How much time on average do you spend on reviewing the source code of a given browser extension before you install it? Also, how do you make sure that the published source code is 1:1 with what you are actually installing?
So simply git clone the extension, have a quick look at the recently opened (and closed) issues/PRs for any red flags, git checkout the most recent tag, and load it as unpacked.
Then you are guaranteed to have the source code of exactly the extension you're running, and have done a reasonable amount due diligence for malware.
And if you're interested at any point in the future you can do a code review.
It's a simple strategy. Here's an example: https://github.com/igrigorik/videospeed