Is Coupert - Automatic Coupon Finder & Cashback safe?
Coupert is medium risk. On navigating to a shopping page, Coupert collects the URLs of every open tab and sends them to its servers. Dynamic analysis captured a POST to coupert.com/api/v2/ext/saveUserTabV2 with all open tabs' {url, id}, no prompt.…
Who publishes itCoupert Science LLC - 3 other listings from the same operator, 2 of them carrying a finding
Coupert Science LLC - 3 other listings from the same operator, 2 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
3 other listings published from this account, 87k+ users between them. 2 of them carry a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
All open tab URLs sent to Coupert server on every navigation
On navigating to a shopping page, Coupert collects the URLs of every open tab and sends them to its servers.
Dynamic analysis captured a POST to coupert.com/api/v2/ext/saveUserTabV2 with all open tabs' {url, id}, no prompt.
You navigate to any website.
The extension collects the URLs of all your open tabs and transmits them as a list to Coupert's server.
This includes tabs you have open in other windows, incognito or not, any tab visible to chrome.tabs.query({}).
| Content-Type | application/json |
{
"tab_data": [
{
"url": "https://www.amazon.com/s?k=laptop",
"id": 2075718804
},
{
"url": "https://mail.google.com/mail/u/0/#inbox",
"id": 2075718805
},
{
"url": "https://en.wikipedia.org/wiki/Laptop",
"id": 2075718806
}
]
}Background service worker: collecting all open tabs (background.js, ~line 73130)
// wZ(): collect all open tabs and send to saveUserTabV2
async function wZ() {
try {
let tabs = await chrome.tabs.query({}); // ALL open tabs, no filter
if (!tabs) tabs = [];
const tabData = tabs
.filter(t => t.url) // drop tabs with no URL
.map(t => ({ url: t.url, id: t.id })) // keep only url + tab id
.slice(0, 20); // cap at 20 tabs
const result = await El(tabData); // POST to saveUserTabV2
if (result?.code === 0) return result.data;
return {};
} catch (e) { return ''; }
}
// El(): the actual POST call
function El(e) {
return apiPost('/ext/saveUserTabV2', {
method: 'post',
data: { tab_data: e }
});
}| Field | Value | Why it matters | |
|---|---|---|---|
Tab URL | https://www.amazon.com/s?k=insulin+pump | The full URL of each open browser tab, including query strings that may contain search terms or session tokens. | |
Tab ID | 2075718804 | Chrome's internal numeric identifier for each tab, used by Coupert to correlate tab snapshots over time. |
- www.coupert.com
Coupert's primary API server. Receives the full open-tab URL list per user session via /api/v2/ext/saveUserTabV2.
Coupert Sends Your Amazon Cart Contents to Its Own Server Automatically
With Coupert installed, opening your Amazon cart makes the extension read every item's product ID and price and send that list to pcp.coupert.com, without a cashback click.
This runs on ordinary navigation, not only on request.
You open your Amazon shopping cart while Coupert is active.
No cashback button, coupon search, or other explicit action is involved.
Coupert reads the product IDs and prices of everything in your cart and sends them to its own server.
The background service worker fires the request roughly 5 seconds after the cart page finishes loading.
{
"domain": "amazon.com",
"position": "cart",
"skus": [
{
"sku": "B088N7KPZN",
"price": ""
},
{
"sku": "B088NLK5P5",
"price": ""
},
{
"sku": "B088NRLMPV",
"price": ""
}
]
}The background handler that fires the POST whenever a super-cashback lookup message arrives
// background.js — message router registered on extension startup
messageBus.backgroundPage().on(
"pcp_api:product.super_cashback.get",
async (message, sendResponse, sendError) => {
try {
const { content: skuPayload = {}, tab = {} } = message;
const { id: tabId = "" } = tab;
// POST the collected SKU/price list straight to Coupert's own API
const result = await postToCoupert({
endpoint: "/product/superCashback",
method: "post",
tabId,
data: skuPayload, // { domain, position, skus: [{ sku, price }, ...] }
isEncrypt: true,
});
sendResponse(result);
} catch (err) {
sendError(err);
}
}
);
// postToCoupert() resolves to https://pcp.coupert.com/api/v1 + endpoint,
// attaches a per-install "guid" query param, and encrypts the body only
// when the extension's remote config has the "pcp.encryptSwitch" flag on.| Field | Value | Why it matters | |
|---|---|---|---|
Amazon product ID (ASIN) | B088NRLMPV | Tells Coupert's server exactly which products you're browsing or have in your cart. | |
Cart position | cart | Tells the server this item came from your shopping cart specifically, not a search result. | |
Retailer domain | amazon.com | Identifies which store you were shopping on when the request fired. | |
Installation ID (guid) | 3d7ac981ecd77de466f2d5f49e0b4ea5 | A persistent identifier tied to your browser install, letting Coupert link every cart/search request back to the same device over time. |
- pcp.coupert.com
Coupert's product-config and cashback-matching backend. Receives Amazon product IDs, prices, and cart position, returns eligibility and an affiliate redirect URL.