Others may wish to discuss the question, but if your add-ons come from the official NVDA add-ons site, you should have nothing to worry about.
Not so anymore, because the official NVDA add-ons site ( is now a marketplace hosting what I call "officially vetted" and "home grown" add-ons that have minimal vetting.

You are correct, though, that any officially vetted add-on should not be of any concern from a security standpoint (ignoring the issues that can arise from having password characters announced as one types them, and I would assume anyone using such an add-on would know when, and when not, to allow such announcement to take place).

