the code that put iframe is the same there is in condenser, with the same security features.. So i guess, if there is a problem here, there is also in condenser.
For what I see, everything works fine in both condenser and in the extension ;)
If users prefer not to risk, just disable the markdown editor extension in the settings. Or trust youtube and others when you paste their links. I don't believe this is really a "security issue". People should hack into youtube and other big websites to take advantage of this...
Regarding the password, I'm taking all the precaution possible ;) I have ALWAYS strong and different passwords in all my accounts.
BTW, I always suggest to install the code manually by downloading from the repository.. that is the safest way to use this extension