Are proxy browser extensions safe? What they can see, and how to check
Are proxy browser extensions safe? What one can see, how to read its permissions, open source versus closed, extensions from providers, and a checklist.
A proxy browser extension is exactly as safe as the people who publish it, because its job requires seeing everything. To switch your proxy and answer its login, it needs the browser's proxy permission, access to every site and a hook into every request. A trustworthy one is open source, maintained, installed from its developer's own link and asks for nothing beyond that job.
That is not a reason to avoid them. FoxyProxy has been around since 2006, both it and SwitchyOmega are open source, and a browser without an extension has its own costs. It is a reason to know what you are granting, and to check it in the five minutes before you install rather than after. This post walks through what a proxy extension can see, how to read its permissions, what open source does and does not buy you, the special case of extensions handed out by proxy providers, and the alternatives that need no extension at all.
What a proxy extension can see
Whoever decides where your browser's requests go can, in principle, send them anywhere. Browsers treat the permission that way. Chrome's install warning for the proxy permission reads "Read and change all your data on all websites." That warning appears for the honest switcher and the dishonest one alike, so it tells you what is at stake, not who is asking.
Here is what the two best-known switchers request, read from their own manifest files:
| Permission | FoxyProxy 9.8 | SwitchyOmega 3 (3.5.2) | What it allows |
|---|---|---|---|
proxy |
yes | yes | Choose the route for every request |
| Access to all sites | yes | yes | Act on requests to any address |
webRequest, webRequestAuthProvider |
yes | yes | Watch requests and answer a proxy's login prompt |
tabs |
yes | yes | Chrome warns "Read your browsing history" |
storage |
yes | yes, plus unlimitedStorage |
Keep settings, proxy logins included |
downloads |
yes | no | Chrome warns "Manage your downloads"; used for settings backups |
notifications, contextMenus |
yes | contextMenus only |
Pop-up notices and right-click entries |
alarms |
no | yes | Run scheduled tasks |
browsingData, privacy |
optional, asked when used | no | Clear site data; change WebRTC settings |
Neither injects scripts into the pages you visit, and neither asks for cookies or history. That is roughly the minimum a full-featured switcher needs. The login part matters most: an extension that fills in your proxy username and password does so by watching requests for the proxy's challenge, which is why webRequest and all-site access come together.
Then there is the password itself. Whatever you type into an extension's login fields sits in that extension's storage, where the extension can read it. If you turn on settings sync (FoxyProxy's Enable Sync covers "global exclude, proxies & patterns"), the same data travels through your browser account too. Use a proxy login for the proxy only, never a password you use anywhere else.
How to read an extension's permissions
Before installing, the store's install prompt lists the warnings, and an open-source extension publishes its manifest.json, which lists every permission by name. After installing:
- Chrome and Edge: open
chrome://extensionsoredge://extensionsand click Details on the extension. The page shows what it holds and which sites it can reach, and the address bar shows its ID. - Firefox: open
about:addonsand select the extension to see the permissions it holds. Firefox also lets extensions declare what data they collect; FoxyProxy's manifest declares none.
Look for permissions that the job does not explain. A proxy switcher has no obvious need for cookies, which together with all-site access can read your sign-in cookies, for history, which Chrome describes as "Read and change your browsing history on all signed-in devices", or for scripts injected into every page. None of these proves bad intent; each deserves a reason you can find in the extension's own documentation.
Chrome also lets you narrow an extension's site access. With a proxy extension that answers logins, narrowing it tends to break the logins, so the lever that matters here is not the toggle but the choice of who you trust with it.
Open source versus closed
Open source does not make code safe. It makes it checkable. FoxyProxy publishes its source under GPL-2.0, and SwitchyOmega 3 under GPL-3.0, both on GitHub with public issue trackers. You can read how FoxyProxy stores logins (one per host and port) or follow SwitchyOmega 3's long-open report about Chrome asking for a password the extension already holds. The store package is built separately from the repository, so "open source" means anyone may look, not that someone has.
Maintenance matters as much as openness. The original SwitchyOmega shows why. Its author has stated that the project is no longer maintained, and Chrome has disabled it because it never moved to the current extension format. The Firefox copy still runs to a degree, and receives no fixes. A tool that sees all your traffic and no longer gets security updates is a risk even if it was fine on the day you installed it. Its maintained fork, SwitchyOmega 3, which our SwitchyOmega guide covers, is the version to use today.
With a closed-source extension, you are relying on the publisher's reputation, its privacy policy and the store's review, and you cannot check any of the three yourself.
Extensions bundled by proxy providers
Some proxy providers offer their own browser extension, usually with your account login built in and a list of locations to click through. Convenience is real. So is the fact that the provider's code then runs inside your browser, on every site, with everything the table above describes.
Before installing one, ask the same questions you would ask of any extension, plus a few:
- Does it need more than the switcher permissions above? Page scripts, cookies or history access deserve an explanation.
- Does it sign you in to your provider account, and does it report usage back? Its privacy policy should say what it sends and when.
- Is the source published, or at least the manifest?
- Do you need it at all? Any HTTP or SOCKS5 proxy works in a general-purpose switcher or in the browser's own settings. A provider-specific extension is rarely the only way in.
Lookalikes in the store
Popular names attract imitations, and a store search returns every listing that uses the name. Install from the link the project itself publishes, then check the ID. FoxyProxy's built-in help lists its IDs: gcknhkkoolaabfmlnjonogaaifnjlfnp in Chrome and [email protected] in Firefox. SwitchyOmega 3's README links its Chrome listing, pfnededegaaopdmhkdmcofjmoldfiped. The ID appears in the store address and on the extension's details page. If yours differs, remove it.
Safer ways to get the same result
You can often skip the extension entirely:
- Firefox's own proxy settings, in a separate Firefox profile used only for proxied browsing. Of Firefox, Chrome and Edge, only Firefox has a proxy form of its own, and it asks for the login in its own prompt, which Firefox's password manager can remember, rather than handing it to an add-on. The browser guide shows the panel.
- System settings, when the whole machine should use the proxy. The Windows and macOS guide covers both, with the warning that every app that honours the setting follows it.
- A separate browser profile for the extension. Extensions are installed per profile, so a profile kept for proxied work limits what the extension sees to that work.
- No browser at all. Scripts and bots take the proxy in code, as every language guide on this site shows.
- An IP allowlist instead of a password. If the proxy lets your address in without a login, no proxy password has to sit in any extension.
What no extension can fully fix
A browser proxy carries the browser's web requests. WebRTC, used for calls and some page features, can try other routes and reveal your own address. FoxyProxy's Limit WebRTC option changes the browser's WebRTC policy for that reason; its Disable Non-Proxied setting, according to FoxyProxy's help, exposes neither your public nor your local address. Check the result on a WebRTC test page rather than assuming.
A checklist before you install
- Installed from the link the developer publishes, with the ID it lists.
- Updated recently, and not declared abandoned by its author.
- Source or at least the manifest published, with an active issue tracker.
- Permissions limited to the job: proxy, site access, request and login handling, storage, tabs. Anything else has a reason you can find.
- A proxy login used for nothing but the proxy.
- Settings sync off, unless you want the login in your browser account.
- One proxy extension at a time. Two fight over the setting, and the browser lets only one win.
- Removed when you stop using it.
Quick answers
Can a proxy extension see my passwords? One with request access and all-site access can read the addresses, headers and form data your browser sends, and that includes what you submit in a login form. https protects the trip between your browser and the site, not what happens inside the browser, where the extension runs. Trust it accordingly.
Is FoxyProxy safe? It is open source, maintained, and asks for the permissions a switcher needs and no more. Install it from its official listing and check the ID.
Is SwitchyOmega safe? The original is unmaintained and disabled in Chrome. Its maintained fork, SwitchyOmega 3, is open source and asks for a similar, small set of permissions.
Where ProxyPanda fits
Our proxies speak plain HTTP and SOCKS5, so they work in FoxyProxy, in SwitchyOmega's maintained fork, in Firefox's own settings, or with no browser at all. Setup for each is in the FoxyProxy and SwitchyOmega guides. The dashboard's IP allowlist lets an address connect with host and port alone, so you can keep the password out of the browser entirely. For the wider question of who to buy from, choosing a safe proxy provider has the questions worth asking first.