Stop putting your API keys everywhere ...
How can an extension change hands with no oversight?