Don’t Auto-Update Safari Extensions
Lex Friedman (via John Gruber):
Thus, the mythical A Decidedly Un-Evil Extension, which could provide the definition of any word you double-clicked on, could seem noble and safe. After a few months of swelling popularity, the extension’s nefarious creator could update the extension with <iframe> evilness, and start gathering personal information about you, from the webpages you visit.
With auto-updating, you probably wouldn’t know that the extension had been updated. Even with manual updating, you have no way of knowing whether the new version has been vetted for security.