But there's no proof that the published source code is the source code of the extension! You still have to just trust them
"Chrome Extension Source Viewer" I use it to audit every single app that I give permission to read each site.
EDIT: a better solution would be if the store itself allowed you to inspect the source that went into building the plugin. Then you would only need to trust the store itself, which you already do (when you trust the browser).
Or at least build it from the source code, like F-Droid.