Affinite WP Affiliate self-updates
Complete affiliate management system for WooCommerce and custom forms with multi-tier commissions, tracking, and payout management.
by Affinite · github.com/affinite/affinite-wp-affiliate · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/affinite/affinite-wp-affiliate/archive/refs/heads/main.zipShips its own WordPress updater (built-in updater), so new versions show up under Dashboard → Updates.
Complete affiliate management system for WooCommerce and custom forms with multi-tier commissions, tracking, and payout management.
Description
Affinite WP Affiliate is a comprehensive affiliate marketing plugin that enables you to create and manage a powerful affiliate program for your WordPress site. With seamless WooCommerce integration and support for custom forms, you can track conversions, manage commissions, and handle payouts efficiently.
Key Features
- Multi-tier Affiliate System - Support for unlimited affiliate levels with customizable commission rates
- Advanced Tracking - Cookie-based tracking with detailed analytics and reporting
- WooCommerce Integration - Seamless integration with WooCommerce orders and products
- Custom Form Support - Track conversions from custom forms and landing pages
- Automated Commissions - Automatic commission calculation and tracking
- Flexible Commission Types - Percentage and fixed amount commissions
- Payout Management - Built-in payout request and processing system
- Affiliate Dashboard - Complete dashboard for affiliates to track performance
- REST API - Full REST API for custom integrations
- Email Notifications - Automated email notifications for key events
- Detailed Reporting - Comprehensive reports and analytics
Multi-tier Commission System
Create a powerful network of affiliates with our multi-tier system:
- Unlimited Levels - Configure up to 5 affiliate levels
- Custom Rates - Set different commission rates for each tier
- Automatic Calculations - Commissions calculated automatically across all levels
- Performance Tracking - Track performance of entire affiliate networks
Advanced Tracking
Powerful tracking system to monitor affiliate performance:
- Cookie-based Tracking - Reliable tracking using secure cookies
- Click Analytics - Detailed click tracking with geographic data
- Conversion Tracking - Track conversions from multiple sources
- Attribution Windows - Configurable attribution periods
- UTM Parameter Support - Track campaigns with UTM parameters
Affiliate Dashboard
Your affiliates get access to a comprehensive dashboard featuring:
- Performance Overview - Real-time statistics and earnings
- Link Generator - Easy affiliate link creation tool
- Commission History - Detailed commission tracking
- Payout Requests - Simple payout request system
- Team Management - Manage sub-affiliates and referrals
- Marketing Materials - Access to promotional resources
Admin Features
Powerful admin interface for complete program management:
- Affiliate Management - Approve, suspend, and manage affiliates
- Commission Control - Review and approve commissions
- Payout Processing - Handle payout requests efficiently
- Detailed Reports - Comprehensive analytics and reporting
- Settings Management - Flexible configuration options
- WooCommerce Integration - View affiliate data in order details
Developer Friendly
Built with developers in mind:
- REST API - Complete REST API for custom integrations
- Hooks & Filters - Extensive hooks for customization
- Clean Code - PSR-12 compliant, well-documented code
- Database Structure - Optimized database design
- Security First - Built with WordPress security best practices
Installation
- Upload the plugin files to the
/wp-content/plugins/affinite-wp-affiliatedirectory, or install the plugin through the WordPress plugins screen directly. - Activate the plugin through the 'Plugins' screen in WordPress.
- Use the Affiliates->Settings screen to configure the plugin.
- Create affiliate pages using the provided shortcodes or Gutenberg blocks.
Minimum Requirements
- WordPress 5.9 or greater
- PHP 8.1 or greater
- WooCommerce 5.0 or greater (recommended but not required)
Automatic installation
Automatic installation is the easiest option -- WordPress will handle the file transfer, and you won't need to leave your web browser. To do an automatic install of Affinite WP Affiliate, log in to your WordPress dashboard, navigate to the Plugins menu, and click "Add New."
In the search field type "Affinite WP Affiliate," then click "Search Plugins." Once you've found us, you can view details about it such as the point release, rating, and description. Most importantly of course, you can install it by! Click "Install Now," and WordPress will take it from there.
Manual installation
Manual installation method requires downloading the plugin and uploading it to your web server via your favorite FTP application. The WordPress codex contains instructions on how to do this here.
Frequently Asked Questions
Does this plugin work with WooCommerce?
Yes! Affinite WP Affiliate is designed to work seamlessly with WooCommerce. It automatically tracks WooCommerce orders and calculates commissions based on your settings.
Can I track conversions from custom forms?
Absolutely! The plugin includes support for tracking conversions from custom forms using our REST API or JavaScript tracking.
How many affiliate levels can I have?
You can configure up to 5 affiliate levels (tiers) with different commission rates for each level.
Can affiliates see their earnings in real-time?
Yes, affiliates have access to a comprehensive dashboard showing real-time statistics, earnings, and commission history.
Is there a REST API available?
Yes, we provide a complete REST API for custom integrations and mobile app development.
How are commissions calculated?
Commissions can be calculated as a percentage of the order value or as a fixed amount. You can set global rates or individual rates for each affiliate.
Can I approve commissions manually?
Yes, you have full control over commission approval. You can enable automatic approval or manually review each commission.
What payment methods are supported for payouts?
The plugin supports various payout methods including bank transfers, PayPal, and checks. Payment processing is handled manually by administrators.
Screenshots
- Affiliate dashboard showing performance overview
- Admin area for managing affiliates
- Commission tracking and management
- Payout request interface
- Detailed reporting and analytics
- Settings configuration panel
Changelog
1.2.0
Security + performance hardening release. Resolves all 12 CRITICAL and 15 HIGH findings from the 2026-05-27 internal audit (38 work units total).
⚠️ Breaking change: the REST endpoint POST /wp-json/affinite-affiliate/v1/track/conversion now requires an X-Affinite-API-Key header. The plugin generates a 48-character key on activation; retrieve it with wp option get affinite_wp_affiliate_api_key. Anonymous callers are refused with 401. Per-IP rate limit (10 requests / 60 s) applied.
Security:
- Stored XSS fixes in
frontend.js(3 spots) andadmin.js+AdminManager.phpinline scripts (5 spots). - SQL injection — all assembled queries now use outer
$wpdb->prepare()with explicit placeholders. - Open redirect on affiliate-supplied
target_url—wp_safe_redirectwith scopedallowed_redirect_hostsfilter, scheme allowlist, redirect-code allowlist[301, 302]. - Removed PHP
session_start()fromTrackingManager— restores Varnish / WP Rocket / W3TC page-cache compatibility. Session fixation vector also closed. track_link_clickdata corruption fixed — the UPDATE used to match byaffiliate_idand overwritelink_idon every prior click. Now updates by primary key, and the redirect handler properly inserts a click row first.- Recursive team query rewritten as iterative BFS with depth + size guards (
max_depth=10,max_members=10000). - IP spoofing protection —
get_client_ip()defaults toREMOTE_ADDRonly. Proxy headers (CF, X-Forwarded-For, Client-IP) honoured only when the newaffinite_wp_affiliate_trust_proxy_headersoption is'yes'. - Allowlist validation for
status,commission_type,payment_methodvia sharedPlugin::*constants. - Login pre-auth no longer leaks account state (
pending/suspended) — status-specific messages only surface after the password matches. - Defense-in-depth
current_user_can('manage_options')check at the top of all 7 admin page renders. - Template XSS + spoofable
?message=affiliate_createdadmin notice replaced with one-shot per-user transient. - REST args now declare proper
enumvalidation at the route level.
Performance:
- Stats query cache (5-minute transients with CRUD-time invalidation) —
get_commission_stats6 queries → 1 single-aggregate,/stats/overview10 queries → cached,update_statistics5 queries → 3. - N+1 fixed on the commissions admin page — new
AffiliateRepository::get_by_ids()does one batchedWHERE IN (...)query; the row loop now hits a keyed map. get_current_affiliate()per-instance cache + 2 redundantCOUNT(*)queries dropped.- Conditional asset enqueue —
frontend.css/jsonly on affiliate pages, the ~200 KB Chart.js CDN bundle only on the dashboard. - Index-friendly date queries — 4 reporting methods swap
MONTH() / YEAR()predicates for half-open>= AND <ranges. - Slim dropdown query for the commissions filter (
get_dropdown_options) — 4 columns instead of 30 for hundreds of rows. - Batched
update_statistics()in refund flow — called once per unique affiliate instead of per commission. - Cron scheduling moved into
single_activate()(saves 2 options reads per request). Daily / hourly callbacks wired up. - All 26
register_setting()and 14add_option()calls passautoload=false.
Architecture & maintainability:
Plugin::VERSIONnow derived fromAFFINITE_WP_AFFILIATE_VERSION(single source of truth).- dbDelta schema migration fixed —
IF NOT EXISTSremoved from all 11 DDL statements,DatabaseInstaller::DB_VERSIONconst added, auto-migration on admin requests. - Optional DI for
CommissionManagerintoAffiliateManager(removes runtimerequire_once). AdminManager::register_ajax_handlers()runs unconditionally (no longer dependent on admin context).- Per-column WHERE builder in
CommissionManager::get_report_overview()— drops the fragilestr_replace('created_at', 'clicked_at', ...)pattern. - Explicit column-format array on
AffiliateRepository::create(). frontend.jscopyText()helper —navigator.clipboard.writeTextfirst,execCommandfallback.clicks-chart.jsreads REST URL fromwindow.affiniteClicksChart.restUrl(works on subfolder installs).- CSS chart-color custom properties (
--affinite-chart-clicks,--affinite-chart-conversions).
Code quality:
- All production
console.logstatements removed (10 in total). - SQL prepare consistency across
Plugin::get_blog_ids(),CommissionManagerstatic reports, anduninstall.php. - i18n hygiene — numbered
%1$s..%n$splaceholders,esc_url_rawon email URLs,wp_unslash + sanitize_text_fieldonHTTP_USER_AGENT. - 89 inline
style=attributes inAdminManager.phpreduced to 36 (-60 %) via new utility classes (affinite-stats-row,affinite-stat-card,affinite-stat-label,affinite-stat-value+ variants).
Documentation:
docs/structure — root markdowns moved intodocs/audits/,docs/guides/,docs/specs/.- 13 per-task decision records under
docs/decisions/covering each work unit.
1.1.0
- Added custom currency system independent from WooCommerce
- Added currency settings page with support for 30+ currencies
- Added CurrencyHelper class for centralized currency management
- Added currency formatting options (position, decimals, separators)
- Added Czech (cs_CZ) translation - complete localization
- Updated all price displays to use new currency system
- Updated affiliate dashboard to show prices in configured currency
- Updated payout requests to use custom currency formatting
- Updated commission displays across admin and frontend
- Fixed currency consistency across the entire plugin
1.0.0
- Initial release
- Multi-tier affiliate system
- WooCommerce integration
- Custom form tracking
- REST API
- Affiliate dashboard
- Commission management
- Payout system
- Detailed reporting
Upgrade Notice
1.2.0
Comprehensive security + performance release. ⚠️ Breaking change: the REST /track/conversion endpoint now requires an X-Affinite-API-Key header — retrieve the activation-generated key with wp option get affinite_wp_affiliate_api_key and configure your server-to-server integrations. Sites that don't use that endpoint do not need to act. Schema is auto-migrated on the next admin request. PHP sessions removed (page-cache compatible). See the full changelog for the 38 work units addressed.
1.1.0
Version 1.1.0 adds a custom currency system and complete Czech translation. You can now choose from 30+ currencies and customize formatting.
1.0.0
Initial release of Affinite WP Affiliate plugin.
Development
This plugin is actively developed on GitHub. Contributions are welcome!
Support
For support, please visit our website or contact us through the WordPress support forums.
Privacy Policy
Affinite WP Affiliate collects and stores affiliate performance data including clicks, conversions, and commission information. This data is used solely for affiliate program management and is not shared with third parties without explicit consent.
Third Party Services
This plugin may integrate with third-party services for payment processing and email notifications. Please review the privacy policies of any connected services.
Credits
Developed by the Affinite team