Podcast: Download (Duration: 47:42 — 54.9MB)
Stopping coupon code abuse comes down to four things: keep a single source of truth for every code your team issues, review redemption data weekly, use single-use codes wherever possible, and hide the promo code field behind a link so only people who were given a code go looking for it. Coupon extensions affect roughly 10% of orders for retailers who have the problem.
In this episode I sat down with Kathleen Booth, CMO of clean.io, a company that helps ecommerce stores protect their margins from browser extensions that auto-inject discount codes at checkout.
Below is the full mechanism: how extensions harvest your codes, why they claim affiliate commissions on sales they never drove, what A/B testing showed about blocking them, and what to do about it at any budget.
Get My Free Mini Course On How To Start A Successful Ecommerce Store
If you are interested in starting an ecommerce business, I put together a comprehensive package of resources that will help you launch your own online store from complete scratch. Be sure to grab it before you leave!
Table of Contents
Key takeaways
- Coupon extensions affect about 10% of orders for retailers with the problem, and that number is rising.
- Extensions scrape codes your VIPs enter. Their privacy policy grants permission, so your customer is not the leak.
- Blocking auto-injection raised average order value 3% to 10% with no drop in conversion rate.
- Honey sold to PayPal for $4 billion. Capital One bought Wikibuy. Payment companies want the spending data.
- Extensions claim affiliate credit even when no coupon applies. The cookie can overwrite your real attribution.
- Extensions can overwrite a legitimate affiliate’s code, so your affiliate loses credit for a sale they did drive.
- Hide the promo field behind a link. A visible box signals that a code exists somewhere.
- iOS 15 brings extensions to mobile Safari. The problem was desktop-only and is about to expand.
What coupon code abuse actually is
Coupon abuse happens when codes designed for a specific audience get used by everyone, which erodes margins and corrupts your attribution data at the same time.
Most codes are targeted by design. The 10% for newsletter subscribers, the code read on a podcast ad, the affiliate codes tracking partner performance. None of those are meant for general circulation.
The two consequences are distinct. Margins compress because average order value drops across a much wider slice of customers than intended, and marketing attribution becomes unreliable because credit lands in the wrong place.
The history explains why this got worse. Coupons were traditionally a top-of-funnel tool, the Bed Bath and Beyond mailer that made you remember you might need towels. Digital couponing extended them across the whole funnel, into repeat purchases, cart abandonment, and order value.
How coupon browser extensions work
Extensions like Honey and Capital One Shopping sit in the browser, activate at checkout, test every code in their database automatically, and apply whichever gives the largest discount.
If nothing works, they display a default state congratulating the shopper on already having the best deal.
The progression matters. Deal aggregator sites like RetailMeNot required leaving the store and manually testing codes, which was enough friction to stop most shoppers. Extensions removed both steps.
The prompt arrives at the worst possible moment for the merchant: the shopper has already decided to buy and has their credit card out.
How coupon extensions get your codes
They scrape codes directly from shoppers who enter them, and their privacy policy explicitly grants that permission when someone installs the extension.
This is the part most merchants get wrong. When you send a large discount to a VIP customer and it appears on coupon sites the next day, that customer usually did not share it. Their extension harvested it the moment they typed it in and pushed it to the shared database.
Codes can also be submitted deliberately, which is a real concern with affiliates. An affiliate can hand their tracking code to an extension for mass distribution and collect commissions on sales they never referred.
Why extensions charge you affiliate commissions
When a merchant joins an extension’s partner program in exchange for control over their codes, the extension becomes an affiliate and collects a commission on any sale where it was present.
The sequence is worth spelling out. You write asking them to remove your wholesale codes, and sometimes they comply.
Often the answer instead is that joining their partner program will give you more granular control.
What you actually agreed to is paying a commission every time a shopper with the extension installed buys from you, whether a coupon applied or not.
The compounding problem is that you already paid to acquire that customer through Facebook ads or another channel. The extension appears at the last mile, contributed nothing to bringing them there, and takes both a discount and a commission.
How coupon extensions break your attribution data
When merchants participate through an affiliate platform like ShareASale, the extension drops a first-party cookie that overwrites existing attribution, including on sales where no coupon was successfully applied.
That means a customer who clicked your Facebook ad can be credited to the extension instead, which distorts the numbers you use to allocate ad spend.
It cuts against your affiliates too. If a legitimate affiliate shares their code and their audience member has Honey installed, a larger coupon in Honey’s database overwrites the affiliate code. The affiliate loses credit for a sale they genuinely drove.
What happens when you block coupon extensions
A/B testing across retailers showed average order value rising 3% to 10% with conversion rates either flat or slightly improved.
The test design: block auto-injection for half of site traffic while leaving the experience visually identical. Extensions still pop up and still appear to test codes, and half of shoppers simply never get a working one.
The AOV increase is the straightforward part, since the discount is not being applied. The conversion result is what surprises people, because the common assumption is that extensions rescue abandoned carts.
Kathleen’s read on why conversion held is reduced distraction. Someone who has already filled a cart has demonstrated high intent, and the coupon prompt pulls them out of the purchase.
She is candid that the sample is not huge and testing is ongoing. Results have been consistent so far across apparel, beauty, and home decor.
My own data points the same direction. I get an alert whenever a coupon fails, and shoppers who try two or three codes without success generally check out anyway.
Kathleen’s estimate is that roughly 20% of retailers recognize this as a problem, while about 80% believe extensions help with cart abandonment and new customer acquisition based on little more than instinct.
Why payment companies bought the coupon extensions
PayPal bought Honey for $4 billion and Capital One bought Wikibuy, now Capital One Shopping, because the spending data is the actual product.
The pattern is that financial services and payments companies made these acquisitions. They gain visibility into what you buy, where, and how much.
Capital One is the sharper example. Combine shopping behavior with the credit cards, checking accounts, and savings accounts many of their users already hold, and the resulting financial picture is unusually complete.
The old rule applies: consumers pay nothing for these extensions, which makes the consumer the product. Affiliate commissions are the second revenue line.
Why extension problems are about to get worse
iOS 15 brings browser extensions to mobile Safari, which expands a desktop-only problem to the majority of ecommerce traffic.
Honey participated in Apple’s developer conference announcement around iOS 15, and other browsers are adding mobile extension support as well.
The demographics are widening too. Extensions were predominantly used by younger women, which is why apparel and beauty saw the worst leakage.
Superbowl advertising featuring Samuel L. Jackson for Capital One Shopping is clearly aimed at expanding well beyond that group.
The problem is most severe in the United States.
How to practice good coupon hygiene
Three practices cover most of the exposure without buying anything.
Keep a single source of truth. Many retailers discover active codes they did not know existed, because codes get generated in Shopify, Klaviyo, and an SMS plugin by different people. A shared spreadsheet with every code and its creation date fixes this.
Review redemption data weekly. A spike that does not correspond to any marketing activity, yours or an affiliate’s, is how leaks announce themselves. Weekly cadence keeps the window small.
Use single-use codes wherever possible. Email and SMS support them well. Podcast ads, display ads, and affiliate relationships generally cannot, which is exactly where hygiene matters most.
My own approach is alert-based rather than scheduled. Any high-value code triggers an email when someone attempts it, so I see unusual activity without reviewing reports. If a code tied to specific large customers gets more than a couple of redemptions a month, something is wrong.
How to design checkout to reduce coupon hunting
Replace the visible promo code box with a link that opens the field, since a visible box signals that a code exists and someone else has it.
Research supports this. Seeing a promo code field makes shoppers believe a valid code is out there, which sends them off to search for one.
The behavioral split works in your favor. Someone who was given a code will hunt down the link and click it. Opportunistic extension users rely on convenience and will not.
Renaming the field also helps. Call it a voucher box and tell recipients to look for the voucher field, and shoppers who were never sent one will not recognize what to look for.
What clean.io’s Clean Cart does
Clean Cart blocks coupon extensions from auto-injecting codes at checkout without changing what the shopper sees or preventing manual code entry.
The extension still appears and still looks like it is testing codes, then renders the default congratulations state because the injection was blocked server-side.
There is a compounding effect. Extensions track which codes succeed, so as your codes stop working they gradually drop out of the shared databases entirely, which reduces manual entry over time too.
The company came out of adtech. Their original product, Clean Ad, protects large publishers including the Boston Globe and CBS Interactive from malicious programmatic ads, and their script sits on roughly 8 million sites. Coupon extensions surfaced as another form of client-side injection visible from that vantage point.
Clean Cart left private beta in March targeting Shopify Plus, with a waitlist for other platforms.
Why merchants should audit third-party code
You legally own your website and do not control most of the code running on it, which is the broader risk this sits inside.
Three layers of code you did not write: the platform or CMS, the apps and plugins you installed, and the browser extensions your visitors arrive carrying.
I learned this directly. I once found an app I had installed sending my customer information to advertising firms without my knowledge, which I only caught by inspecting the outbound traffic.
The exposure is real. A small piece of JavaScript on your site can scrape every form field, including email addresses, and send them anywhere. If a customer used a unique email only at your store and it leaks, you are the one who gets blamed.
Marketing departments now run larger software budgets than IT departments at many companies, which makes this a marketer’s responsibility rather than something to hand to the IT team.
Frequently asked questions
How do coupon extensions get discount codes?
They scrape codes shoppers enter manually, with permission granted in the extension’s privacy policy at install. A VIP customer who types in a private code is not deliberately sharing it, and the extension pushes it to a database shared with all users.
Does blocking coupon extensions hurt conversion rates?
A/B testing showed conversion rates flat or slightly improved while average order value rose 3% to 10%. The likely explanation is reduced distraction, since shoppers who have already filled a cart demonstrated high intent and the coupon prompt pulls them out of the purchase.
How does Honey make money?
Through spending data and affiliate commissions. PayPal bought Honey for $4 billion and Capital One bought Wikibuy, both payments companies seeking visibility into consumer spending. Extensions also collect affiliate commissions from merchants who join their partner programs.
Do coupon extensions steal affiliate credit?
Yes, in both directions. When a merchant joins an extension’s partner program, the extension claims commission on sales where it was present even with no coupon applied. It can also overwrite a legitimate affiliate’s code, so that affiliate loses credit for a sale they drove.
What percentage of orders do coupon extensions affect?
Roughly 10% on average for retailers who have the problem, and the number is growing. It is most severe in the United States, on desktop, and in apparel and beauty, though advertising campaigns are broadening the user base.
How do you prevent coupon codes from leaking?
Keep every code your team issues in one shared spreadsheet with creation dates, review redemption data weekly for spikes that do not match marketing activity, and use single-use codes wherever the channel supports them. Alerts on high-value codes catch leaks without scheduled reviews.
Should you hide the promo code field at checkout?
Yes. Replace the box with a link that opens it. Research shows a visible field makes shoppers believe a code exists and sends them searching. People who were given a code will find the link, and opportunistic extension users relying on convenience will not.


