Security question: Is a web extension safe if it is installed but if you're not using it at the moment? For example, if I were logged into my bank's website and I did not click the SingleFile button in the extension toolbar, could it still theoretically collect info from my bank's webpage or do other actions?
I'd like to use SingleFile and have no reason at all to distrust it, but I'd like to understand the security impact of installing lots of web extensions. How do people handle security risks like that? Do you run a separate vanilla browser with no extensions for sensitive tasks?