Jump to content

WHMCS.Community

  1. WHMCS Beta Program

    1. WHMCS 9.1 Beta Discussion

      We're excited to announce the beta release of WHMCS 9.1. Be among the first to try out the new features and functionality by getting involved in the release candidate today.

      The purpose of this board is to ask any questions, raise issues or provide feedback on the WHMCS V9.1 Beta. This board will remain open until we reach release day, at which point they be archived. WHMCS V9.1 includes Invoice Immutability Control, Unattended Automatic Updates, New Admin Theme "Iris", New Password Strength & Reuse Controls, PHP 8.4 Support and much more!

      Check out the release highlights for an overview and the release notes for full details.

      As always, RC releases are intended for testing only and are not recommended for production use

      6
      posts
  2. WHMCS.Community

    1. Community Announcements

      Our WHMCS Community Announcements with everything from our community rules to updates on making our community more awesome

      160
      posts
    2. Introduce Yourself

      Introduce yourself here and be sure to come back to welcome others.

      1.3k
      posts
    3. MarketConnect Partner Product Status Updates

      This board is used to communicate any planned or unplanned MarketConnect partner product status updates, this board is read-only and will be updated via the MarketConnect Team when issues arise.  If you are experiencing an issue that is not reported in this board please review the MarketConnect Help Centre or Open a Ticket with our team

      37
      posts
  3. Using WHMCS

    1. Pre-Sales Questions

      Considering purchasing WHMCS but have some questions? Ask them here.

      13.1k
      posts
    2. Admin & Configuration Questions

      This is your space for any questions about WHMCS configuration settings.
       

      6.5k
      posts
    3. Installation, Upgrade, and Import Support

      Get help from the community with installing, upgrading and migrating to WHMCS here

      6.1k
      posts
    4. Using WHMCS

      Have a question about how something works or need help configuring and using WHMCS? Here's the place to do it.

      96.4k
      posts
    5. Troubleshooting Issues

      Use this board to discuss any issues or problems you are encountering. If you think you've found a bug, please report it here

      28.6k
      posts
    6. Vendor Discussions

      Discuss Control panels, payment gateways and domain registrars here

      854
      posts
  4. WHMCS Showcase

    1. Showcase Your Site

      Customized and integrated WHMCS in some way? Show the WHMCS Community here!
       

      8.1k
      posts
    2. Share Your Best Practices & Tips

      Share your tips and advice to the rest of the WHMCS community.
       

      363
      posts
  5. Developing & Extending WHMCS

    1. Third Party Add-ons

      A place to discuss third party modules, add-ons and extensions for the WHMCS platform.

      marketplace_inverse_728x90.png&key=ebc9c3244aa6bb0297564b81d8e33ae4d631eaca838fc05b66038be9162910c7&resource=1

      18.7k
      posts
    2. Service Offers & Requests

      A place to post offers & requests for services related to WHMCS. Rules apply.

      22.9k
      posts
    3. Developer Corner

      Integration, customization and module development, if you have questions, ask them here.

      59.1k
      posts
    4. Building Modules

      Need help while building an extension? Ask your questions here.

      636
      posts
    5. Share Ideas for WHMCS Modules

      Looking for an extension that doesn't exist? Share your ideas and vote on others.

      183
      posts
  6. Community Competitions

    1. News, Announcements & Blogs from WHMCS

      The latest WHMCS News, Announcements & Blog Posts from WHMCS are shared here

      621
      posts
    2. Competitions

      From time to time we run community competitions this is the place you'll find them

      • No posts here yet
  7. General Discussions

    1. General Discussion

      Board for general conversation, share interests, discuss industry related news, etc...

      40.1k
      posts
  8. General Feedback & Assistance

    1. Feedback

      WHMCS Community Feedback helps us to continue improving WHMCS software.

      8.7k
      posts
    2. WHMCS.Community Tips & Tricks

      This board provides an overview of some features and functionality that WHMCS.Community provides.  We add new content from time to time.

      6
      posts
  9. Club Forums

      • No posts here yet
    1. Katamaze Free Scripts

      Perfect your WHMCS with free action hooks, reports and modules. Follow us on Github for more contents.

      51
      posts
    2. Katamaze Module Support

      This board acts as a place where you can get support by us (no guarantee) or by fellow users using your same module.

      149
      posts
    3. 17
      posts
    4. 523
      posts
    5. 494
      posts
    6. 108
      posts
    7. RactStudio Club Topics

      RactStudio is a software development company that offers a range of WHMCS and WordPress products and services that are designed to enhance the functionality and user experience of these platforms. With a focus on quality, affordability, and customer support, RactStudio is the perfect partner for any web hosting company, blogger, and other online businesses who want to take their online presence to the next level.

      • No posts here yet
    8. 69
      posts
    9. 90
      posts
    10. 6
      posts
    11. 7
      posts
    12. 5
      posts
      • No posts here yet
    13. 29
      posts
      • No posts here yet
    14. 30
      posts
    15. 298
      posts
    16. 20
      posts
    17. 22
      posts
  • Popular Contributors

  • Our picks

  • Topics

  • Posts

    • LEGEND, thank you so much Rob
    • Hey Steve, I just built this on my own WHMCS and it works well. It's a custom client area page that shows the domain status, DNS records and full WHOIS, all inside your theme's header, footer and menu. WHOIS goes through WHMCS's own DomainWhois API, so it uses the same lookup servers your domain checker already uses. DNS uses PHP's dns_get_record(). You need two files. 1. dnscheck.php in your WHMCS root folder: <?php use WHMCS\ClientArea; define('CLIENTAREA', true); require __DIR__ . '/init.php'; $ca = new ClientArea(); $ca->setPageTitle('WHOIS & DNS Lookup'); $ca->addToBreadCrumb('index.php', Lang::trans('globalsystemname')); $ca->addToBreadCrumb('dnscheck.php', 'WHOIS & DNS Lookup'); $ca->initPage(); $domain = strtolower(trim($_POST['domain'] ?? '')); $records = []; $whois = ''; $status = ''; $error = ''; if ($domain !== '') { if (!filter_var($domain, FILTER_VALIDATE_DOMAIN, FILTER_FLAG_HOSTNAME) || strpos($domain, '.') === false) { $error = 'Please enter a valid domain name.'; } else { $result = localAPI('DomainWhois', ['domain' => $domain]); if (($result['result'] ?? '') === 'success') { $status = $result['status']; $whois = html_entity_decode(strip_tags(urldecode($result['whois'] ?? '')), ENT_QUOTES); } $records = @dns_get_record($domain, DNS_A | DNS_AAAA | DNS_CNAME | DNS_MX | DNS_NS | DNS_TXT) ?: []; } } $ca->assign('domain', $domain); $ca->assign('records', $records); $ca->assign('whois', $whois); $ca->assign('status', $status); $ca->assign('error', $error); $ca->setTemplate('dnscheck'); $ca->output();   2. dnscheck.tpl in your active theme folder (templates/yourtheme/): <form method="post" action="dnscheck.php"> <div class="input-group mb-3"> <input type="text" name="domain" class="form-control" value="{$domain|escape}" placeholder="example.com"> <button class="btn btn-primary" type="submit">Look Up</button> </div> </form> {if $error}<div class="alert alert-warning">{$error}</div>{/if} {if $status} <p><strong>Status:</strong> {if $status == 'available'}Available to register{else}Registered{/if}</p> {/if} {if $records} <h4>DNS Records</h4> <table class="table table-striped"> <tr><th>Type</th><th>Host</th><th>Value</th><th>TTL</th></tr> {foreach $records as $r} <tr> <td>{$r.type}</td> <td>{$r.host|escape}</td> <td>{if $r.ip}{$r.ip}{elseif $r.ipv6}{$r.ipv6}{elseif $r.target}{if $r.pri}{$r.pri} {/if}{$r.target|escape}{elseif $r.txt}{$r.txt|escape}{/if}</td> <td>{$r.ttl}</td> </tr> {/foreach} </table> {/if} {if $whois} <h4>WHOIS</h4> <pre style="white-space:pre-wrap;color:inherit;background:rgba(255,255,255,.05);padding:15px;border-radius:4px;">{$whois|escape}</pre> {/if}   Then go to yourwhmcs.com/dnscheck.php and you're set. You can add it to your menu with a navbar hook, or just link to it from your site. A couple of notes: - The color:inherit on the WHOIS box makes it readable on both dark and light themes. - Since it's a public page, I'd add a captcha or rate limit so bots don't hammer it. - A lot of WHOIS records hide owner details now because of privacy rules, so you'll mostly see the registrar, dates and nameservers. Hope that helps! Rob K & K Web Services
    • Hey, I've done this on my own WHMCS. All of that comes from homepage.tpl in your theme. On Twenty-One it's /templates/twenty-one/homepage.tpl. The domain search and the "Browse our Products/Services" boxes are both in that file. I'd make a child theme instead of editing Twenty-One directly, though. Otherwise the next WHMCS update will overwrite your changes. Here's how I do it: 1. Make a new folder, like /templates/mytheme/ 2. Inside it, make a file called theme.yaml with this in it: name: "My Theme" parent: twenty-one 3. Copy homepage.tpl from twenty-one into your new folder 4. Edit your copy: take out the domain search and product sections, and put in your own HTML 5. Go to System Settings > General Settings > General, change Template to "My Theme" and save Only the files you copy into your folder get overridden, and everything else still loads from Twenty-One, so updates won't break anything. That captcha under the search box is set in System Settings > General Settings > Security. Once the domain search is gone from the homepage, it won't show there anyway. Hope that helps!  
    • Version: 2.0.1 Released (10/09/2026) Added: separate PIN and Email subtabs and tables to User Logs and Admin Logs. Added: optional legacy migration, table preservation, and a separate migration verification page. Updated: Removed the User column and added Main Account/Sub Account labels. Updated: Widget totals to include main users and subusers, removed the cache delay, and corrected PIN/Email links. Updated: Retained the original pin and email provider names. Updated: Corrected admin provider checks to use authmodule. Updated: Support WHMCS 8.13.x, 9.0.9 & 9.1 Updated: Support ionCube Loader v15 Improved: Subuser logging and prevented duplicate active entries. Version: 2.0.0 Released (10/05/2026) Added: WHMCS dashboard widget showing clients with 2FA, clients without 2FA, clients using Email 2FA, and clients using Pin 2FA. Added: User Logs and Admin Logs for 2FA security: Email 2FA and PIN 2FA records. Added: Delete Logs action for removing old log records before a selected date. Added: Bypass Clients management. Added: User Logs now show the actual client user as well as the linked client account, including Pin records stored with either user or client type. Added: Change logging when users disable or re-enable Email 2FA or Pin 2FA. Added: WHMCS CSRF tokens to Email 2FA and Pin 2FA login challenge forms. Updated: addon and security module versions to 2.0.0. Updated: Prevents login errors if the IP-trust table was removed by recreating ws_iptrust2fa_ip before updating or reading last-login data. Updated: Email 2FA now recreates the required WHMCS two-factor email templates before sending a code if they are missing. Updated: The About page styling to match the Brevo Integration layout. Fixed: User/Admin Logs now only show the currently active 2FA method and clear the other method when switching between Email 2FA and Pin 2FA. Fixed: Provides fresh Email 2FA and Pin 2FA security providers under security/email2fa and security/pin2fa. Fixed: The About page module version card now shows the local 2.0.0 version and aligns its button with the other cards.
    • Can't say I agree there. This will likely bite you at some point, badly. 
    • Hi, How do we create a page to display WHOIS information for the websiite visitor to use? Thank you, steve
    • Yeah or just develop your own solution, like we did. 🙂 Not only cheaper (in the end), but also faster, more control, less bugs and (which is the best part) only include what you really use! We don't use 60% or 70% of WHMCS functions. The majoriity is for us considered as bloatware (no offence meant).  But I fully understand that for the majority WHMCS is a complete solution and they lack the skills to developer their own solution. Then you have to search for alternatives and like SwiftModders stated; there are quite a few alternatives available nowadays (2026). Sidenote; everything owned by WebPros; SolusVM, WHMCS, Plesk, cPanel, etc. etc. etc. all suffer from yearly price increases. It's absurd. Back in the day (7 or 8 years ago) we had over 800 Plesk licenses. But after many years of price increases (7th price increase in a row) we are down to less than 50 Plesk licenses. Our server customers do not want to pay absurd prices (or price increases) for an interface where 80% is never used. For interface panels there is even a wider choice nowadays. And instead of paying over 500 Euro's for a Web Host Edition; we are now paying just a bit more than 1/3 a year. For almost 95% same functions. The difference in the past was Plesk support, but with AI, who needs support anymore. We don't. Our customers don't. Nobody does.  My 2 cents; look around for alternative solutions, dig in and test it. In the end you can save a lot of money!
    • A complete passwordless authentication addon for WHMCS that lets your clients log in to the client area with a single click — no password required. Magic Login Link sends a secure, time-sensitive login link straight to the client's email address; opening it signs the user in through WHMCS' native Single Sign-On engine. The module eliminates login friction while keeping accounts thoroughly protected. Every token is single-use, expires automatically, is bound to the requester's IP address and browser fingerprint, and is protected by a built-in rate limiting engine (per-IP and per-email throttling with a configurable decay window). Clients can request a magic link themselves from the login page, and administrators can generate or send one directly from the Client Summary page or the Client Users table. The addon ships with a full analytics Dashboard (token metrics, login trends, security events and system health), a dedicated Activity Logs screen with a filterable, server-side audit trail of every event, two ready-made email templates (Magic Link Request and Magic Link Security Alert) that install into WHMCS' email template editor with registered merge fields, and a single Configuration page for expiry, throttling, fingerprint binding, security alerts and automatic log pruning — everything governed by modern, secure, CSRF-protected admin screens. Owned License ($40.00) - https://www.hardsoftcode.com/cart/link/magic-login-link-for-whmcs/owned Source Code License ($280.00) - https://www.hardsoftcode.com/cart/link/magic-login-link-for-whmcs/source What's new in v2.5 v2.5 adds full observability and tighter admin control on top of the existing passwordless login engine: Module Activity Logs — a new dedicated audit screen (hsc_magiclink_activity_logs) recording every event with a severity level (success / info / warning / danger), the acting user or admin, IP address and browser/device. Events include token requests, admin sends, every email send (and failure), login successes and failures, IP / browser mismatches, rate-limit hits, manual invalidations and record deletions. Analytics Dashboard — metric cards for token counts by status, successful logins with a month-over-month trend, security events, throttled/blocked attempts, top users by logins, recent activity, and a system health panel. Audit table management — the Dashboard audit table now supports per-row Invalidate and Delete actions (AJAX, no page reload), and the Browser & Device column was removed for a cleaner layout. Email send logging — every dispatched email (client request, admin send and security alerts) is recorded in the Activity Logs as email_sent / email_failed. Automatic pruning — the daily cron job now also prunes old activity log rows (PruneActivityLogsDays), in addition to old tokens (PruneLogsDays). Granular admin configuration — strict IP matching, login limit threshold, security alerts, fallback redirect URL and pruning retention are all configurable from the module's own Configuration page. Features Passwordless login Login page button — a "Magic Login Link" button is injected automatically into the client-area login page (or provide your own custom button HTML). Clicking it opens a modal where the visitor enters their email address. Single-use, expiring tokens — every magic link works exactly once and expires after the configured number of hours (default 24; 0 = never expires). Native SSO sign-in — clicking the link logs the user in through WHMCS' CreateSsoToken API and redirects to a configurable destination (default /clientarea.php). Account-enumeration safe — the request form always shows the same generic success response whether or not the email exists. Security engine Strict IP matching — require the login to come from the same IP address that requested the link. Browser/device fingerprint binding — the requester's User-Agent is stored as a SHA-256 hash and must match at login. Consecutive login limit — cap how many times a single token can be used in sequence; the counter resets when the user logs in with their normal password. Rate limiting & cooldown — per-IP and per-email request throttling with a configurable decay window (enabled/disabled, max requests, decay minutes). Automatic token invalidation — all active tokens are expired when the client or user changes their password. Login security alert email — after every magic-link login the user receives a notification with the account, date & time, IP address and browser/device used (toggleable). Sensitive email suppression — the EmailPreLog hook stops the magic-link email (which contains the login URL) from being stored in WHMCS' email logs. Admin tools Send / generate from the admin area — a "Send Magic Link" action link on the Client Summary page and in the Users & Permissions dropdown of the client users table: send the email instantly. Dashboard analytics — token counts by status, lifetime logins with month-over-month trend, security event counts, throttled attempts, top users, recent activity feed and a system health panel (table presence + pruning retention). Audit table actions — invalidate an active token or permanently delete an audit record straight from the Dashboard, with SweetAlert confirmation and AJAX table reload. Activity Logs screen — server-side DataTable with global search, severity and event-type filters, severity badges, actor labels (User / Admin / System) and a per-row AJAX delete. Email integration Two ready-made email templates created on activation: Magic Link Request and Magic Link Security Alert. Custom merge fields registered in WHMCS' email template editor: {$login_link}, {$login_url}, {$expire_time} (request) and {$login_ip}, {$login_time}, {$user_agent} (security alert). Housekeeping Daily cron pruning — old used/expired/invalidated/failed tokens and old activity log rows are removed automatically after the configured retention days.
    • Absolutely after backlash. Enough so that 8.x remained.  'Recommended' does not mean best suited.  We did the 9 upgrade and it's been an admin nightmare for billing. We disabled it early with the config setting but it's been a mess.    We will be doing full disable once GA. 
    • I get hat, but WHMCS only added that after significant backlash - and all it does is provide previous functionality, and a warning.   Using WHMCS with the invoice immutability option set as recommended makes it impossible to work with.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated