A practical audit of your browser extensions
Check extension permissions, site access and publishers, then remove unnecessary add-ons without losing data or breaking your workflow.
An extension installed for a single task can remain in your browser for years. Its icon disappears into a menu, but the permission you granted may still matter every time you open a page.
An extension audit is not a hunt for a perfect review score. It is a decision about which extra software belongs inside your browser and what access each piece needs. You can do a useful first pass without installing another scanner or uploading your extension list anywhere.
Keep your work practical: identify the extension, check its purpose, review access, save any necessary data and remove what you no longer use.
Start with the complete installed list
Open the browser's extension-management page rather than judging by toolbar icons. Hidden icons do not mean disabled software. In Chrome, the route is Extensions, then Manage extensions; Google's management guide explains the available controls.
For each item, write down its name, publisher and reason for keeping it. Group the results into three piles: used regularly, used occasionally and not recognized. Do not assume an unfamiliar item is malicious; it may belong to an employer, accessibility tool or password manager.
On a managed computer, ask the administrator about required extensions instead of attempting to remove policy-installed software. On a personal computer, an extension you cannot identify deserves investigation before you grant it additional access.
Record the browser profile too. You may have different extensions in your personal and work profiles, and removing one copy does not necessarily settle the other.
Read permissions as descriptions of access
“Read and change data on websites” is a meaningful permission, not just a line to click past. It may be necessary for a tool that modifies page content, but it is a broad capability for a simple utility.
Mozilla's extension permission guide explains the kinds of access Firefox extensions can request. Use that documentation to translate a permission into a practical question: can this extension see pages, downloads, tabs or clipboard data involved in my normal work?
Consider the task and the scope together. A tool that formats code on one development site has a different need from an accessibility tool designed to work across the web. Broad access is not automatically evidence of abuse, but it should have a clear purpose.
Avoid judging an extension only by its name. “Privacy,” “security” or “helper” in a title does not tell you how permissions are used or whether the publisher still maintains the software.
Narrow website access where the browser allows it
Chrome offers site-access choices for supported extensions, including access when selected, on particular sites or on all sites. Review the details page and choose the scope that matches your actual use.
For an occasional page tool, start with access only when you invoke it. For a tool tied to one service, specify that service where possible. Then visit the relevant site and test the feature you need.
Some capabilities, including certain proxy or VPN permissions, are not fully limited by ordinary website-access settings. Read the browser's description rather than assuming one dropdown constrains every function of the extension.
Also review private-window access. Granting an extension access to private browsing is a separate decision. The private browsing guide explains why an extension should not be treated as invisible simply because the window is private.
Check the publisher without trusting one signal
Open the extension's store listing from its management page. Compare the publisher, support link and privacy information with the developer's official website. Look for a clear explanation of what is collected and which features require an account or remote processing.
A recent update can be useful evidence that a project is maintained, but it is not proof of safety. A large installation count or a high rating is not proof either. Read recent reports for specific, repeatable issues such as unexpected redirects or changes in requested permissions.
Avoid following a sponsored search result to “update” an extension. Use the browser's own update process or the official store. If the publisher has changed, review the new ownership and policy before treating the extension as the same product you originally chose.
For a sensitive workplace task, the organization's approved-software list should take priority over a personal impression from reviews.
Save what you need before removing anything
Some extensions store notes, settings, templates or saved sessions. Check whether removing the extension also removes local data and whether that data is synchronized elsewhere.
Export through the extension's documented process when necessary. Store the export appropriately; a password-manager export or session file may be highly sensitive. Do not move such a file into a public downloads folder just to complete the cleanup faster.
Disable uncertain extensions one at a time and repeat the tasks you use them for. This helps identify which one supplies a feature you still need. Once you are confident, remove unused items rather than leaving a growing collection disabled indefinitely.
For a password manager, follow a separate password-manager setup and migration plan. Do not remove the only working access method before confirming the replacement and its recovery options.
Replace one-off extensions with narrower workflows
A simple task may not need a permanent extension. A built-in browser feature, a local desktop application or a browser tool used only when needed can be easier to reason about.
The Productivity directory includes utilities for documents, images and text. Check the individual tool's processing model before giving it a file. A webpage is not automatically private merely because it avoids installation.
For documents containing personal information, read how to choose an online file converter. That guide separates local processing, remote uploads and output checks so that removing an extension does not simply move the exposure to another service.
Avoid replacing one unused extension with three new ones promising a comprehensive cleanup. The purpose of the audit is a smaller, understandable set of tools.
Test the final browser, not just the extension count
After removal, restart the browser and try the tasks that matter: filling a login, joining a call, opening a work application and downloading a known file. Check whether homepage, search-engine or new-tab settings changed unexpectedly.
If suspicious behavior persists, review the browser's official troubleshooting steps and installed applications as well. An extension list is only one part of the system. Do not assume that reaching a low number proves the browser is clean.
Keep a note of the extensions you intentionally retained and their purpose. Review that list when a permission request changes or when your work changes. A short list with a reason beside each item is a better result than an impressive-looking collection of tools you cannot explain.
Sources and further reading
- Google Chrome Help: Install and manage extensions Consulted 28 September 2026.
- Mozilla Support: Permission request messages for Firefox extensions Consulted 28 September 2026.
Consult the linked documentation for current details. Settings, availability and interface labels may change.
Spotted something that needs correcting? Send a correction with this article’s title and the relevant source.