Is LoveDeals: AI-Powered Coupon Finder safe?

Medium risk

LoveDeals silently opens a hidden background tab through its own affiliate link on merchant sites you visit organically.

When you browse a supported shopping site, LoveDeals sends the page's domain to lovedeals.ai and checks the response for an active coupon and an 'auto_out' flag. If set, and it hasn't fired for that merchant in the last 24 hours, the extension opens an invisible, pinned background tab that redirects through lovedeals.ai/deal/api/v1/transit before landing back on the site you were already on, planting its own affiliate tracking cookie. The tab never becomes visible and closes itself within seconds, with no popup, click, or other user action involved, and it fires even if another affiliate network's cookie is already present.

LoveDeals: AI-Powered Coupon Finderv2.7.0Firefox Add-ons
45Risk
Who publishes it

LoveDeals: AI-Powered Coupon Finder - no other listings under this identity, 3 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
LoveDeals: AI-Powered Coupon Finder

Shared hosts - 3 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

lovedeals.ai
Also called by 1 other listing: LoveDeals: Automatic Coupons & Deals
pikbest.com
Also called by 1 other listing: LoveDeals: Automatic Coupons & Deals
lovepik.com
Also called by 2 other listings, including LoveDeals: Automatic Coupons & Deals

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-506
SourceAI FOUND

LoveDeals auto-opens a pinned background tab to plant its own affiliate cookie

Code analysis shows LoveDeals' background script opens a pinned, unfocused tab to its own affiliate-redirect endpoint on qualifying page loads, then closes it within seconds, with no click or visible tab switch.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You load a page on a merchant site that LoveDeals currently has an active coupon deal for.

No click, popup, or consent prompt is required.

The extension did this

The background script opens a pinned, unfocused tab to LoveDeals' own affiliate-redirect endpoint, then closes it a few seconds later.

This plants LoveDeals' affiliate cookie on the sale whether or not another affiliate network already has a legitimate claim to it.

02EvidenceFIELD TABLE
What the unfocused-tab request sends
FieldValueWhy it matters
Site domain
domain=walmart.comThe domain of the page you're on, sent so the server can check for an active deal there.
Deal ID
cid=48213Identifies which affiliate deal LoveDeals is claiming credit for on this sale.
Full page URL
goto=https%3A%2F%2Fwww.walmart.com%2Fip%2Fexample-product%2F123456The exact page you're on, used to send you back there once the affiliate redirect completes.
03EvidenceCORRESPONDENCE
Automatic open, automatic close
WhenYou didExtension did
immediately; throttled to once per deal ID per 24h
server
The info response says this domain has an active deal with auto_out enabled.
service_worker
Extension opens the pinned, unfocused affiliate-redirect tab.
~8s after load completes, 10s hard cutoff
extension
The unfocused tab finishes loading, or 10 seconds pass, whichever comes first.
service_worker
Extension force-closes the tab.
04EvidenceCODE COMPARE
The code that does this

autoOpenTrack() and openTrackTab() in the background script

What it actually does
autoOpenTrack() (readable)static/background/index.js
autoOpenTrack(e) {
  e.auto_out && this.storage.get("auto_out").then(t => {
    if (t) {
      let r = JSON.parse(t);
      (!r[e.id] || Math.floor(new Date().getTime() / 1e3) - r[e.id] > 86400) && (
        this.openTrackTab({ cid: e.id, url: e.url }),
        r[e.id] = Math.floor(new Date().getTime() / 1e3),
        this.storage.set("auto_out", JSON.stringify(r)).then()
      )
    } else {
      this.openTrackTab({ cid: e.id, url: e.url }),
      this.storage.set("auto_out", JSON.stringify({ [e.id]: Math.floor(new Date().getTime() / 1e3) }))
    }
  })
}
openTrackTab() (readable)static/background/index.js
openTrackTab(e) {
  let t = this.tabs();
  if (!e.url) return !1;
  console.log("https://lovedeals.ai/deal/api/v1/transit?type=1&cid=" + e.cid + "&goto=" + encodeURIComponent(e.url));
  t.create({
    url: "https://lovedeals.ai/deal/api/v1/transit?type=1&cid=" + e.cid + "&goto=" + encodeURIComponent(e.url),
    active: !1,
    pinned: !0
  }).then(e => {
    this.returnTabIds[e.id] = !0;
    let r = () => {
      this.getTabById(e.id).then(r => {
        r && (t.remove(e.id).then(), delete this.returnTabIds[e.id])
      }).catch(e => {
        console.log("close track tab error:", e)
      })
    };
    setTimeout(() => {
      t.onUpdated.addListener((t, i) => {
        try {
          t == e.id && "complete" == i.status && setTimeout(() => { r() }, 8e3)
        } catch (e) {
          console.log("close track tab error 1", e)
        }
      })
    }, 500), setTimeout(() => { r() }, 1e4)
  })
}
05EvidenceARTIFACT
Check if you're affected

Logs every pinned, unfocused tab LoveDeals opens to its own affiliate-redirect endpoint, so a fleet owner can confirm the behavior on a managed profile.

RequiresChrome with Developer mode enabledLoveDeals installed and enabled
lovedeals-tab-watch.js · js
chrome.tabs.onCreated.addListener((tab) => {
  if (
    tab.pinned &&
    !tab.active &&
    typeof tab.url === "string" &&
    tab.url.startsWith("https://lovedeals.ai/deal/api/v1/transit")
  ) {
    console.log("[lovedeals-watch] affiliate-redirect tab opened:", tab.url, new Date().toISOString());
  }
});

chrome.tabs.onRemoved.addListener((tabId) => {
  console.log("[lovedeals-watch] tab closed:", tabId, new Date().toISOString());
});
How to run it
  1. 1
    Open chrome://extensions and enable Developer mode.
  2. 2
    Under LoveDeals, click 'Inspect views: service worker'.
  3. 3
    Paste this script into the console.
  4. 4
    Browse to a few major retail sites and watch the console for tab events.
06EvidencePLAIN NOTE
Observation

Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.

What it can do

Permissions this extension asks for, as declared in version 2.7.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Read and change your data on every secure site you visit

    https://*/*

  • Read and change your data on every site you visit

    http://*/*

  • Store data in your browser

    storage

  • Run its own code inside the pages you visit

    scripting

  • Read and change cookies, including the ones that keep you signed in

    cookies

  • See the address and title of every tab you have open

    tabs

Where it sends data

Destinations our analysis observed LoveDeals: AI-Powered Coupon Finder contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.

  • lovedeals.ai

    LoveDeals: AI-Powered Coupon Finder sends data to lovedeals.ai. One other extension we have analysed sends data here.

Updated 30 September 2026amo-2903009