Why do browser extensions break websites, and how do you find the culprit?
Because extensions have deep access to the pages you visit — they can read, rewrite, block and inject content — so an extension doing its job can easily interfere with a site doing its job. The symptoms rarely point at the cause, which is why this is so frustrating to diagnose.
What extensions actually do to a page:
Block network requests, which is how ad and tracker blockers work — and blocking a request a site genuinely needs breaks functionality, commonly payment forms, embedded video, login flows and analytics-dependent features.
Inject or modify scripts and styles, which can collide with the site's own code.
Rewrite the page structure, which breaks scripts expecting particular elements.
Intercept form fields, which is what password managers do and why they sometimes fight with a site's own handling.
Alter headers or cookies, breaking authentication.
The classic symptoms of an extension problem: a page that works in a private window, works in another browser, works logged out, or fails only on one specific action such as checkout.
How to find the culprit efficiently:
Try a private or incognito window first. Most extensions are disabled there by default, so this takes seconds and tells you whether extensions are involved at all.
Disable all extensions, confirm the site works, then re-enable in halves rather than one at a time. This binary approach finds the culprit among twenty extensions in about five steps rather than twenty.
Check the extension's own controls before removing it — most blockers let you disable them for one site, which is usually the right answer.
Look at the browser console for blocked-request errors, which name the culprit directly.
What else produces identical symptoms, and should be ruled out:
Cached files and stale cookies, fixed by a hard reload or clearing site data.
Content blocking at the network level — a DNS-based blocker or router filtering, which follows you across browsers and devices and is therefore easy to misattribute.
VPN or corporate proxy interference.
Strict privacy settings blocking third-party cookies a site depends on.