AI Extension Security Data
Of 5 AI browser extensions we scanned, 80% request permission to read and change data on every website you visit, as of the 2026-07-31 scan. 4 request permissions broader than typical for their category, and across all scans we observed 425 distinct third-party domains contacted by these extensions.
This page is generated directly from our extension scan database and updates whenever an extension is re-scanned. We disclose manifest permissions, third-party data flow, and privacy-policy quality, and note where an extension requests more than its category typically needs — detailed in the security methodology. Domain counts are a static-analysis lower bound. Every figure below is stated as of the scan date shown; we report facts and a category-relative profile, never a bare verdict of "safe" or "avoid".
Permission profile distribution
As of the latest scans, the 5 scanned extensions break down as:
- Typical for its category: 1
- Broader than typical: 4
High-risk permissions requested
How many of the 5 scanned extensions request each high-risk permission, as of their scan date:
| Permission | Extensions requesting |
|---|---|
cookies | 3 of 5 |
nativeMessaging | 2 of 5 |
webRequest | 2 of 5 |
userScripts | 1 of 5 |
tabCapture | 1 of 5 |
Per-extension scan results
| Extension | Permission profile | All-sites access | 3rd-party domains |
|---|---|---|---|
| DeepL Translate | Broader than typical | No | 40 |
| Grammarly | Broader than typical | Yes | 32 |
| Merlin AI Assistant | Broader than typical | Yes | 25 |
| Sider: ChatGPT Sidebar | Broader than typical | Yes | 279 |
| Monica: ChatGPT AI Assistant | Typical for its category | Yes | 129 |
Cite this data
This dataset is free to cite with attribution (CC BY 4.0). Suggested citation:"AI Browser Extension Security Scan Data, AI Tools Insider (2026-07-31), https://aitoolsinsider.xyz/data". Machine-readable data is available at /api/extensions.json. See the security methodology for how this disclosure is produced.