Extension is really just another web page with more system privileges than normal web pages. It can communicate with servers and peek your current webpage’s data without your permission. From this perspective it’s less secure than a normal webpage.
The narrative on Nostr is if you centralize your private key risk to a single extension that you trust, then you don’t have to trust individual Nostr clients. Meaning you still need to pick one extension that you trust. Extensions are not intrinsically safer.