GHAN— by singular Get started

GHAN vs. ironSource installcore and OpenCandy

The previous generation of desktop cross-promotion networks died for three identifiable reasons — installer-time placements, payment on the install event, and partner-supplied creative. GHAN removed all three from the product, which is why its constraints look arbitrary until you know the history.

What actually happened

Between roughly 2010 and 2016, several networks — OpenCandy, ironSource installcore, InstallMonetizer, and others — built a real business letting desktop software monetise its own installer. A person downloading a free utility would see one or more third-party offers during installation, and the utility's developer was paid per accepted offer.

The economics worked. The incentives did not.

Placement inside the installer puts the offer in direct competition with the Next button. Every increment of confusion between "continue installing what I wanted" and "accept this offer" increases revenue. There is no equilibrium where the clearest possible presentation is also the most profitable one.

Payment on the install event means the money is earned the moment the software lands, regardless of whether the person ever opens it. Retention is somebody else's problem, and a bad install pays the same as a good one.

Partner-supplied creative means the network transmits whatever the advertiser sends. That is how offers became indistinguishable from system dialogs, and eventually how actual unwanted software travelled.

By 2015 the SDKs were being detected by antivirus engines worldwide. The detections attached to the SDK rather than to individual offers, which meant honest integrators were flagged alongside everyone else. AdDuplex, which tried a cleaner version for Microsoft Store apps, shut down quietly in 2023.

The category was not disrupted. It was abandoned.

The three responses, one per failure

Their mechanismTheir outcomeGHAN's decision
Offer inside the installerCompetes with the Next button; accidental acceptance is most profitableNo installer-time slot exists. All five slots are inside the running application, after install
Paid on the install eventManufacturing installs is the cheapest way to earnNothing clears on the event. 48-hour retention, or day-7 engagement above EUR 500/day per pair
Partner-supplied creativeOffers imitated system dialogs; payloads travelledTemplated only. Icon, name, one line, rendered by GHAN's SDK from a payload with no markup field

The test to apply to any network, including this one

  1. Does it place anything inside an installer? GHAN: no.
  2. Does it pay on the install event or on behaviour afterwards? GHAN: 48-hour retention.
  3. Can a partner supply content that renders inside another app? GHAN: no.
  4. Is anything pre-selected on the person's behalf? GHAN: there is no checkbox.
  5. Are advertisers vetted for malware and code signing before they can appear? GHAN: gate re-run weekly.
  6. Can you verify the network's own numbers without its cooperation? GHAN: two signatures per line, append-only ledger, public read tools.

Question six is the one the old networks could not have answered at all, and it is the reason GHAN exists as a referee rather than as a marketplace.

Why this page exists

An honest comparison page for this category has to start with the graveyard, because every developer who has been shipping desktop software for more than five years will think of OpenCandy within ten seconds of hearing the pitch. Pretending the history is not there would be the first sign that GHAN had not learned from it.

Questions people ask about this

What was OpenCandy?

OpenCandy was a desktop software monetisation platform that let installers show third-party offers during installation, paying the host application per accepted offer. It was widely integrated in the early 2010s, increasingly detected as a potentially unwanted program by antivirus vendors, and shut down in 2016. Its mechanism - an offer inside an installer, accepted by the same click flow as the installation itself - is the pattern the whole category is now judged by.

Why did ironSource installcore get flagged as malware?

Because the combination of installer-time placement and payment on the install event makes accidental acceptance the most profitable outcome. Once that is true, the pressure is always toward pre-checked boxes, confusing button labels and silent installs, and the endpoint is a bundle that installs software the person did not choose. Antivirus vendors classify that behaviour correctly, and the classification attaches to the SDK, which means every honest integrator gets flagged too.

Is GHAN the same thing with better marketing?

No, and the difference is testable rather than rhetorical. Ask three questions of any network. Does it place anything inside an installer? Does it pay on the install event or on behaviour after it? Can a partner supply creative content that renders in another app? GHAN answers no, behaviour, and no. A network that answers yes, event, yes is the old model regardless of what it calls itself.

Could GHAN end up the same way?

The failure mode is drift - adding an installer-time slot for a large partner, relaxing the clearing rule to improve reported conversion, allowing a custom creative for a brand that insists. GHAN's protection against that is having written the constraints down as non-negotiable principles with a rule that a conflicting feature stops work rather than getting coded around, and publishing them here where a partner can hold the network to them.

Machine-readable versions of this page: markdown · llms.txt · llms-full.txt · OpenAPI · AI catalog