For technical reasons beyond my control, SingleFile injects a (very small) script when the page loads even if you don't click on the button. It could also send any data to a third party server. Unfortunately, it is therefore impossible for me to technically and formally guarantee that SingleFile cannot behave maliciously.
Note however that the extension has the status "recommended" on Firefox and that it undergoes a manual code review by Mozilla at each update.