The researchers found that a huge number of websites — about 15% of more than 7,000 they looked at — store sensitive information as plain text in their HTML source code.
The problem is passwords being exposed in plain text. I already assume that my browser extensions can see everything I do, which is why I only use a couple of open source extensions with solid reputations.