Add-on signing in Firefox

Revision Information
  • Revision id: 94019
  • Created:
  • Creator: Joni
  • Comment: simplified second to last sentence
  • Reviewed: Yes
  • Reviewed:
  • Reviewed by: heyjoni
  • Is approved? Yes
  • Is current revision? No
  • Ready for localization: No
Revision Source
Revision Content
This applies to newer versions of Firefox (version 39 and above).

Add-ons that change your browser's settings without your consent have become increasingly common. Some add-ons add unwanted toolbars or buttons, change your search settings or inject ads or malware into your computer. (Learn more about search hijacking.)

How does add-ons signing protect me?

Firefox protects you by allowing only digitally signed or verified add-ons in your browser. While Firefox currently has a blocklist system, it is increasingly difficult to track and block the growing number of malicious add-ons. The add-ons signing process requires developers to follow Mozilla Developer guidelines to ensure that their add-ons are safe.

Developers: Learn more about add-ons signing guidelines at Mozilla Developer Network.

What types of add-ons need to be signed?

Extensions (add-ons that add features to Firefox) will need to be signed. Themes, language packs and plugins do not need to be signed.

Where would I encounter unsigned add-ons?

Add-ons installed through the official Firefox Add-ons site undergo a rigorous review process before they are published. These add-ons are signed and verified.

When you install an add-on through another website, Firefox checks to make sure that the add-on has been digitally signed before you can install it.

The add-ons signing process only targets malware and browser hijacking. It does not control or censor the content that you choose to see.