I can not empathize this more! Using a browser extension that can read the data on steemit.com is a huge risk and should not be treated lightly. If you can (I know Firefox supports it) disable auto update or better, install it from the source I reviewed.
We are currently having multiple scamming attempts and a browser extension that steals your keys is definitely a possibility. And don't take anyone's word for it that an extension is secure. Humans make mistakes and a security audit is no protection.