Reclaim 2–5% of your revenue
~5% of your traffic is influenced by extensions pulling shoppers off-site or injecting unauthorized deals—creating measurable revenue drag.
Instantly blocked—no ads, no injections, no disruption.
5 minutes to go live. 60 Days for Free.
It's alleged in active federal litigation, not proven. Creators allege Honey injected its own affiliate cookie at checkout, overwriting the referrer's under last-click attribution. On June 22, 2026, a federal judge denied PayPal's motion to dismiss and every claim survived into discovery. A denial is not a finding of liability.
Yes — twice. You pay the discount on a shopper already at checkout who was going to convert, and you pay affiliate commission on a sale your own marketing sourced. Because the extension fires at the last click, last-click attribution credits it rather than the channel that earned the visit.
Generally yes, where the merchant acts only within their own site. A site owner controls what executes in their own pages, and preventing a third-party script from running there is legally distinct from modifying software on a shopper's device — which raises computer-misuse and consent questions. Confirm with counsel in your jurisdiction.
Shopify merchants have three options: a client-side script that detects and blocks the extension at checkout, replacing public codes with single-use protected links, or requesting delisting from the extension (rarely effective). Script-based blocking is the only method that works without changing your checkout. BrandLock deploys this via GTM in five minutes.
A shopper whose browser is altering your site without your knowledge. Injected competitor ads, price-comparison popups, fake coupon offers, or outright redirects — caused by adware or aggressive extensions on their own device. Your code is clean; the changes render only on their screen, which is why merchants rarely detect it.
Because they aren't in your code. Injections originate from software on the shopper's machine, so your site renders clean for you, your QA team and your uptime monitoring. Detecting them requires client-side measurement from inside a real shopper session — server logs and analytics won't surface it.
The largest by install base: Microsoft Edge's built-in shopping (263m users), Honey (16m), Capital One Shopping (8m), Avira (6m), Avast SafePrice (5m), Rakuten (3m), Pie (2m), Coupert (2m), Klarna (1m) and AVG SafePrice (1m), plus PriceBlink, Skimlinks, RetailMeNot, Swagbucks, CNET Shopping and 200+ smaller tools.
Blocking stops the extension firing entirely — right for passive deal-hunters who'd have bought anyway. Block-and-replace stops it and serves a merchant-controlled offer instead — right for active deal-hunters who'd otherwise leave to find a code. Which performs better depends on your audience, so both should be tested.
Yes. BrandLock runs entirely as a script on your own site, with nothing installed on the shopper's machine and no browser permissions requested. This matters legally as well as practically — a merchant can act on what executes in their own pages, not on someone else's browser.
No — it usually speeds it up. Coupon extensions scan your DOM, open background tabs and inject elements at checkout, all of which add latency to your slowest, highest-value page. Removing that work removes the overhead. A blocking script should be a single asynchronous tag with no render-blocking dependency.
It protects it. Coupon and cashback extensions routinely claim last-click credit for traffic they never sourced, so you pay commission on sales your own marketing earned. Blocking them means you pay only for legitimate referrals, and your channel attribution stops being distorted in favour of affiliate.
Around 5% of traffic runs an extension that pulls shoppers off-site or injects codes at checkout. Blocking them returns a 2–3% revenue lift, measured against a holdout control. Live results: Timberland 5% lift, Peter Millar 6%, Bose 2% — each A/B tested in the client's own analytics.