Is Coupert - Automatic Coupon Finder & Cashback safe?

Medium risk

Coupert is medium risk. On navigating to a shopping page, Coupert collects the URLs of every open tab and sends them to its servers. Dynamic analysis captured a POST to coupert.com/api/v2/ext/saveUserTabV2 with all open tabs' {url, id}, no prompt.…

Coupert.comv6.70.59Chrome Web Store
45Risk
Who publishes it

Coupert Science LLC - 3 other listings from the same operator, 2 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Coupert.com
Declared legal entity
Coupert Science LLC
Registered address
8 The Green, Ste A, Dover, DE 19901, US
Registered contact
Jimmy Zhao

Same store account

3 other listings published from this account, 87k+ users between them. 2 of them carry a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

All open tab URLs sent to Coupert server on every navigation

On navigating to a shopping page, Coupert collects the URLs of every open tab and sends them to its servers.

Dynamic analysis captured a POST to coupert.com/api/v2/ext/saveUserTabV2 with all open tabs' {url, id}, no prompt.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You navigate to any website.

The extension did this

The extension collects the URLs of all your open tabs and transmits them as a list to Coupert's server.

This includes tabs you have open in other windows, incognito or not, any tab visible to chrome.tabs.query({}).

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.coupert.com/api/v2/ext/saveUserTabV2
Coupert server returns {code: 0, data: {...}} on success.
Headers
Content-Typeapplication/json
Body
{
  "tab_data": [
    {
      "url": "https://www.amazon.com/s?k=laptop",
      "id": 2075718804
    },
    {
      "url": "https://mail.google.com/mail/u/0/#inbox",
      "id": 2075718805
    },
    {
      "url": "https://en.wikipedia.org/wiki/Laptop",
      "id": 2075718806
    }
  ]
}
03EvidenceCODE COMPARE
The code that does this

Background service worker: collecting all open tabs (background.js, ~line 73130)

What it actually does
// wZ(): collect all open tabs and send to saveUserTabV2
async function wZ() {
  try {
    let tabs = await chrome.tabs.query({});          // ALL open tabs, no filter
    if (!tabs) tabs = [];
    const tabData = tabs
      .filter(t => t.url)                            // drop tabs with no URL
      .map(t => ({ url: t.url, id: t.id }))          // keep only url + tab id
      .slice(0, 20);                                 // cap at 20 tabs
    const result = await El(tabData);               // POST to saveUserTabV2
    if (result?.code === 0) return result.data;
    return {};
  } catch (e) { return ''; }
}

// El(): the actual POST call
function El(e) {
  return apiPost('/ext/saveUserTabV2', {
    method: 'post',
    data: { tab_data: e }
  });
}
04EvidenceFIELD TABLE
Fields sent per tab in the saveUserTabV2 payload
FieldValueWhy it matters
Tab URL
https://www.amazon.com/s?k=insulin+pumpThe full URL of each open browser tab, including query strings that may contain search terms or session tokens.
Tab ID
2075718804Chrome's internal numeric identifier for each tab, used by Coupert to correlate tab snapshots over time.
05EvidenceTHIRD PARTY LIST
Destination receiving all open tab URLs
  • www.coupert.com

    Coupert's primary API server. Receives the full open-tab URL list per user session via /api/v2/ext/saveUserTabV2.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Coupert Sends Your Amazon Cart Contents to Its Own Server Automatically

With Coupert installed, opening your Amazon cart makes the extension read every item's product ID and price and send that list to pcp.coupert.com, without a cashback click.

This runs on ordinary navigation, not only on request.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open your Amazon shopping cart while Coupert is active.

No cashback button, coupon search, or other explicit action is involved.

The extension did this

Coupert reads the product IDs and prices of everything in your cart and sends them to its own server.

The background service worker fires the request roughly 5 seconds after the cart page finishes loading.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://pcp.coupert.com/api/v1/product/superCashback?guid=3d7ac981ecd77de466f2d5f49e0b4ea5
200 OK, JSON response included an affiliate out_url for the cart's contents
Body
{
  "domain": "amazon.com",
  "position": "cart",
  "skus": [
    {
      "sku": "B088N7KPZN",
      "price": ""
    },
    {
      "sku": "B088NLK5P5",
      "price": ""
    },
    {
      "sku": "B088NRLMPV",
      "price": ""
    }
  ]
}
03EvidenceCODE COMPARE
The code that does this

The background handler that fires the POST whenever a super-cashback lookup message arrives

What it actually does
// background.js — message router registered on extension startup
messageBus.backgroundPage().on(
  "pcp_api:product.super_cashback.get",
  async (message, sendResponse, sendError) => {
    try {
      const { content: skuPayload = {}, tab = {} } = message;
      const { id: tabId = "" } = tab;

      // POST the collected SKU/price list straight to Coupert's own API
      const result = await postToCoupert({
        endpoint: "/product/superCashback",
        method: "post",
        tabId,
        data: skuPayload,   // { domain, position, skus: [{ sku, price }, ...] }
        isEncrypt: true,
      });

      sendResponse(result);
    } catch (err) {
      sendError(err);
    }
  }
);

// postToCoupert() resolves to https://pcp.coupert.com/api/v1 + endpoint,
// attaches a per-install "guid" query param, and encrypts the body only
// when the extension's remote config has the "pcp.encryptSwitch" flag on.
04EvidenceFIELD TABLE
What each superCashback request carries
FieldValueWhy it matters
Amazon product ID (ASIN)
B088NRLMPVTells Coupert's server exactly which products you're browsing or have in your cart.
Cart position
cartTells the server this item came from your shopping cart specifically, not a search result.
Retailer domain
amazon.comIdentifies which store you were shopping on when the request fired.
Installation ID (guid)
3d7ac981ecd77de466f2d5f49e0b4ea5A persistent identifier tied to your browser install, letting Coupert link every cart/search request back to the same device over time.
05EvidenceTHIRD PARTY LIST
Where the cart data goes
  • pcp.coupert.com

    Coupert's product-config and cashback-matching backend. Receives Amazon product IDs, prices, and cart position, returns eligibility and an affiliate redirect URL.

Updated 30 September 2026mfidniedemcgceagapgdekdbmanojomk