Is LoveDeals: AI-Powered Coupon Finder safe?
LoveDeals silently opens a hidden background tab through its own affiliate link on merchant sites you visit organically.
When you browse a supported shopping site, LoveDeals sends the page's domain to lovedeals.ai and checks the response for an active coupon and an 'auto_out' flag. If set, and it hasn't fired for that merchant in the last 24 hours, the extension opens an invisible, pinned background tab that redirects through lovedeals.ai/deal/api/v1/transit before landing back on the site you were already on, planting its own affiliate tracking cookie. The tab never becomes visible and closes itself within seconds, with no popup, click, or other user action involved, and it fires even if another affiliate network's cookie is already present.
Who publishes itLoveDeals: AI-Powered Coupon Finder - no other listings under this identity, 3 shared hostnames
LoveDeals: AI-Powered Coupon Finder - no other listings under this identity, 3 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 3 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
LoveDeals auto-opens a pinned background tab to plant its own affiliate cookie
Code analysis shows LoveDeals' background script opens a pinned, unfocused tab to its own affiliate-redirect endpoint on qualifying page loads, then closes it within seconds, with no click or visible tab switch.
You load a page on a merchant site that LoveDeals currently has an active coupon deal for.
No click, popup, or consent prompt is required.
The background script opens a pinned, unfocused tab to LoveDeals' own affiliate-redirect endpoint, then closes it a few seconds later.
This plants LoveDeals' affiliate cookie on the sale whether or not another affiliate network already has a legitimate claim to it.
| Field | Value | Why it matters | |
|---|---|---|---|
Site domain | domain=walmart.com | The domain of the page you're on, sent so the server can check for an active deal there. | |
Deal ID | cid=48213 | Identifies which affiliate deal LoveDeals is claiming credit for on this sale. | |
Full page URL | goto=https%3A%2F%2Fwww.walmart.com%2Fip%2Fexample-product%2F123456 | The exact page you're on, used to send you back there once the affiliate redirect completes. |
| When | You did | Extension did |
|---|---|---|
| immediately; throttled to once per deal ID per 24h | server The info response says this domain has an active deal with auto_out enabled. | service_worker Extension opens the pinned, unfocused affiliate-redirect tab. |
| ~8s after load completes, 10s hard cutoff | extension The unfocused tab finishes loading, or 10 seconds pass, whichever comes first. | service_worker Extension force-closes the tab. |
autoOpenTrack() and openTrackTab() in the background script
autoOpenTrack(e) {
e.auto_out && this.storage.get("auto_out").then(t => {
if (t) {
let r = JSON.parse(t);
(!r[e.id] || Math.floor(new Date().getTime() / 1e3) - r[e.id] > 86400) && (
this.openTrackTab({ cid: e.id, url: e.url }),
r[e.id] = Math.floor(new Date().getTime() / 1e3),
this.storage.set("auto_out", JSON.stringify(r)).then()
)
} else {
this.openTrackTab({ cid: e.id, url: e.url }),
this.storage.set("auto_out", JSON.stringify({ [e.id]: Math.floor(new Date().getTime() / 1e3) }))
}
})
}openTrackTab(e) {
let t = this.tabs();
if (!e.url) return !1;
console.log("https://lovedeals.ai/deal/api/v1/transit?type=1&cid=" + e.cid + "&goto=" + encodeURIComponent(e.url));
t.create({
url: "https://lovedeals.ai/deal/api/v1/transit?type=1&cid=" + e.cid + "&goto=" + encodeURIComponent(e.url),
active: !1,
pinned: !0
}).then(e => {
this.returnTabIds[e.id] = !0;
let r = () => {
this.getTabById(e.id).then(r => {
r && (t.remove(e.id).then(), delete this.returnTabIds[e.id])
}).catch(e => {
console.log("close track tab error:", e)
})
};
setTimeout(() => {
t.onUpdated.addListener((t, i) => {
try {
t == e.id && "complete" == i.status && setTimeout(() => { r() }, 8e3)
} catch (e) {
console.log("close track tab error 1", e)
}
})
}, 500), setTimeout(() => { r() }, 1e4)
})
}Logs every pinned, unfocused tab LoveDeals opens to its own affiliate-redirect endpoint, so a fleet owner can confirm the behavior on a managed profile.
chrome.tabs.onCreated.addListener((tab) => {
if (
tab.pinned &&
!tab.active &&
typeof tab.url === "string" &&
tab.url.startsWith("https://lovedeals.ai/deal/api/v1/transit")
) {
console.log("[lovedeals-watch] affiliate-redirect tab opened:", tab.url, new Date().toISOString());
}
});
chrome.tabs.onRemoved.addListener((tabId) => {
console.log("[lovedeals-watch] tab closed:", tabId, new Date().toISOString());
});
- 1Open chrome://extensions and enable Developer mode.
- 2Under LoveDeals, click 'Inspect views: service worker'.
- 3Paste this script into the console.
- 4Browse to a few major retail sites and watch the console for tab events.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 2.7.0. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every secure site you visit
https://*/*
Read and change your data on every site you visit
http://*/*
Store data in your browser
storage
Run its own code inside the pages you visit
scripting
Read and change cookies, including the ones that keep you signed in
cookies
See the address and title of every tab you have open
tabs
Where it sends data
Destinations our analysis observed LoveDeals: AI-Powered Coupon Finder contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- lovedeals.ai
LoveDeals: AI-Powered Coupon Finder sends data to lovedeals.ai. One other extension we have analysed sends data here.