• edric@lemm.ee
    link
    fedilink
    arrow-up
    34
    ·
    1 year ago

    This is more about developers carelessly integrating 3rd party code into their extension without verifying if it’s malicious. People should be able to spot this if it’s a widely reviewed open source extension. At the end of the day, you have to make sure you trust the developer that they have sound programming skills and decent security knowledge to not be duped into adding code from an untrusted source just because of an offer for income.