FluentAffiliate 1.6.5 - signed updates, plus tighter tracking
FluentAffiliate 1.6.5 is out. Signed updates land here too, and there are a couple of changes to tracking and referrals you should know about before you look at your numbers.
Signed updates
Same change we shipped in FluentSupport Pro and FluentCommunity Pro. Until now, when your site updated FluentAffiliate, it downloaded the file and trusted it. No way to check it was really ours.
Now every release we publish is signed with a key that lives offline. Not on our licensing servers, not in our build pipeline, not on the CDN. Before WordPress downloads an update, your site checks the signature, that the package is really FluentAffiliate, that the version is not older than yours, and that the file hash matches what we signed. Any check fails, nothing installs.
Nothing to configure. It is on by default. This is rolling out across all our premium plugins.
Custom conversion referrals now need your approval
Referrals created through custom conversions used to go through on their own. Now they land as pending and wait for an admin to approve them. If you use custom conversions, check your pending queue after updating.
Visit tracking got stricter
We added deduplication for repeat visits and per-IP flood limits. This means your visit counts will likely go down a bit. That is not a bug. The old numbers were counting things they should not have been. Clicks that were never real traffic are just no longer showing up.
Also in this release
- New filters for signup roles and reserved field names
- License management now shows your plan, expiry, and renewal alerts
- Security hardening across permissions, registration, tracking, and output escaping.
More cooking π
Great update!
One workflow I would love to see on the roadmap is privacy-aware bonus fulfilment for influencer affiliates. Many creators promise buyer-only bonuses to people who purchase through their link or code.
Eg.: I will check FirstPromoter (system used by XCloud for example!) that lets admins decide whether referral emails are masked.
In FluentAffiliate, the affiliate can see the referral, but there is no documented privacy-safe workflow to identify the buyer and deliver the promised bonus.
Could FluentAffiliate support:
- admin-configurable buyer identity (masked by default, with fuller disclosure only where the merchant has an appropriate legal basis or consent);
- a βDeliver bonusβ action that sends from the merchant site without exposing the buyerβs email, with an audit log;
- optional checkout consent to share an identifier with the affiliate;
- sub-ID/source reporting per link; and
- source filters, rejection reasons and bulk approval for the new pending custom-conversion queue?
This would make FluentAffiliate much stronger for influencer launches while keeping privacy under the merchantβs control. Is anything along these lines already planned? π
Jorge de los ReyesΒ Will discuss this feature with you in the coming weeks. Looks interesting.
Shahjahan JewelΒ thanks Jewel. Happy to help!