Neither Vimium nor SurfingKeys don't hold a candle to KeySnail because back in the days add-ons worked you could control the browser's chrome as well as a bunch of other non-HTML elements.
Today, you cannot even use browser extensions to close a browser window if the page didn't load in it.
These tools were intended for "power users", who could establish for themselves if the piece of code they want to use is doing something malicious or not. Also being an easy way to extend the browser without a need to recompile it and a need to understand a huge project with a ton of infrastructure... flushed down the drain.
This reminds me about how Alan Key said in one of his interviews that if a motorcycle was invented today, it would've been outlawed right away due to safety concerns.
Curious to discuss if there is a way to trust these extensions without establishing ourselves that the code is not harmful.
Of course you need to do some due diligence, but it isn't anywhere near as taxing as you seem to think.
Security is worthless if it prevents you from doing useful things. Given a choice between a chance of security breach and not being able to do the useful thing at all, in the circumstances like using a Web browser, I'd definitely choose to have the useful thing w/o security.
And assessing risk of freely available open source software is still difficult, you either rely on all the authors being standup citizens, or on the bulk of the reviewers to be truthful and knowledgeable.
* The extension has a genuine need for the permissions
* It’s an old extension at this point, with known maintainers with names and faces
* I really, really want the features