We all know (right?) that when installing third-party extensions for Magento/Adobe Commerce, code review is essential. Bad practices can severely impact your site’s performance, its uptime, and even your security. Publication on the Magento marketplace does not necessarily guarantee that an extension will not have performance implications on your site. Nor should it mean that you consider it exempt from your own code review processes, whether that be through your agency or internal developers. All third-party extensions should be reviewed. Also, per PCI DSS requirement 6.2.3, you are required to independently review code when feasible.