Installing the real thing
Fake wallet extensions appear in official stores regularly, sometimes with convincing review counts. Install only from the link on the project's own site, and check the publisher and install count before adding it.
An extension that asks you to import a phrase immediately on install, before you have created anything, is the clearest possible warning sign.
Other extensions are part of your threat model
Any extension with permission to read page content can see what you are doing, and some can modify it. A compromised or sold-on extension — a common fate for popular free ones — inherits that access.
Audit your installed list. Remove anything you do not use. Consider a dedicated browser profile, or a separate browser entirely, used only for wallet activity.
Clipboard and page-level attacks
Clipboard hijackers replace a copied address with the attacker's. Overlay attacks render a fake approval dialog on top of a real page. Both are defeated by verifying the address in your wallet's own prompt rather than on the website.
The wallet prompt is rendered by the extension, not by the page, which is why it is the authoritative view of what you are about to sign.
Sensible limits
Keep the browser wallet as a spending account. Use a hardware wallet as the signer for anything significant — the extension then becomes an interface rather than a key store. Lock the wallet when you walk away, and keep the browser updated.
FBT Swap works with browser wallets and with hardware wallets through them. In either case the signing prompt comes from your wallet, and that prompt is the thing worth reading.