Skip to main content
All Terms Glossary

Browser Plugins and Extensions

Definition

Browser plugins and extensions extend the functionality of web browsers, such as adding ad-blocking or password management features. However, poorly coded or malicious plugins can inject scripts, capture keystrokes, and exfiltrate sensitive data. From a client-side security viewpoint, limiting the number of extensions installed, keeping them up to date, and reviewing their permissions can thwart many browser-based attacks. Security policies and corporate controls often restrict or whitelist certain plugins to avoid introducing vulnerabilities.

What plugins and extensions are

Browser extensions are small programs that add features to a browser, from ad blockers and password managers to shopping and productivity tools. Built on the WebExtensions API supported by Chrome, Firefox, and Edge, they can be granted permission to read and change the pages a user visits, access browsing history, intercept network requests, and store data. Older NPAPI plugins such as Flash and Java, which ran native code inside the browser, have been removed from modern browsers because of their poor security record; today the words plugin and extension are usually used interchangeably to mean an installed add-on. The deep access to page content that makes extensions useful is also what makes a bad one dangerous.

Why they matter for security

An extension with broad permissions effectively runs as the user inside every page. A malicious or compromised one can inject scripts, read form fields and session cookies, capture keystrokes, rewrite page content, and quietly exfiltrate data, behaving much like a man-in-the-browser attack that no server-side control can see. Extensions have also been caught stripping security response headers, weakening a site's own protections. The supply chain is a real risk: popular extensions get bought by new owners or hijacked through developer-account phishing, then pushed as an auto-update to millions of users who already trusted them. Because the code lives on the user's machine, the website being attacked usually has no visibility into it.

Defending against risky extensions

Defence is mostly about restraint and review. Install as few extensions as possible, prefer well-maintained ones from reputable publishers, and scrutinise the permissions requested; an add-on that wants to read data on every site should justify it. Keep extensions updated, remove ones you no longer use, and in managed environments use enterprise policies to allow-list approved add-ons and block the rest. Site operators should recognise a limit here: because extensions execute in the visitor's own browser, outside the page's control, a website cannot inspect or remove a user's extensions. Server-side and script-monitoring tools, cside included, see the scripts a site loads, not the add-ons a visitor has installed, so the last line of defence is the user's own hygiene.

Definition

What is the difference between a plugin and an extension?

Historically a plugin was native code, like Flash or a PDF viewer, that ran inside the browser to handle content the browser could not. Extensions are add-ons written with browser APIs that modify browsing itself. Native plugins have largely been retired for security reasons, so today the terms are often used to mean the same thing.

Definition

Can a website tell which extensions I have installed?

Sometimes, indirectly. Sites cannot list your extensions, but some detect specific ones by the resources they inject or the changes they make to a page, and that detection can even feed fingerprinting. A website cannot, however, control or remove your extensions; managing them is up to you or your organisation.

Got more questions

Talk to a security expert

We answer client-side security questions every day. Bring yours.

Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead