We Scanned 534,000 Chrome Extensions. Here's What We Found.

At Extension Auditor, we continuously monitor the Chrome Web Store. Not a sample. Not a snapshot. Every extension, every version, every change.

Our dataset currently covers 534,026 extensions and over 1.3 million versions with parsed manifests. Here's what the data reveals — and why it should concern every security team.


The Numbers

42% of All Extensions Have Been Removed

Of the 534,026 extensions we track:

  • 294,050 are currently active
  • 225,677 have been removed (obsolete/taken down)

That's a 42% removal rate. Nearly half of all extensions that were once available — and potentially installed on your employees' browsers — no longer exist in the Chrome Web Store. Some were abandoned. Some were policy violations. Some were malicious.

The question for your security team: do you know which ones your employees installed before they were removed?

4.7 Billion User Installs

The active extensions in the Chrome Web Store represent a combined 4.7 billion user installs. That's not unique users — it's total install count across all extensions. The attack surface is enormous.

11% of Active Extensions Request Access to All Your Data

Out of 226,550 active extensions with analyzed manifests:

  • 25,709 (11.3%) request access to all URLs — meaning they can read and modify every webpage you visit
  • 53,066 (23.4%) request the tabs permission — they can see every tab you have open
  • 9,693 (4.3%) request access to your cookies — including session tokens
  • 8,872 (3.9%) use webRequest — they can intercept and modify your network traffic

Let that sink in: 1 in 9 active Chrome extensions can see everything you do on the web.


What This Means for Enterprise Security

The Permission Problem

When an employee installs an extension that requests <all_urls>, they're granting it the same level of access as a man-in-the-middle attack — except the user clicked "Add to Chrome" voluntarily.

Most enterprises have no policy governing this. No review process. No monitoring.

The Ghost Extension Problem

Extensions that get removed from the Chrome Web Store don't automatically uninstall from users' browsers. If your employee installed an extension that was later taken down for malicious behavior, it's likely still running on their machine right now.

The Update Problem

Extensions auto-update silently. A legitimate extension today can push a compromised update tomorrow — exactly what happened in the Cyberhaven breach. Without version-level monitoring, you won't know until it's too late.


The Data Doesn't Lie

Browser extensions are one of the largest unmonitored attack surfaces in enterprise security. The data is clear:

  • Hundreds of thousands of extensions have been removed for a reason
  • Tens of thousands of active extensions have dangerous permission combinations
  • Billions of installs mean billions of opportunities for exploitation

The first step is visibility. You can't secure what you can't see.


This data is from Extension Auditor's continuous monitoring of the Chrome Web Store. Updated daily. extensionauditor.com