Exclude Network Accounts in Pay Affiliates - The Pay affiliates advanced search has a new Exclude commissions box with options to leave out commissions from suspended network accounts and from network accounts with a negative balance (#16908)
Improvements
User Interface
Import Progress - The CSV import notification shows a progress bar, the total row count, the percentage and an estimate of the remaining time, and long file names wrap instead of being clipped (#17065) (#17073)
Wider Help Tooltips - Help tooltips with long text are no longer squeezed into a narrow column on wide screens and are no longer cut off at the edge of the form (#16474)
Performance
Faster Background Tasks - Cron runs keep processing other waiting tasks for the whole time slot instead of ending early, so imports and other long tasks finish noticeably faster on busy accounts (#17058)
Lighter Tracking Requests - Accounts with high page traffic, especially those using the "Affiliate info in external page" plugin, no longer write to the database on nearly every page view, as visit processing is now triggered at most once per minute (#17060)
Security
Security Improvements - Improved input sanitization on replicated sites and stricter server-side enforcement of merchant role permissions (#16601) (#16896) (#15169)
Bug Fixes
Commissions
Commissions of Declined Affiliates - The "What to do with commissions of declined affiliate?" setting now applies to the whole multi-tier chain: Do not save no longer pays parent affiliates for sales through a declined affiliate, Save as declined stores the parents' commissions as declined too, and Save to parent moves the parent affiliates up a tier also for merchant-added commissions, direct links and clicks. The setting also got a help text explaining each option (#16619)
Logins History
Logins History Search - Fixed "Unable to load data" when searching in a view without the Role column (#17040)
MCP Server for AI Assistants - AI tools such as Claude, Cursor and ChatGPT can connect to your account over MCP from the new Tools > Integration > AI assistants (MCP) screen: the assistant signs in with your merchant login through OAuth, you choose read-only or read and write access, and connected assistants can be revoked at any time. Available tools cover affiliates, commissions, campaigns, banners, clicks, traffic and top affiliates reports, refunds and chargebacks, and an order diagnosis that explains why an order did not create a commission; bearer tokens are available for tools without OAuth, and only the merchant role is supported in this version (#16557) (#16933)
Domain Settings
Managed Let's Encrypt Certificates - Hosted accounts with a custom domain can choose a managed Let's Encrypt certificate that is issued and renewed automatically instead of uploading their own, and the Domain settings screen was redesigned with a Set custom domain dialog that first asks for the certificate type (#15451)
Integrations
Ecwid Plugin - The Ecwid plugin was rebuilt for Ecwid's current API: it connects with the Store ID and secret token of a private app created in your Ecwid Control Panel, approves, refunds or declines commissions automatically from Ecwid order status webhooks, and supports multiple stores as separate configuration tabs. Automatic status updates are optional and require the plugin's webhook URL and the app's client secret to be set up (#9031)
Webhooks and Application Callbacks
Payout Fields in Affiliate Profile Change Webhook - The Affiliate Profile Change Webhook plugin can now watch and send the affiliate's payout method, minimum payout and payout method fields such as bank account or PayPal email, and signup Application Callbacks can include the same payout fields as variables. Payout values are masked in the event log (#14292)
Improvements
REST API v3
Search Filters and Operators - The q parameter accepts >= and <= operators, date-only range bounds include the whole end day, and new filter fields were added: visitor_id, ip, approved_at and starred on GET /transactions, alias, is_default, account_id and starred on GET /campaigns, and is_confirmed, destination_url and starred on GET /banners. The campaign type filter and transaction type values such as refund, chargeback and cpm now work (#16989)
Partial Refunds and Notes - The refund and chargeback endpoints accept total_cost to reverse only part of a commission, and refund, chargeback and status change requests accept a system_note visible only to merchants; the note of PATCH /transactions/{id}/status is now stored (#16989)
Typed Response Fields - starred is returned as a boolean in affiliate, campaign, banner and transaction rows, application.currency_decimals in GET /settings is an integer, empty logo_url and product_ids are null, GET /banners/{id} returns campaign_name, GET /affiliates/{id} returns every custom field defined in the affiliate form, and campaign rows no longer include the duplicate campaignid and the unused networkstatus (#16989)
URL Parameter Names in Settings - GET /settings returns the configured URL parameter names for affiliate, banner and campaign IDs, data1, data2 and the destination URL under tracking.url_parameter_names, so integrations can build correct tracking links without API v1 (#16957)
Lifetime Referrals
Lifetime Referrals Export and Import - The Lifetime referrals grid and CSV export offer optional Commission group ID and Channel code columns whose values are accepted as-is on re-import, and the import option was renamed to "Update existing relations" with a clearer explanation that only the columns present in the CSV are updated (#16955)
Banners and Campaigns
Collapsible Category Filters - Banner and campaign category filters in the merchant and affiliate panels show only main categories when the whole tree does not fit, a click expands or collapses a whole branch, and a chevron in the header expands or collapses all; search results keep their parent categories and the path to already selected categories is expanded (#13887)
Integrations
Shopify Imported and Old Orders - Orders older than 7 days by their placement date are no longer processed when Shopify reports them as created, and status notifications for such orders are ignored unless a commission already exists, so bulk imports of historical orders no longer delay tracking. Orders without a storefront checkout, such as POS or draft orders, are processed on the first attempt without retries (#16981)
Shopify Diagnostics - The event log shows the visitor ID on created Shopify sales and warns when a customer who came through an affiliate link could not be matched to the affiliate; an updated checkout pixel code in the plugin configuration reports pixel-side failures and should be pasted again into Shopify Customer events (#16980)
Security
Login Hardening - Strengthened protection of the merchant, affiliate and API logins against automated login attempts (#16946) (#16948)
Bug Fixes
Site Replication
Links and Embeds on Replicated Sites - Links that open in a new tab from a replicated site, such as the Back Office link to the affiliate login, work again. A new "Sandbox replicated sites" option under Features > Site Replication > Configure, enabled by default, can be turned off to allow embedded videos and cookies on replicated pages if you trust every replicated site (#16871)
Banners
Rebranded PDF Banner Filenames - Rebranded PDF banners with accented or other non-ASCII characters in the file name now download with the correct name (#16938)
Plugins
Affiliate Profile Change Webhook Responses - Fixed false critical errors in the event log when the webhook endpoint accepted the request with a success status other than 200, such as 201 or 204 (#17022)
Plugin Configuration Layout - Removed the empty space below plugin and feature configuration forms with conditionally hidden fields (#16930)
Affiliate Panel Menu Categories - Merchants can add a category to the affiliate panel menu from Configuration > Affiliate panel > Menu & screens. A category groups other screens and has no content of its own, so clicking it only expands its submenu; categories can be placed only at the first level of the menu and are hidden when they have no visible screens (#13620)
Multiple Currencies
Narodowy Bank Polski Exchange Rates - Automatic exchange rates now combine the European Central Bank and Narodowy Bank Polski feeds, extending coverage from about 30 to roughly 150 currencies, with daily updates for major currencies and weekly updates for exotic ones. Rates for currencies with very large or very small values, such as JPY, are also rounded more precisely (#16786)
Application Callbacks
Extra Bonus Callbacks - Extra bonus is available as a commission type in Application Callbacks, so a callback can fire when an extra bonus commission is created, approved or declined. Callbacks set to All commission types keep firing only for sale and action commissions (#16876)
Improvements
Security
Username Character Validation - Usernames may contain only letters, digits and the characters _ . + @ -, and referral IDs derived from usernames follow the same rule (#16740)
Themes
Session Expired Dialog - The session expired dialog is styled for the Trace theme and uses simpler wording in all themes; pressing Enter or Esc reloads the page (#16879)
Trace Theme Autofill Colors - Browser-autofilled fields in Trace theme dark mode keep a readable yellow background (#16883)
Bug Fixes
Banners
Sample Promotional Email Banner - Fixed broken product and Unsubscribe links in the sample promotional email banner; unedited copies in existing accounts are repaired automatically (#16862)
Theme Editor Customization Tracking - Customized theme files are marked with a Modified badge and their save date, can be filtered with "Show only modified", and can be compared side by side with the version shipped with the theme. Reverting a file now shows the exact lines that would be lost before confirming (#16777)
Affiliate Activity Checking
Parent Affiliate Inactivity Notifications - Automatic affiliate activity checking can now also email the parent affiliate when a sub-affiliate receives an inactivity warning or when the inactivity action is applied. Both notifications are opt-in in Configuration > Affiliates activity check (#16643)
Improvements
Security
Improved Input Validation - Strengthened server-side validation in merchant panel configuration forms and the theme editor (#16598) (#16769)
Improved Error Handling - Generic error messages for invalid merchant panel form requests (#16846)
Email System
Confirmation for Email Quick Action Links - Quick action links in notification emails (approve or decline affiliate, unsubscribe, download links, and others) now open a confirmation page and execute only after the action is confirmed, so email security scanners that prefetch links no longer trigger the action. Links in already-sent emails keep working (#16727)
Signup Forms
Agree to Terms on Signup Forms - Affiliate and network merchant signup forms share one agree-to-terms layout: clicking the checkbox or its label toggles agreement, and a separate View terms link opens the terms popup. The Coupe theme keeps its inline terms text (#16378)
REST API v3
Tracking Script Names in Settings - GET /settings now includes the hashed alternative names of the tracking scripts under tracking.scripts (#15760)
Bug Fixes
REST API v3
Not Found Responses - Requests to unknown API v3 paths now return a Not Found error instead of a generic Bad Request error (#16840)
Themes
Saving Unchanged Theme Files - Saving a theme file without changes no longer creates a customized copy, so the file keeps receiving template updates shipped with new versions (#16774)
Theme Editor Folders - Removed the edit icon from folders in the theme editor file tree (#16821)
Affiliate Links Banner Colors - The general affiliate links banner in the affiliate panel header now follows the merchant's customized colors in both light and dark mode across all affiliate themes (#15367)
Mobile App
Traffic Tab for Affiliates - The Traffic tab is visible again for affiliates in the mobile app (#16779)
Integrations
Shopify Product Data - The Shopify plugin with per-order tracking now fills product-related extra data fields (product title, SKU, price, quantity, and others) using the order's first line item (#16731)
AI Assistant
AI Assistant Button - The AI Assistant button no longer disappears after opening and closing dialogs such as Import transactions or Send pending emails in the Summer and Compact themes (#16797)
User Interface
Date Filter in Advanced Search - Typing text into a Date created custom filter field in Advanced Search no longer fails and leaves the filter unusable (#11011)
Campaign Display Name - Campaigns can have an optional display name that affiliates see instead of the internal campaign name across grids, reports, banners, coupons, tracking codes, and emails. Merchants keep seeing the real name, with an optional Display name column and filter in the Campaigns grid, and the alias is available in REST API v3 (#13922)
Affiliates Manager
Bulk File Download - Files uploaded by affiliates to a file uploader field can be downloaded for selected affiliates as a single ZIP archive. Large downloads run in the background with a progress dialog and an optional email notification when the archive is ready (#16542)
Improvements
Security
Improved Output Escaping - Improved escaping of affiliate-entered data (#16596) (#16765)
Improved Access Control - Strengthened access control checks for account-scoped configuration data (#16764)
Site Replication Hardening - Hardened how replicated site content is served (#11880)
Performance
Clicks Report on Large Databases - The Clicks list no longer times out on installations with a very large click history when filtered by affiliate, campaign, or date range (#16730)
REST API v3
Consistent Date Parameters - Empty date and period parameters are now treated the same as absent ones across endpoints, and GET /reports/top-affiliates defaults to the current month instead of all-time data when no date parameters are given (#16639)
Network
Lifetime Referrals Access Control - Affiliate details in the Lifetime referrals grid are shown only to merchants allowed to read affiliates, and network merchants see only referrals of their own account (#16497)
Bug Fixes
Login
Google Sign-In Login Records - Signing in with Google is now recorded as a regular login: the What's new page no longer reappears on every login, last login date and login count are updated, and new-IP login notification emails are sent (#16711)
Login to Affiliate Panel Button - The Login to affiliate panel button no longer fails with "Can not login. User is not approved." when clicked right after opening an approved affiliate's profile (#16736)
User Interface
Color Picker Position - The color picker popup now opens next to its field, at the correct size and fully within the page, in both left-to-right and right-to-left languages (#16657)
Direct Links to Configuration Screens - URL anchors for Payouts Balance and eight other configuration screens now open the requested screen instead of redirecting to Home (#16645)
Site Replication
Tracking Code Placement - The click tracking code is now inserted after the page's real opening body tag, so replicated pages whose head scripts write a body tag in JavaScript no longer render broken (#13768)
Declined Click Redirect - Declined clicks on replicated pages are now redirected to the configured URL instead of failing with a server error (#16640)