A delisted extension is one that no longer remains available in a marketplace but is still installed on endpoints. That state matters because removal from the store does not automatically remove existing copies, so the extension may continue to run and expose users until it is explicitly remediated.
Expanded Definition
A delisted extension is a browser, application, or platform extension that has been removed from an official marketplace or store but still exists on one or more endpoints. The important boundary is that delisting changes distribution status, not local presence: if the extension was already installed, it may continue to load, retain permissions, and interact with data until administrators or users remove it.
That distinction is easy to miss because many teams assume store removal equals neutralisation. It does not. Delisting usually indicates a policy, security, support, or compliance decision by the platform owner, but the installed copy can remain operational unless there is a separate enforcement mechanism on the device. For security teams, the term sits closer to software inventory and endpoint governance than to simple catalog management.
A common misunderstanding is treating delisting as a cleanup event. In practice, it is often an intelligence signal that requires endpoint discovery, version review, and ownership checks. For platform governance and software trust decisions, the relevant question is not whether the listing disappeared, but whether the extension is still active anywhere it should not be.
Examples and Use Cases
Delisted extensions appear in ordinary enterprise environments in several ways:
- A browser extension is removed from a public store after review concerns, but employees who installed it earlier still have it running.
- An internal productivity extension is delisted during migration to a new version, while unmanaged endpoints keep the old copy in place.
- A security team identifies an extension that is no longer supported by its publisher, then checks whether it still has access to sensitive pages or session data.
- An organisation uses endpoint management to compare installed extensions against an approved list and flags delisted items for removal.
- A platform operator delists an extension due to policy violations, and IT must decide whether to block, quarantine, or replace it.
The operational tradeoff is straightforward: store visibility is useful for discovery, but it is not a reliable control plane for removal. If endpoints are not centrally managed, delisted extensions can persist indefinitely, especially on personal or exception-based devices.
For governance teams, this often becomes a reconciliation exercise between marketplace status, installed inventory, and business ownership. The extension may be unavailable to new users, yet remain a live dependency for existing ones.
Security Implications
Delisted extensions create residual exposure because the security event is often only half complete. Even after removal from the marketplace, the installed extension may still hold broad browser permissions, access page content, or interact with authentication flows. If the extension is unsafe, unsupported, or malicious, those permissions can continue to create data leakage, session abuse, or supply-chain risk on already-infected endpoints.
The failure mode is usually inventory blindness. Security teams may assume a delisting action has reduced exposure, while the actual attack surface remains until the extension is explicitly removed or disabled. That gap can leave organisations with unmonitored code running inside the browser, which is especially problematic when extensions can read content, modify pages, or observe user activity.
In practice, the observable symptoms are uneven: some endpoints lose the extension quickly, while others keep it for weeks or months. That makes endpoint scoping, ownership assignment, and remediation tracking critical. The security question is not just whether the extension is bad, but whether any managed or unmanaged device still trusts it.
Domain and Governance Relevance
In identity and access environments, a delisted extension matters because browser extensions often sit close to login flows, tokens, and user sessions. That proximity means a legacy or unsupported extension can affect credential handling, page instrumentation, or access to identity portals even when it is no longer available for fresh installs.
From a governance perspective, delisting should trigger a lifecycle decision: remove, replace, restrict, or formally approve an exception. The term is therefore relevant to software asset management, endpoint control, and trust governance, not merely to marketplace hygiene. Where extensions support SSO, password management, session helpers, or workflow automation, the governance bar is higher because the extension can influence identity-bearing activity.
For NHIMG, the practical interpretation is that delisting is only meaningful when paired with endpoint visibility and explicit offboarding. A removed listing without removal on devices leaves a live software identity in circulation, which can outlast the platform decision that created the delisting.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 2.1 — Inventory and Control of Enterprise Assets | Delisted extensions remain installed assets that need discovery and tracking. |
| 2.3 — Address Unauthorized Assets | Delisted copies can persist as unauthorized software after store removal. | |
| 4.1 — Establish and Maintain a Secure Configuration Process | Extension delisting should feed configuration enforcement on browsers and endpoints. | |
| Recommendation — Inventory installed extensions and remove delisted items from managed endpoints. Detect and quarantine delisted extensions that persist outside approved software. Enforce browser configuration baselines that block unapproved extensions. | ||
| NIST CSF 2.0 | ID.AM-1 — Physical Devices and Systems Inventoried | Installed extensions must be visible in asset inventories to spot delisted copies. |
| PR.AC-4 — Access Permissions and Authorizations Managed | Delisted extensions may still retain permissions after marketplace removal. | |
| PR.IP-1 — Configuration Management Policy and Processes | Delisting requires a controlled process for removal and exception handling. | |
| Recommendation — Map extension inventory into endpoint asset records and reconcile delisted entries. Revoke extension permissions when an extension is delisted or unsupported. Apply configuration management to remove or disable delisted extensions consistently. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org