric is not designed to measure.
AI assistance disclosure
We use AI to assemble review text strictly from our own structured data — every generated sentence maps back to an evidence record, and the mapping is stored for audit. AI never invents claims, scores, or evidence.