Personally, I removed any addon that's not open-source and thus subject to inspection by outside individuals, and even then, basically have limited it to a password manager and ublock origin.
I know 'you should read the code!' is very nonsense as a security measure, but if it's public the odds of SOMEONE reading it and finding out it's doing shady shit is substantially higher, and if shady shit happens, you just fork the code pre-shady and carry on.
Also, the workflow reliance on all these add-ons has always struck me as maybe not the best choice: it's just adding software to your browser that has access to data that's of value for black hats, marketers, and other unsavory types. Even if the dev doesn't sell you out, there's no guarantee that some otherwise perfectly innocuous behavior can't later be exploited due to some security issue.