How the most popular Chrome extensions affect browser performance
debugbear.com
debugbear.com
I have observed that even though the memory usage as reported by developer tools under "JavaScript VM instance" stay rather stable in uBO[1] even after a lot of memory churning operations[2], the figure reported in Chromium's Task Manager keeps climbing up after each of these memory churning operation, and forcing garbage collection does not bring the reported usage down in the Task Manager.
There is something happening in Chromium's extension process (and outside the JavaScript VM in which the extension run) which may cause wildly various memory figures for even the same extension depending on how much memory-churning operations have occurred -- I wish Chromium devs would provide technical insights about this.
* * *
[1] Around 8 MB when using default settings/lists.
[2] For instance, repeatedly purging all filter lists and forcing an update.
The main takeaways seem to be that 1) extensions in general wind up massively increasing CPU time (by 5-20x) when loading "example.com", and 2) ad blockers wind up massively reducing CPU time (by 4-20x) when loading a "WCPO news article".
Which makes me happy that I use uBlock (edit: Origin, thanks below), and sad that I have to use LastPass.
HOWEVER -- I feel like both these metrics are potentially highly misleading, because CPU time isn't something the user directly observes -- it might be the limiting factor, or it might not affect the user experience at all (because the CPU usage is happening while waiting for further network resources that are even slower, or the CPU usage is happening after the page has visually finished loading all relevant content).
I'd be much more interested to see how extensions like Evernote or LastPass increase the time it takes for a real webpage (e.g. "nytimes.com") to finish painting the viewport not including ads, and similarly whether adblocking actually decreases the same -- or if all the advertising stuff really only happens afterwards. (Because sites are architected differently, you'd need to compute an aggregate score across a range of common sites.)
I just ran a few quick tests with the Top 50 extensions and an NYT article. The charts are ordered by largest median metric value.
https://gist.github.com/mattzeunert/de3c8aedd2936a34eeb88b62...
The Largest Contentful Paint (LCP) chart suggests an interesting phenomenon. Extensions like Dashlane and Evernote appear to slightly increase when that paint happens. These extensions load a large amount of code, but don't block the initial render.
Grammarly does not seem to push up LCP much. Its JS code runs before the page starts rendering, so maybe it is less likely to compete with other code later on.
Normally running code before the page renders would be bad, but if the page is network-constrained at that point it might soften the impact.
I recently switched from LastPass to 1Password because of the added latency from Lastpass. Lastpass adds about 70ms to first contentful paint on example.com. 1Password, on the other hand, runs after the painting is done so it doesn't block rendering. I polished up a blog draft I had lying around about switching to 1Password: https://joe.schafer.dev/passing-lastpass/
> I'd be much more interested to see how extensions like Evernote or LastPass increase the time it takes for a real webpage (e.g. "nytimes.com") to finish painting the viewport not including ads.
I reinstalled Lastpass to test on nytimes.com. It takes 58ms to evaluate onloadwff.js (the Lastpass entry point) before any content is rendered.
The only annoying thing is that LastPass requires the whole page to reload first - I don’t know why Chrome can’t load an extension into an already-loaded page.
I found what I was looking for, this is the article I ran the tests on: https://www.wcpo.com/news/education/higher-education/miami-u...
This can be very noticeable though, leading to sluggishness, stuttering scrolling, slowing down other tasks, increasing fan noise on laptops. uBO in my anecdotal experience may almost make a bigger positive impact in this fashion than simply at the initial render.
DuckDuckGo Privacy Essentials reduces the CPU time of the article page from 31s to just 1.6s. All other tested extensions also bring CPU time down to at most 10s.
It seems the single most important thing regarding Real Word Performance is a good content blocking functionality (not to mention other boons). Why don't browsers come with one by default?
They do rely on Google's advertising revenue for multiple $100M of funding; so they presumably don't want to be too successful in democratising ad-blocking.
Eich used to be a controlling influence on FF (as Mozilla CEO), since he was ousted he heads Brave browser which includes content blocking by default (and a content revenue model).
In short perhaps FF/Mozilla are curtailed by financial considerations.
[1] https://blog.getadblock.com/the-adblock-family-gets-a-new-ad...
For example, we had to rearchitect part of our site that was talking about marketing and advertising because various ad blockers decide any url pattern with '/advertising/' shouldn't be loaded.
That doesn't preclude the browser from making choices to protect privacy and security, but all sites should be treated equally (as Safari does with its tracking protection, for instance).
The reverse is also problematic, sites treat browsers (or even user agents) very differently. Why should browsers not do the same?
> Sites treat browsers (or even user agents) very differently. Why should browsers not do the same?
But isn't that exactly why browsers are now phasing out user agents? I'm all for that—I shouldn't have to fake my user agent in order for Slack to work in a mobile browser.
If there's a certain browser feature that a website needs, and the website detects this feature isn't present and changes its behavior accordingly, that's quite different!
Never seen that myself in my time using Brave.
FWIW I quite like the BAT and affiliate link model and was made aware of both prior to my install.
Just wondering, can browser extensions codesplit their bundles? If it's possible, then it is really disappointing to see these large companies loading huge bundles on initial load.
Gracias!
When I clicked on EditThisCookie it said there were no cookies when it was set to "when you click this extension", but when I changed it to "all sites" it showed me cookies.
Too bad.
On mobile, with slower networks and much worse CPUs, uBlock often completely changes the experience. (thanks Mozilla!)
I would note though that only example.com was examined (and apple.com in one test).
I also did not see information if tests were repeated, as no variance/stddev is given. I'd expect it to be pretty high.
I ran tests on example.com, apple.com, and a WCPO news article (for the ad blocker tests).
The biggest performance issue is that extensions just dump large scripts into pages indiscriminately. Most of the time extensions don't do anything differently based on the content of the page.
I also tested a WCPO news article to see the impact of ad blockers. I picked a local news website specifically because they contain a lot of ads. If a page doesn't have any ads the performance impact of an ad blocker will be slightly negative.
What my tests don't pick up is extensions that only run a certain domains. For example, if you run Honey on a shop they support I expect the CPU consumption to increase a lot more.
I wrote a similar article last year, which tests a few other pages as well: https://www.debugbear.com/blog/measuring-the-performance-imp...
The boxplot looks encouraging (as in, the variance doesn't seem too relevant for drawing conclusions)
I hope to use this as another source whenever marketing wants to add yet another tracker.
Firefox for iOS is not really Firefox.
Some Chromium based Android browsers do as well.
Yesterday I opened Chrome and received a warning that the Avira extension had been installed.
I certainly did not install it willingly. I'm pretty sure I didn't install any other software that sneakily bundled it recently, either - I mean, I'm 99.9% sure that I haven't installed _any_ software in the past week. So how why did it suddenly show up? I reported it to Chrome from the web extensions store. Highly unlikely that they'll do anything about it though.
If Avira has a pay-per-install program, I would say it's pretty likely that you're part of a botnet.
I ran every kind of virus test I could find about a month ago since I was getting weird display/jank issues. Couldn't find anything, and in the end I tracked the issues down to a windows display scaling error.
Any idea how I would go about testing for a botnet?
If something has driver / kernel level privileges it can trivially hide such traffic from any sniffer you have running.
This was a key driver behind writing Hyperscan (https://github.com/intel/hyperscan) which I used to work on when it was primarily used for network security (thousands or tens of thousands of regular expression rules for firewalls), but doing this for ad blocking seems pretty sensible too.
Looking at on-page CPU time for Evernote, 91% is spent just processing JavaScript or HTML. So I expect any benefit of a GPU to be minimal.
I also briefly mention it in the section on FCP, explaining why it makes sense for the extension to use render-blocking content scripts. https://www.debugbear.com/blog/2020-chrome-extension-perform...
I wonder who thought that would be a good idea... Sounds like something that could be significantly improved by compiling all patterns into a single statemachine.
Enpass has been great. The setup with Dropbox sync isn’t as quick but that’s just one per device. It’s very speedy and hasn’t gotten in the way at all.
I use the native desktop apps for them, previously LastPass and currently Bitwarden. The UX suffers a bit but you at least you gain some security.
This sounds interesting. A bit of searching is not providing much enlightenment - anyone care to explain in a bit more detail?
Also, if it is so fast, why aren't all the filter add-ons doing it?
Even though, and despite this added burden, I will point out that uBO is almost as performant as DDG Privacy Essentials as per this report.
Furthermore, uBO contains WASM modules but they are not used in the Chromium version of the extension since this would require to add a `wasm-eval` directive to uBO's extension manifest, something I prefer to avoid for the time being, I fear this would cause more lengthy validation of the extension by the Chrome Web Store.
* * *
[1] Able to enforce EasyList, EasyPrivacy et al.
It is a deep dive into how modern content blockers work and what kind of rules they have to enforce (they are usually much more complex than simple domains, though).
As a side node, I recently ran a small experiment and found out that around 90% or blocking from Easylist/EasyPrivacy/uBO lists can be done based on domain information only. But of course this leaves a lot of corner cases where sites might break or ads might still show, and ultimately more granularity is needed to address these cases.
This is used in hash tables, for example: https://en.wikipedia.org/wiki/Hash_table
Object properties in JS are mostly the same thing.
I guess other extensions can't do the same because they don't have a simple value to search in a whitelist, but rather a list of regex which must all be executed.
duckduckgo privacy essentials, ublock origin, privacy badger, and whatever built-in firefox has.
Perhaps this is overkill but they all cover slightly different things.
Edit: I realized that I sound like I’m bashing PB too much. PB is definitely better than nothing, and doesn’t break any sites, but there are better things you can do which make PB obsolete.
It doesn't even slow down the pages, the opposite is true here.