Skip to main content

FluentAffiliate 1.6.5 - signed updates, plus tighter tracking

FluentAffiliate 1.6.5 is out. Signed updates land here too, and there are a couple of changes to tracking and referrals you should know about before you look at your numbers.

Signed updates

Same change we shipped in FluentSupport Pro and FluentCommunity Pro. Until now, when your site updated FluentAffiliate, it downloaded the file and trusted it. No way to check it was really ours.

Now every release we publish is signed with a key that lives offline. Not on our licensing servers, not in our build pipeline, not on the CDN. Before WordPress downloads an update, your site checks the signature, that the package is really FluentAffiliate, that the version is not older than yours, and that the file hash matches what we signed. Any check fails, nothing installs.

Nothing to configure. It is on by default. This is rolling out across all our premium plugins.

Custom conversion referrals now need your approval

Referrals created through custom conversions used to go through on their own. Now they land as pending and wait for an admin to approve them. If you use custom conversions, check your pending queue after updating.

Visit tracking got stricter

We added deduplication for repeat visits and per-IP flood limits. This means your visit counts will likely go down a bit. That is not a bug. The old numbers were counting things they should not have been. Clicks that were never real traffic are just no longer showing up.

Also in this release

  • New filters for signup roles and reserved field names
  • License management now shows your plan, expiry, and renewal alerts
  • Security hardening across permissions, registration, tracking, and output escaping.

More cooking πŸ™Œ

Great update!

One workflow I would love to see on the roadmap is privacy-aware bonus fulfilment for influencer affiliates. Many creators promise buyer-only bonuses to people who purchase through their link or code.

Eg.: I will check FirstPromoter (system used by XCloud for example!) that lets admins decide whether referral emails are masked.

In FluentAffiliate, the affiliate can see the referral, but there is no documented privacy-safe workflow to identify the buyer and deliver the promised bonus.

Could FluentAffiliate support:

  • admin-configurable buyer identity (masked by default, with fuller disclosure only where the merchant has an appropriate legal basis or consent);
  • a β€œDeliver bonus” action that sends from the merchant site without exposing the buyer’s email, with an audit log;
  • optional checkout consent to share an identifier with the affiliate;
  • sub-ID/source reporting per link; and
  • source filters, rejection reasons and bulk approval for the new pending custom-conversion queue?

This would make FluentAffiliate much stronger for influencer launches while keeping privacy under the merchant’s control. Is anything along these lines already planned? πŸ˜„

Shahjahan Jewel

Jorge de los ReyesΒ Will discuss this feature with you in the coming weeks. Looks interesting.

Shahjahan JewelΒ thanks Jewel. Happy to help!