3 answers
As someone who actively uses online services (from client booking to ordering stuff for my morning runs), I agree - convenience is nice and all, but it's important to choose extensions from trusted companies with a good reputation for security, not just install whatever comes first.
Personally, I only use ones that have independent security audits and encrypt data on the client side, rather than storing passwords on the extension's servers.
It's not quite that simple. Yes, extensions from major companies are usually safer, but browser extensions themselves are inherently designed to access a bunch of data - your history, cookies, whatever text you've typed. So even a good password manager is potentially vulnerable just because it operates in the browser. That doesn't mean you shouldn't use one, it just means you need to understand that you're giving the extension a certain level of trust.
The main thing is to check the company's reputation: how long have they been around, do they get independent security audits, how do they respond when vulnerabilities are found. Well-known managers like Bitwarden, 1Password, or Dashlane undergo regular checks. But even with them, it makes sense to enable two-factor authentication for the password manager itself - that significantly boosts your protection.
And one more thing: not all extensions are created equal. Some store passwords locally and just sync them in encrypted form, others keep data on their servers. Read up on exactly how your chosen option works before you install it. If you picked a trusted product and set up two-factor authentication, the risk is minimal.
The main thing is to choose managers only from well-known companies with open source code or at least independent security audits.
I've been using a popular extension for a long time without any problems, but when friends recommended some obscure plugin, I checked the reviews and ratings in the extension store - the comments had serious security concerns, so I avoided installing it. If an extension has millions of users, regular updates, and the reputation of a well-known brand, then the risk is minimal, but you shouldn't blindly trust it anyway - still check your passwords and account activity periodically.
Your answer
Log into answer.