"No script" is a must ... it allows you to give permisions to a website for java only as nessesary and blocks java until you give it the ok .
the others are
"Adblock" and its " Filterset G updater"
Also in general Firefox fixes its exploits ussually 1 to 2 days befor they get reported from other sources ... its still a pritty darn safe browser when coupled with a good AV program .
just beware of the microsoft hackers as vista arrives .. i bet alot of dirty deeds will be directed at Firefox to force people towards IE .
And dont even think for a second that vista will be safe ...