Glossary
Extension security, in plain English.
The concepts behind extension risk — what permissions grant, what obfuscation hides, what a bill of materials contains, and how trusted extensions change hands — each defined the way we use them when scoring extensions.
Extension permissions
What browser extension permissions like host access, tabs, and nativeMessaging actually grant, which ones are dangerous, and how to audit them before installing.
Updated September 29, 2026
Extension SBOM
What a software bill of materials for an extension contains, why bundled dependencies make extensions a supply-chain surface, and how to use an SBOM to triage risk.
Updated September 29, 2026
Obfuscation
What obfuscated code in a browser or IDE extension means, why publishers obfuscate, which patterns indicate malicious packers, and how scanners score it.
Updated September 29, 2026
Publisher takeover
How publisher and account takeovers turn trusted extensions into malware, the warning signs of ownership drift, and how to detect a compromised maintainer.
Updated September 29, 2026
Put the definitions to work
Every concept above shows up as concrete findings on the extensions we analyze. Search an extension you rely on, or browse a marketplace's risk picture.