﻿=== affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display ===
Contributors: cservit 
Tags: affiliate, amazon, ebay, awin, product display
Requires at least: 5.6
Tested up to: 7.0
Stable tag: 3.9.1
Requires PHP: 8.2
License: GPLv2 or later
License URI: http://www.gnu.org/licenses/gpl-2.0.html

Fast & Compatible with every WordPress Theme: With our plugin for WordPress, you can easily create and add your affiliate products to your website.

== Description ==

[vimeo https://vimeo.com/761349407]

**The most powerful affiliate plugin for WordPress** – Create professional affiliate websites with Amazon, eBay, AWIN, and 20+ other networks. Build comparison tables, import products automatically, and monetize your content with ease.

affiliate-toolkit is the perfect solution for bloggers, niche site owners, and affiliate marketers who want to create professional product presentations without coding. Use our modern templates, powerful import features, and extensive customization options to build your affiliate business.

**🚀 Key Highlights:**
* **Multi-Network Support** – Connect to Amazon, eBay, AWIN, CSV feeds, and many more
* **Flexible Templates** – 20+ ready-to-use templates for product boxes, comparison tables, lists
* **Smart Import** – Bulk import products, bestseller lists, and search results
* **100% Cache Compatible** – Works perfectly with WP Rocket, W3 Total Cache, and more
* **Gutenberg & Classic Editor** – Full support for both editors

**📚 Resources:**
* [Plugin Homepage](https://www.affiliate-toolkit.com/)
* [Documentation & Tutorials](https://www.affiliate-toolkit.com/kb/)
* [Support Tickets](https://www.affiliate-toolkit.com/create-support-ticket/)

= Core Features (Free): =

**Product Management**
*   Visual shortcode generator with live preview
*   Import products individually or in bulk
*   Search and filter products from backend
*   Manual product creation with custom data
*   Product categories and taxonomies
*   Multiple product variations support

**Display & Templates**
*   50+ professional templates included
*   Product boxes, comparison tables, and lists
*   Fully responsive and mobile-optimized
*   Custom template editor with Blade syntax
*   Template import/export functionality
*   Customizable colors, fonts, and styles

**Amazon Integration**
*   Amazon Product Advertising API 5.0 support
*   Import via ASIN, keyword, or bestseller lists
*   All 22 Amazon marketplaces supported
*   Automatic price and availability updates
*   Star ratings and customer reviews
*   Amazon No-API mode available (addon)

**Performance & Compatibility**
*   100% compatible with all caching plugins
*   Lazy loading and AJAX support
*   Image proxy for faster loading
*   Works with Gutenberg and Classic Editor
*   Multisite support
*   HTTPS/SSL ready

= Premium Extensions: =

**🤖 AI Assistant** [Coming Soon]
*   AI-powered content generation (titles, descriptions, pros/cons)
*   Automatic product scoring and quality analysis
*   SEO-optimized alt text generation
*   AI template generator with natural language
*   Support for OpenAI GPT-4 and Anthropic Claude

**📊 Price History** ([Learn more](https://www.affiliate-toolkit.com/downloads/price-history/))
*   Track and display price changes over time
*   Beautiful price history charts
*   Price drop notifications
*   Historical data analysis

**🔍 Frontend Search and Filter** ([Learn more](https://www.affiliate-toolkit.com/downloads/frontend-search-filter/))
*   Live product search for frontend
*   AJAX-powered instant results
*   Customizable search widgets
*   Filter by category, price, rating

**📋 Comparison Tables** ([Learn more](https://www.affiliate-toolkit.com/downloads/responsive-compare-table/))
*   Create professional comparison tables
*   Side-by-side product comparisons
*   Custom fields and attributes
*   Mobile-responsive tables

**🛍️ WooCommerce Connector** ([Learn more](https://www.affiliate-toolkit.com/downloads/woocommerce-connector/))
*   Sync affiliate products with WooCommerce
*   Use WooCommerce checkout for external products
*   Combine physical and affiliate products

**🌍 Geolocation** ([Learn more](https://www.affiliate-toolkit.com/downloads/geo-targeting-for-affiliate-products/))
*   Show products based on visitor's location
*   Automatic currency conversion
*   Country-specific affiliate links
*   IP-based redirection

**📱 Product Pages** ([Learn more](https://www.affiliate-toolkit.com/downloads/frontend-product-pages/))
*   Create dedicated product landing pages
*   Custom page templates
*   SEO-optimized product pages
*   Full design control

**📋 Import Sets** ([Learn more](https://www.affiliate-toolkit.com/downloads/importsets-for-products/))
*   Manage multiple import configurations
*   Schedule different import tasks
*   Organize imports by category or campaign
*   Batch processing for large datasets

**📤 Field Export** ([Learn more](https://www.affiliate-toolkit.com/downloads/product-field-export/))
*   Export product data to CSV
*   Custom field selection
*   Bulk data management
*   Integration with third-party tools

**🎨 Template Packs** ([Learn more](https://www.affiliate-toolkit.com/downloads/template-pack/))
*   Premium template collections
*   Industry-specific designs
*   Conversion-optimized layouts
*   Regular new template releases

**⚙️ Custom Fields** ([Learn more](https://www.affiliate-toolkit.com/downloads/custom-fields/))
*   Add unlimited custom product fields
*   Custom taxonomies and attributes
*   Advanced filtering options
*   Flexible data structure

**📄 XML Import** [Coming Soon]
*   Import from XML feeds
*   Support for various XML formats
*   Automatic field mapping
*   Scheduled XML imports

**🧱 Gutenberg Blocks**
*   Native Gutenberg blocks for products and lists
*   Drag-and-drop interface with live preview
*   Inline product and list selection
*   Direct product import from shops
*   Block-based content editing
*   Full German translation support

**🔗 Network Connectors**
*   eBay Product API ([Learn more](https://www.affiliate-toolkit.com/downloads/ebay-product-import/))
*   AWIN Product Feed ([Learn more](https://www.affiliate-toolkit.com/downloads/awin-product-importer/))
*   Geizhals.at ([Learn more](https://www.affiliate-toolkit.com/downloads/geizhals-wordpress-plugin/))
*   Billiger.de ([Learn more](https://www.affiliate-toolkit.com/downloads/billiger-de-product-import/))
*   TradeDoubler ([Learn more](https://www.affiliate-toolkit.com/downloads/tradedoubler-product-import/))
*   Tracedelight
*   Yadore ([Learn more](https://www.affiliate-toolkit.com/downloads/yadore-product-import/))
*   Belboon, Commission Junction (CJ)  and other networks via CSV feed
*   and more

**🎨 Compatibility Modes**
*   ASA 1 & ASA 2 compatibility ([free addon](https://www.affiliate-toolkit.com/downloads/asa-1-asa-2-compatiblity-mode/))
*   AAWP compatibility ([free addon](https://www.affiliate-toolkit.com/downloads/aawp-compatibility/))
*   Amazon Site Stripe replacement ([free addon](https://www.affiliate-toolkit.com/downloads/amazon-site-stripe-compatibility-mode/))

= Supported Affiliate Networks: =
Amazon (22 countries), eBay, AWIN, Commission Junction, Geizhals, Billiger.de, TradeDoubler, Tracedelight, Yadore, Belboon, Custom CSV Feeds

= Supported Countries (Amazon): =
🌍 Australia, Belgium, Brazil, Canada, China, Egypt, France, Germany, India, Italy, Japan, Mexico, Netherlands, Poland, Saudi Arabia, Singapore, Spain, Sweden, Turkey, United Arab Emirates, United Kingdom, USA

= Supported languages: =
*   German
*   English
*   Translatable with *.po files

= Need more features? =
Search in our extensions and download the extensions you need. Upload the extension as plugin and activate it.

Our free and premium extensions:
https://www.affiliate-toolkit.com/extensions/

Get affiliate-toolkit now: <a href="https://www.affiliate-toolkit.com/pricing/">https://www.affiliate-toolkit.com/pricing/</a>


<br /><br />




= German/Deutsch =

[vimeo https://vimeo.com/761349365]

**Das leistungsstärkste Affiliate-Plugin für WordPress** – Erstelle professionelle Affiliate-Websites mit Amazon, eBay, AWIN und über 20 weiteren Netzwerken. Erstelle Vergleichstabellen, importiere Produkte automatisch und monetarisiere deinen Content mit Leichtigkeit.

affiliate-toolkit ist die perfekte Lösung für Blogger, Nischenwebsites und Affiliate-Marketer, die professionelle Produktpräsentationen ohne Programmierung erstellen möchten. Nutze unsere modernen Templates, leistungsstarke Import-Funktionen und umfangreiche Anpassungsoptionen für dein Affiliate-Business.

**🚀 Highlights:**
* **Multi-Netzwerk-Support** – Verbinde Amazon, eBay, AWIN, CSV-Feeds und viele mehr
* **Flexible Templates** – 20+ einsatzbereite Templates für Produktboxen, Vergleichstabellen, Listen
* **Smart Import** – Massenimport von Produkten, Bestseller-Listen und Suchergebnissen
* **100% Cache-kompatibel** – Funktioniert perfekt mit WP Rocket, W3 Total Cache und mehr
* **Gutenberg & Classic Editor** – Volle Unterstützung für beide Editoren

**📚 Ressourcen:**
* [Plugin Homepage](https://www.affiliate-toolkit.com/de/)
* [Dokumentation & Tutorials](https://www.affiliate-toolkit.com/de/kb/)
* [Support Tickets](https://www.affiliate-toolkit.com/de/support-ticket-erstellen/)

= Kernfunktionen (Kostenlos): =

**Produktverwaltung**
* Visueller Shortcode-Generator mit intuitiver Oberfläche
* Einzel- oder Massenimport von Produkten
* Suchen und Filtern von Produkten im Backend
* Manuelle Produkterstellung mit individuellen Daten
* Produktkategorien und Taxonomien
* Unterstützung für mehrere Produktvarianten

**Darstellung & Templates**
* Über 20 professionelle Templates inklusive
* Produktboxen, Vergleichstabellen und Listen
* Vollständig responsive und mobil-optimiert
* Custom Template Editor mit Blade-Syntax
* Template Import/Export Funktionalität
* Anpassbare Farben, Schriften und Stile

**Amazon-Integration**
* Amazon Product Advertising API 5.0 Support
* Import via ASIN, Keyword oder Bestseller-Listen
* Alle 22 Amazon-Marktplätze unterstützt
* Automatische Preis- und Verfügbarkeitsaktualisierungen
* Sternebewertungen und Kundenbewertungen
* Amazon No-API Modus verfügbar (Addon)

**Performance & Kompatibilität**
* 100% kompatibel mit allen Caching-Plugins
* Lazy Loading und AJAX-Support
* Bild-Proxy für schnelleres Laden
* Funktioniert mit Gutenberg und Classic Editor
* Multisite-Unterstützung
* HTTPS/SSL ready

= Premium-Erweiterungen: =

**🤖 AI Assistant** [Bald verfügbar]
* KI-gestützte Content-Generierung (Titel, Beschreibungen, Pro/Contra)
* Automatische Produktbewertung und Qualitätsanalyse
* SEO-optimierte Alt-Text-Generierung
* KI Template Generator mit natürlicher Sprache
* Unterstützung für OpenAI GPT-4 und Anthropic Claude

**📊 Price History** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/preisentwicklung/))
* Verfolge und zeige Preisänderungen über die Zeit
* Wunderschöne Preisverlaufs-Diagramme
* Preissenkungsbenachrichtigungen
* Historische Datenanalyse

**🔍 Frontend Suche & Filter** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/frontend-suche-filter/))
* Live-Produktsuche für das Frontend
* AJAX-gestützte Sofortergebnisse
* Anpassbare Such-Widgets
* Filter nach Kategorie, Preis, Bewertung

**📋 Vergleichstabellen** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/responsive-vergleichstabelle/))
* Erstelle professionelle Vergleichstabellen
* Produkte nebeneinander vergleichen
* Individuelle Felder und Attribute
* Mobile-responsive Tabellen

**🛍️ WooCommerce Connector** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/woocommerce-affiliate-plugin/))
* Synchronisiere Affiliate-Produkte mit WooCommerce
* Nutze WooCommerce-Checkout für externe Produkte
* Kombiniere physische und Affiliate-Produkte

**🌍 Geolocation** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/geo-targeting-fuer-affiliate-produkte/))
* Zeige Produkte basierend auf Besucherstandort
* Automatische Währungsumrechnung
* Länderspezifische Affiliate-Links
* IP-basierte Weiterleitung

**📱 Product Pages** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/frontend-produktseiten/))
* Erstelle dedizierte Produkt-Landing-Pages
* Custom Page Templates
* SEO-optimierte Produktseiten
* Volle Design-Kontrolle

**📋 Import Sets** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/importsets-fuer-produkte/))
* Verwalte mehrere Import-Konfigurationen
* Plane unterschiedliche Import-Aufgaben
* Organisiere Imports nach Kategorie oder Kampagne
* Batch-Verarbeitung für große Datenmengen

**📤 Field Export** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/produktfeld-export/))
* Exportiere Produktdaten nach CSV
* Individuelle Feldauswahl
* Massendatenverwaltung
* Integration mit Tools von Drittanbietern

**🎨 Template Packs** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/template-pack/))
* Premium Template-Sammlungen
* Branchenspezifische Designs
* Conversion-optimierte Layouts
* Regelmäßig neue Template-Releases

**⚙️ Custom Fields** ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/benutzerdefinierte-felder/))
* Füge unbegrenzte individuelle Produktfelder hinzu
* Custom Taxonomien und Attribute
* Erweiterte Filteroptionen
* Flexible Datenstruktur

**📄 XML Import** [Bald verfügbar]
* Import aus XML-Feeds
* Unterstützung verschiedener XML-Formate
* Automatisches Feld-Mapping
* Geplante XML-Imports

**🧱 Gutenberg Blocks**
* Native Gutenberg-Blöcke für Produkte und Listen
* Drag-and-Drop Interface
* Live-Vorschau im Editor
* Block-Templates und Patterns

**🔗 Netzwerk-Konnektoren**
* eBay Product API ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/ebay-affiliate-produkt-import/))
* AWIN Product Feed ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/awin-affiliate-produkt-importer/))
* Geizhals.at ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/geizhals-wordpress-plugin/))
* Billiger.de ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/billiger-de-wordpress-plugin/))
* TradeDoubler ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/tradedoubler-affiliate-wordpress-plugin/))
* Tracedelight
* Yadore ([Mehr erfahren](https://www.affiliate-toolkit.com/de/downloads/yadore-wordpress-plugin/))
* Belboon, Commission Junction (CJ) und andere Netzwerke via CSV Feed
* und mehr

**🎨 Kompatibilitätsmodi**
* ASA 1 & ASA 2 Kompatibilität ([kostenloses Addon](https://www.affiliate-toolkit.com/de/downloads/asa-1-asa-2-kompatibilitaetsmodus/))
* AAWP Kompatibilität ([kostenloses Addon](https://www.affiliate-toolkit.com/de/downloads/aawp-kompatibilitaetsmodus/))
* Amazon Site Stripe Ersatz ([kostenloses Addon](https://www.affiliate-toolkit.com/de/downloads/amazon-site-stripe-kompatibilitaetsmodus/s))

= Unterstützte Affiliate-Netzwerke: =
Amazon (22 Länder), eBay, AWIN, Commission Junction, Geizhals, Billiger.de, TradeDoubler, Tracedelight, Yadore, Belboon, Custom CSV Feeds

= Unterstützte Länder (Amazon): =
🌍 Australien, Belgien, Brasilien, China, Deutschland, Ägypten, Frankreich, Indien, Italien, Japan, Kanada, Mexiko, Niederlande, Polen, Saudi-Arabien, Schweden, Singapur, Spanien, Türkei, Vereinigte Arabische Emirate, Vereinigtes Königreich, USA

= Unterstützte Sprachen: =
* Deutsch
* Englisch
* Übersetzbar mit *.po-Dateien

= Benötigst du weitere Funktionen? =
Durchsuche unsere Erweiterungen und lade die gewünschten Erweiterungen herunter. Die Erweiterung kannst du einfach als Plugin hochladen und aktivieren.

Unsere kostenlosen und Premium-Erweiterungen:
https://www.affiliate-toolkit.com/de/erweiterungen/

Hol dir das Affiliate-Toolkit jetzt: <a href="https://www.affiliate-toolkit.com/de/preise/">https://www.affiliate-toolkit.com/de/preise/</a>

== Installation ==

1. Upload the plugin via **Plugins → Add New → Upload Plugin** or extract the zip file into the `wp-content/plugins/` directory.
2. Activate the plugin from the **Plugins** page.
3. Navigate to **affiliate-toolkit → Shops** and create a new shop (e.g. Amazon with Creator API).
4. Import products via **affiliate-toolkit → Products → Import** or create them manually.
5. Display products in your posts or pages using the **Gutenberg product box block** or the **shortcode generator**.

== Frequently Asked Questions ==

**Is the plugin completely free?**
Yes, the core plugin is completely free and includes product management, templates, and Amazon integration.

**What if I need more features?**
Premium extensions for additional networks (AWIN, eBay, CJ, etc.), AI content generation, price history, and more are available at [affiliate-toolkit.com](https://www.affiliate-toolkit.com/).

**Do I need an Amazon API key?**
No. You can use the Amazon Creator API or the No-API mode to import products without the traditional Product Advertising API. However, using the PA-API gives you access to more product data and automatic updates.

**Which affiliate networks are supported?**
The free version supports Amazon. With premium extensions you can connect to AWIN, eBay, Commission Junction, Tradedoubler, and 20+ other networks, or import products via CSV feeds.

**Does the plugin work with my theme?**
Yes, affiliate-toolkit is designed to work with any WordPress theme. All templates are fully responsive and adapt to your theme's styling.

**Is the plugin compatible with caching plugins?**
Yes, it works with all major caching plugins including WP Rocket, W3 Total Cache, WP Super Cache, and LiteSpeed Cache.

**Can I use the plugin with Gutenberg?**
Yes, affiliate-toolkit provides a dedicated Gutenberg block for displaying product boxes directly in the block editor. You can also use shortcodes in any editor.

**How do I display products on my site?**
After importing products, you can display them using the Gutenberg product box block or the shortcode generator. The shortcode generator lets you choose from different templates and search for products directly.

== Screenshots ==
1. Shop setup with Amazon Creator API and No-API mode.
2. Shortcode generator with template type selection.
3. Product search within the shortcode generator.
4. Gutenberg editor with the affiliate-toolkit product box.

 
== Changelog ==
= 3.9.1 =
*   SECURITY: Fixed Remote Code Execution by low-privileged users (Contributor and above) — reported by Artus KG via WPScan. This is a complete fix for the incomplete patch of CVE-2026-6169. Template bodies are compiled and executed by the BladeOne engine, but the template renderer accepted any post id and read its atkp_template_body custom field, so a Contributor could turn their own draft post into an executable template. Template references are now resolved through a single guard that only accepts posts of the administrator-only atkp_template post type. The guard is applied to all four render paths: the AJAX render endpoint, the shortcode/product output, the live search template output, and @include/@extends targets inside the template engine.
*   SECURITY: Hardened the template sanitizer as defence in depth. In addition to literal PHP tags it now also strips the Blade directives that exist purely to emit raw PHP (@php, @php ... @endphp) or to instantiate an arbitrary class (@inject). Note that the sanitizer alone can never make an untrusted template safe — most of the Blade language embeds its expression into the compiled PHP — which is why the post type check above is the actual fix.
*   SECURITY: The template sanitizer is now also applied on the live search template path and on @include/@extends targets, which previously bypassed it entirely.
*   PERFORMANCE: Added a missing index on wp_atkp_queues_entries (post_id, id). The "Queue History" metabox in the product, list and shop editor reads the most recent queue entries for the edited post, but the table only had indexes on queue_id. On large installations MySQL had to scan the whole table backwards through the primary key for every editor page load — on a table with 1.1 million entries this single query took up to 10 seconds. With the index it is an index lookup of only the matching rows (~2 ms). Reported by a customer with database-level analysis.
*   FIX: Queue table index creation is now idempotent. On a table structure version bump the existing CREATE INDEX statements were executed again and failed with MySQL error 1061 ("Duplicate key name"). Indexes are now only created when they do not exist yet, and a manually created index on post_id is detected so no redundant second index is added.
*   FIX: A PHP Error (e.g. TypeError) inside a shop provider no longer stops the cronjob permanently. The queue processing only caught Exception, so a PHP Error escaped both the inner and the outer handler and killed the run before the entry statuses were written. The same batch of 10 entries was then fetched again on every following cron run, the queue stayed "active" forever and — because queue cleanup only runs after a queue completes — old queues were never deleted again. All cronjob handlers now catch Throwable and mark the affected entries as errors so the queue can continue.
*   FIX: Endless loop in the queue processing when an atkp_queue_process_entries_* filter returns only part of the entries it was given. The dropped entries kept the status "prepared" and were delivered again by get_next_entries on every iteration. They are now marked as not processed, like entries the filter leaves untouched.
*   FIX: The "Delete" row action in the queue and template lists always failed with "Go get a life script kiddies". The link was created with the nonce action atkp_edit_queue/atkp_edit_template but verified against atkp_delete_link.
*   IMPROVED: The active queue is now selected deterministically (oldest first) instead of relying on the storage order of the table.
*   NEW: Stalled queues are detected and aborted. A queue that makes no progress across several cron runs — because the same package always dies on a fatal error, a timeout or out of memory — used to stay "active" forever, which blocked every new queue and stopped the cleanup of old queues. The number of open entries is now tracked per run (in internalstatus); if it does not change for 3 consecutive runs and no entry has been written for 30 minutes, the queue is set to "abort", the remaining entries are marked as errors and the next cron run starts a fresh queue. Both thresholds are filterable via atkp_queue_stall_minutes and atkp_queue_max_stall_retries, and the new action atkp_queue_aborted fires on abort.
*   IMPROVED: Old queues are now cleaned up on every cron run instead of only after a queue has completed, so a single stalled queue can no longer stop the cleanup permanently. Active queues are excluded from the cleanup so the queue currently being processed is never deleted.
*   PERFORMANCE: Added an index on wp_atkp_queues_entries (queue_id, updatedon). The cronjob reads the last entry activity of the running queue on every run, which previously sorted all entries of that queue (on large installations hundreds of thousands of rows) instead of doing an index lookup.
*   IMPROVED: The "Retries" column of the queue list now shows the number of cron runs without progress. The counter is reset as soon as the queue advances, so it no longer grows with the plain number of runs.
*   FIX: The disclaimer with the "Last updated on ..." line was missing in all templates — most visibly in the WooCommerce price comparison tab, where it is the only place the update time is shown. The option cache introduced in 3.8 carries its own table of fallback values, and because that table pre-seeds every key, isset() always matched and the real defaults in atkp_options were never reached. show_disclaimer therefore resolved to 0 and disclaimer_text to an empty string on every installation that had not explicitly saved the display settings. An option value that was actually saved — including a deliberately emptied disclaimer text — still takes precedence.
*   FIX: A default value passed by the caller now takes precedence over the option cache's fallback table whenever the option has never been saved, which is how get_option() behaved before the cache was introduced. This also corrected the fallbacks for add_to_cart and boxcontent, which contradicted their getters as well (both were masked by default branches in the consuming switch statements and had no visible effect).
*   FIX: Undefined variable $hidedisclaimer in the AJAX render path. The disclaimer is now controlled by the template parameters there as well, so the hidedisclaimer attribute of the shortcode and a template-specific disclaimer text are honored on the AJAX path too.
*   FIX: The "disable disclaimer" flag of a template (used by compatibility templates) was only honored on the AJAX render path and ignored everywhere else. It is now evaluated once in atkp_template_parameters::buildTemplateArray(), so it applies on every output path — including the @if($parameters->get_show_disclaimer()) checks inside the Blade templates, which never saw the flag at all. The duplicated check in the AJAX path was removed.
*   FIX: Two disclaimers were rendered inside one product box when a template that carries a disclaimer block (for example "Price comparison (simple)", "Price comparison" or a custom template) was selected as the template for the additional offers. The dropdown for that sub-template is filled from the same flat list as the main template, so the inner @include produced a second "Last updated on ..." line in the middle of the box. The disclaimer is now only rendered by the outermost template; BladeOne tracks the nesting level of @include for that, and both atkp_template_parameters::get_show_disclaimer() and atkp_formatter::get_disclaimer() evaluate it. Custom templates stored in the database benefit from this without being edited.
*   FIX: Product images were not imported from shops whose CDN rejects requests that do not look like a browser (403 Forbidden). The image download built a stream context with a User-Agent header but then never passed it to file_get_contents(), so every image was requested without a User-Agent, an Accept and a Referer header. Images are now downloaded through the WordPress HTTP API with a desktop browser user agent and a referer pointing at the image host. A 403 or 429 is retried once with the Googlebot image crawler user agent, because hotlink protections and bot filters commonly let the search engine crawlers through. The request arguments and the list of user agents are filterable via atkp_image_download_args and atkp_image_download_useragents. Note that a 403 caused by the server ip being blocked or rate limited cannot be solved with request headers - the log now contains the HTTP status code to tell the two cases apart.
*   FIX: The error logged for a failed image download came from error_get_last() and could therefore show a completely unrelated PHP notice instead of the actual reason. The HTTP status code or transport error of the image request is logged now.
*   FIX: An image url with a query string (for example image.jpg?ts=1790734482) lost its file extension, because the extension was taken with strrchr() from the whole url instead of its path, and the result was longer than three characters. Every such image was stored as .jpg - a .png or .gif therefore ended up with a mime type that did not match its content. The extension is now read from the url path, and four character extensions (jpeg, avif) are accepted as well.
*   FIX: Images are no longer stored with a wrong extension when the shop CDN does content negotiation. Such a CDN answers a .jpg url with a WebP or AVIF body as soon as a browser-like Accept header is sent. The Accept header deliberately does not offer those formats, and if the answer still has a different content type than the url suggests, the extension is taken from the content type.
*   IMPROVED: An error page that a CDN returns with status 200 instead of an error code is no longer stored as a product image. The response has to be an image by content type or by content, otherwise the download counts as failed.

= 3.9.0 =
*   FIX: Comparison table not rendered when tracking_id is set in shortcode (Creators API cart URLs use ?AssociateTag= instead of &AssociateTag= after removal of AWSAccessKeyId parameter)
*   FIX: Tracking code replacement errors no longer break entire template output (graceful fallback to original URL)
*   IMPROVED: Admin styles updated to use standard WordPress UI colors and buttons instead of custom branding
*   IMPROVED: Extensions page redesigned with installed/bundled status badges, version info, and cleaner layout

= 3.8.9 =
*   SECURITY: Fixed SQL Injection vulnerability in admin list tables (orderby parameter) — reported via Wordfence. orderby and order parameters are now validated against a strict whitelist of allowed column names instead of relying on esc_sql(), which does not protect unquoted SQL identifiers.

= 3.8.8 =
*   FIX: License check no longer invalidates active licenses when the API server is temporarily unreachable
*   FIX: License status comparison corrected from 'active' to 'valid' on the license settings page
*   FIX: Manual offers not displayed in the frontend due to wp_rand() returning positive shop IDs instead of negative
*   FIX: Template PHP sanitization now only applies to user-created templates (DB), not to built-in filesystem templates

= 3.8.7 =
*   NEW: Admin notice informing about the PHP tag filtering security feature (with explicit confirmation)
*   NEW: Option to disable PHP tag filtering in templates (Advanced Settings, requires explicit opt-in)
*   IMPROVED: Extension loading moved from init to plugins_loaded for better compatibility
*   IMPROVED: Minimum PHP version raised to 8.2
*   FIX: ATKP_StoreController class existence check added to prevent fatal errors in discount notifications

= 3.8.6 =
*   SECURITY: Raw PHP code (<?php ?> tags) is now automatically stripped from templates to prevent code injection via BladeOne eval()
*   FIX: Double-slash in API URLs to affiliate-toolkit.com
*   FIX: HTTP timeouts increased from 15s to 30s for license checks and store API calls
*   FIX: Sub-module plugins no longer trigger unnecessary WordPress.org update checks (Update URI header added)
*   FIX: Translation loading moved to init hook to prevent "too early" notices on WordPress 6.7+
*   FIX: JavaScript syntax error on bulk import page caused by wp_set_script_translations without JSON translation files
*   FIX: Incorrect escaping in inline JavaScript (esc_url/esc_html replaced with esc_js/esc_url_raw)
*   FIX: Embedded URLs in translatable strings now use sprintf placeholders for proper i18n
*   FIX: Undefined constant ATKP_PLUGIN_VERSION replaced with ATKP_UPDATE_VERSION
*   FIX: Dashicon vertical alignment in admin buttons
*   FIX: Auto-detect option removed from Amazon Creators credential version selector
*   FIX: Broken jQuery selector for search option radio buttons in bulk import

= 3.8.5 =
*   NEW: Amazon Creators API support
*   IMPROVED: Gutenberg editor button now opens shortcode generator on modal
*   IMPROVED: Iframe mode for shortcode generator (distraction-free interface)
*   IMPROVED: German translations updated
*   FIX: Improved null handling in product loading

= 3.8.4 =
*   FIX: Classic Editor shows the shortcode generator popup on page load
*   FIX: Images not showing on local product search in shortcode generator tool

= 3.8.3 =
*   FIX: Shortcode Generator now accessible for Editor role (users with edit_posts capability)
*   FIX: Shortcode Generator button with AT icon now opens in new tab
*   FIX: Shortcode Generator button now also available in Gutenberg classic block
*   FIX: Product images now displayed in Shortcode Generator search results (both imported and external products)
*   FIX: Product images now displayed in Gutenberg blocks for imported products
*   FIX: Clicking on product row (without import) in Shortcode Generator no longer auto-advances to prevent invalid shortcodes
*   FIX: After successful product import, Shortcode Generator now auto-advances to next step
*   IMPROVED: JavaScript cache-busting added to ensure latest versions are loaded
*   IMPROVED: Consistent product image display across Shortcode Generator and Gutenberg (60x60px, Flexbox layout)

= 3.8.2 =
*   fix: debug infos written into log file

= 3.8.1 =
*   NEW: Amazon PA-API 5.0 OffersV2 implemented
*   NEW: Modern shortcode generator with step-by-step wizard
*   NEW: Native Gutenberg block support integrated into core plugin (atkp/product and atkp/list blocks)
*   NEW: Create products and lists on-the-fly without leaving the editor
*   IMPROVED: Redesigned UI with modern card-based interface

= 3.8.0 =
*   fix: add license validation for shops and products, enhance live search error handling

= 3.7.9 =
*   fix: correct option name extraction in get_setting method
*   fix: issue with empty sub lists in shop

= 3.7.8 =
*   fix: correct option name extraction in get_setting method

= 3.7.7 =
*   fix: standardize spacing and formatting in various files
    Performance optimizations and code cleanups

= 3.7.6 =
*   Bugfix: image not loaded, shop logo alt text added

= 3.7.5 =
*   Bugfix: language was not loaded

= 3.7.4 =
*   Bugfix: template import/export
*   Fixed: Security issue (thanks to stealthcopter)

= 3.7.3 =
*   Minor fix

= 3.7.2 =
*   Bugfix: Shortcode link didn't worked
*   Changes for the Amazon NO Api Mode

= 3.7.1 =
*   Fixed: Security issue (thanks to Peter Thaleikis)

= 3.7.0 =
*   Bugfix: List import not importing product attributes
*   Bugfix: Shop config import was not working for csv shops

= 3.6.9 =
*   Fixed: shortcode was not processed

= 3.6.8 =
*   Fixed: Language issue (wp 6.7 update)
*   Fixed: Security issue (thanks to Peter Thaleikis)

= 3.6.7 =
*   Added option "Languages Of Preference" to the Amazon API

= 3.6.6 =
*   Fixed issue ajax load
*   Fixed: Security Issue

= 3.6.5 =
*   Fixed issue atkp list

= 3.6.4 =
*   Fixed issue WP_CLI cronjob
*   Fixed issue saving display settings

= 3.6.3 =
*   Fixed issue with list selection
*   Fixed Issue product import error esc_attr

= 3.6.2 =
*   Fixed issue with manual list
*   Fixed the naming of the plugin

= 3.6.1 =
*   Fixed: Html code display
*   Added Amazon Belgium support

= 3.6 =
*   Fixed: Security Issue
*   Added Escaping for output values

= 3.5.5 =
*   Fixed: Missing Authorization via AJAX (thanks to Lucio Sá)
*   Bugfix: Sometimes the info of the cronjob execution was not correct
*   Added global functions for displaying product data (https://www.affiliate-toolkit.com/kb/global-functions/)

= 3.5.4 =
*   Bugfix: Error on product view "get_smalllogourl"

= 3.5.3 =
*   Bugfix: Saving was not possible

= 3.5.2 =
*   New error handler: TypeError catch for some templates
*   Removed Rocketscrape key
*   Bugfix: product category now opened inside affiliate-toolkit menu
*   License key are now hidden
*   Bugfix: EAN was not enabled on product import
*   Display shop logo is now default enabled
*   Bugfix: Backend product view: Shop logos not displayed when filter was active
*   Added sorting to outdated products. In some cases (big datasets) the product was never updated.
*   Added global function atkp_display_box and atkp_get_largeimageurl to display product information without shortcode.
*   Added link into footer for rating - Please rate us :-)

= 3.5.1 =
*   Bugfix: Error on product search

= 3.5.0 =
*   Bugfix: atkp_queue table generation was not working

= 3.4.9 =
*   Support for umami.is tracking
*   Bugfix: Hide disclaimer was not working in shortcodes
*   Sitestripe: Added support for template

= 3.4.8 =
*   Bugfix: Sitestripe and product box template
*   New: Support for new Amazon No-API mode extension

= 3.4.7 =
*   Bugfix: Uncaught TypeError: Typed property atkp_queue_view::$saving must be an instance of mixed

= 3.4.6 =
*   Fixed: XSS issue (thanks to Ngô Thiên An)
*   Support for Amazon Site Stripe replacement extension: <a href="https://www.affiliate-toolkit.com/downloads/amazon-site-stripe-compatibility-mode/">Amazon Site Stripe Replacement</a>

= 3.4.5 =
*   Bugfix: image redirect for manual images
*   Security fix: log file location moved
*   Security fix: External cronjob added key check
*   *Important:* replace your existing cronjob url

= 3.4.4 =
*   Bugfix: image redirect for manual variants
*   Bugfix: EAN article number import was not correct
*   Fixed: Security issue for bulk import

= 3.4.3 =
*   Bugfix: image redirect for lists was not working

= 3.4.2 =
*   Fixed security issue for image redirect *Important: Clear your cache after plugin update.
*   Improvement for template editor
*   Improvement for template export and import

= 3.4.1 =
*   Added option to use price as fallback and not for overwrite

= 3.4.0 =
*   Fixed: Open Redirection vulnerability (thanks to minhtuanact)

= 3.3.9 =
*   Bugfix: Field percentagesaved was not exported
*   Bugfix: Import shop settings throw fatal error
*   New: Option for deactivating the select extension for the widget area
*   New: Hide primary and secondary button via display settings.
*   New: New "moreoffers" templates: "Additional offers (Buttons)" and "Additional offers (Logos)"

= 3.3.8 =
*   Bugfix: Customer ratings not showing
*   Bugfix: Exceptions in the template engine now are caught
*   Bugfix: Existence check improved
*   New: Welcome page on activation

= 3.3.7 =
*   Bugfix: Some extensions did not show an update.
*   Bugfix: German language file was not loaded for formal language
*   Added missing translations

= 3.3.6 =
*   Fixed: Cross-Site Scripting (XSS) vulnerability (thanks to Yuchen Ji)
*   Support for "lock ean,gtin,isbn"
*   Updated German translation
*   Bugfixes

= 3.3.5 =
*   Fixed: Cross-Site Scripting (XSS) vulnerability (thanks to hackintoanetwork)
*   Bugfix: Price  history: bugfix in removed shops
*   Support for Amazon Poland
*   Bugfix: Widget product select was not working
*   Bugfix: AWIN Subshops are deleted when subshop changed
*   Bugfix: Pagination was not working for templates

= 3.3.4 =
*   Fixed: Cross-Site Scripting (XSS) vulnerability (thanks to yuyudhn)
*   Fixed: Image loading checksum error
*   Optimized shop fields
*   Support for new "Import Set" functionality
*   Improved Amazon no api mode. Following countries supported: de,en,co.uk,ca,fr,co.jp,it,cn,es,in
*   Improved stars rating load
*   Rewrite of list load interface

= 3.3.3 =
*   add button "send report now"
*   bugfix: report was not sent
*   Bugfix: own features and description are now display when exists as default
*   Last product will not be removed. It will be hold until manual update.
*   moving child shops to trash

= 3.3.2 =
*   Redirect external logos via proxy
*   New: Hide offers
*   New: Feature/Description options for overwrite
*   New: "Saved" percent in templates
*   Amazon: Support for custom fields (filled when custom field exists): "a_color", "a_height", "a_length", "a_width", "a_weight"
*   New: Style option (inline, inline head, file)
*   New: Hide shop is now better visible
*   Bugfix: border radius fix for highlight

= 3.3.1 =
*   Bugfix: Posts view was not working

= 3.3.0 =
*   Bugfix: Product title and title hover remain black after saving
*   Bugfix: Tracking ID (override) in shortcodes was not replaced
*   Bugfix: WP backend menu closes in product category and template view
*   Setting "Default for the product box" removed
*   Hidden shops are now hidden marked in backend
*   Hidden shops are not displayed correct in frontend when offer is first position
*   Bugfix: Extensions view fixed
*   Bugfix: URL shortener was not working for subshops
*   Removed: goo.gl shortener is now removed (service disabled in 2019)
*   Bugfix: Title link color was not saved
*   New attribute: "ajax_mode='enabled' and 'disabled'"
*   New option: Enable ajax load functionality without loading all shortcodes via ajax
*   Improved: Loading of products via ASIN and EAN
*   Internal tables creation: Support for InnoDB and remove of MyISAM


= 3.2.9 =
*   Bugfix: Search via keyword does not always match
*   Bugfix: Price reduction was not calculated on cron update
*   Bugfix: Compare table lost styles
*   Bugfix: Activating Ajax loading gave error for some lists

= 3.2.8 =
*   Bugfix: Custom taxonomy placeholder was not working
*   Amazon: Replaced the amazon sitestripe function
*   Bugfix: Comparison Table showed error
*   Bugfix: Tradedoubler Update was not working
*   New Template: "Numbered product list"
*   New custom design functionality

= 3.2.7 =
*   Bugfix: Sortorder in field groups
*   Product load via slug
*   Bugfix: Redirect after duplicate in templates
*   Bugfix: Creation of products in list import
*   Bugfix: Admin links wrong link
*   Bugfix: Toolset compatiblity issue
*   Load products via Ajax

= 3.2.6 =
*   bugfixes
*   Added improvements to UI

= 3.2.5 =
*   Bugfix: settings page throws error
*   optimized the image loading via image proxy
*   improved the min/max offer change for productboxes
*   "group_result" parameter for grouping products (not showing every single offer)
*   added filter "atkp_product_filter_args" and "atkp_product_filter_has_wp_filter"
*   atkp shortcode shows now correct admin links

= 3.2.4 =
*   Bugfix: Lists are empty if "import" was enabled
*   Bugfix: Star rating not displayed if empty
*   Bugfix: Manual offers not displayed

= 3.2.3 =
*   Updated naming of setting tabs
*   Removed unused files
*   Added notification of discounts (disable via settings)

= 3.2.2 =
*   Bugfix: widget error
*   Bugfix: cronjob url fixed
*   New: Option to show or hide shop name
*   Prime logo replaced
*   Bugfix: Products were visible in frontend search
*   New: Shop logos now visible in backend

= 3.2.1 =
*   Improvement for loading extensions
*   Bugfix: "Umlaute" issue on product import

= 3.2.0 =
*   Compatiblity fixes

= 3.1.9 =
*   Relaunch of the complete plugin

= 2.7.5 =
*   Bugfix: affiliate char was not displayed after a link
*   Removed the amazon logo (https://forum.affiliate-toolkit.com/index.php?thread/657-h%C3%A4lt-das-plugin-die-amazon-teilnahmebedingungen-ein/)

= 2.7.4 =
*   Bugfix: Widget don't list products (select2 lib updated)

= 2.7.3 =
*   Bugfix: Guzzle Http Error (if BackWup is installed)

= 2.7.2 =
*   Bugfix: Fatal error when saving the amazon shop

= 2.6.6 =
*   Bugfix: Amazon v5 Api support

= 2.2 =
*   Bugfix: Percent character title will be now encoded

= 2.1 =
*   Bugfixes

= 2.0 =
*   Bugfixes
*   New shortcode-generator added (button in wordpress-editor "AT Shortcode")
*   Support for manual product lists
*   Support for own templates
*   and much more...

= 1.3 =
*   Bugfix: "Warning: Missing argument 6 for" 

= 1.2 =
*   Updated the readme.txt and adding the stable tag

= 1.1 =
*   Updated the readme.txt and the plugin name

= 1.0 =
*   Initial release