Jump to content

All Activity

This stream auto-updates

  1. Today
  2. Can't say I agree there. This will likely bite you at some point, badly.
  3. Hi, How do we create a page to display WHOIS information for the websiite visitor to use? Thank you, steve
  4. Yeah or just develop your own solution, like we did. πŸ™‚ Not only cheaper (in the end), but also faster, more control, less bugs and (which is the best part) only include what you really use! We don't use 60% or 70% of WHMCS functions. The majoriity is for us considered as bloatware (no offence meant). But I fully understand that for the majority WHMCS is a complete solution and they lack the skills to developer their own solution. Then you have to search for alternatives and like SwiftModders stated; there are quite a few alternatives available nowadays (2026). Sidenote; everything owned by WebPros; SolusVM, WHMCS, Plesk, cPanel, etc. etc. etc. all suffer from yearly price increases. It's absurd. Back in the day (7 or 8 years ago) we had over 800 Plesk licenses. But after many years of price increases (7th price increase in a row) we are down to less than 50 Plesk licenses. Our server customers do not want to pay absurd prices (or price increases) for an interface where 80% is never used. For interface panels there is even a wider choice nowadays. And instead of paying over 500 Euro's for a Web Host Edition; we are now paying just a bit more than 1/3 a year. For almost 95% same functions. The difference in the past was Plesk support, but with AI, who needs support anymore. We don't. Our customers don't. Nobody does. My 2 cents; look around for alternative solutions, dig in and test it. In the end you can save a lot of money!
  5. Yesterday
  6. A complete passwordless authentication addon for WHMCS that lets your clients log in to the client area with a single click β€” no password required. Magic Login Link sends a secure, time-sensitive login link straight to the client's email address; opening it signs the user in through WHMCS' native Single Sign-On engine. The module eliminates login friction while keeping accounts thoroughly protected. Every token is single-use, expires automatically, is bound to the requester's IP address and browser fingerprint, and is protected by a built-in rate limiting engine (per-IP and per-email throttling with a configurable decay window). Clients can request a magic link themselves from the login page, and administrators can generate or send one directly from the Client Summary page or the Client Users table. The addon ships with a full analytics Dashboard (token metrics, login trends, security events and system health), a dedicated Activity Logs screen with a filterable, server-side audit trail of every event, two ready-made email templates (Magic Link Request and Magic Link Security Alert) that install into WHMCS' email template editor with registered merge fields, and a single Configuration page for expiry, throttling, fingerprint binding, security alerts and automatic log pruning β€” everything governed by modern, secure, CSRF-protected admin screens. Owned License ($40.00) - https://www.hardsoftcode.com/cart/link/magic-login-link-for-whmcs/owned Source Code License ($280.00) - https://www.hardsoftcode.com/cart/link/magic-login-link-for-whmcs/source What's new in v2.5 v2.5 adds full observability and tighter admin control on top of the existing passwordless login engine: Module Activity Logs β€” a new dedicated audit screen (hsc_magiclink_activity_logs) recording every event with a severity level (success / info / warning / danger), the acting user or admin, IP address and browser/device. Events include token requests, admin sends, every email send (and failure), login successes and failures, IP / browser mismatches, rate-limit hits, manual invalidations and record deletions. Analytics Dashboard β€” metric cards for token counts by status, successful logins with a month-over-month trend, security events, throttled/blocked attempts, top users by logins, recent activity, and a system health panel. Audit table management β€” the Dashboard audit table now supports per-row Invalidate and Delete actions (AJAX, no page reload), and the Browser & Device column was removed for a cleaner layout. Email send logging β€” every dispatched email (client request, admin send and security alerts) is recorded in the Activity Logs as email_sent / email_failed. Automatic pruning β€” the daily cron job now also prunes old activity log rows (PruneActivityLogsDays), in addition to old tokens (PruneLogsDays). Granular admin configuration β€” strict IP matching, login limit threshold, security alerts, fallback redirect URL and pruning retention are all configurable from the module's own Configuration page. Features Passwordless login Login page button β€” a "Magic Login Link" button is injected automatically into the client-area login page (or provide your own custom button HTML). Clicking it opens a modal where the visitor enters their email address. Single-use, expiring tokens β€” every magic link works exactly once and expires after the configured number of hours (default 24; 0 = never expires). Native SSO sign-in β€” clicking the link logs the user in through WHMCS' CreateSsoToken API and redirects to a configurable destination (default /clientarea.php). Account-enumeration safe β€” the request form always shows the same generic success response whether or not the email exists. Security engine Strict IP matching β€” require the login to come from the same IP address that requested the link. Browser/device fingerprint binding β€” the requester's User-Agent is stored as a SHA-256 hash and must match at login. Consecutive login limit β€” cap how many times a single token can be used in sequence; the counter resets when the user logs in with their normal password. Rate limiting & cooldown β€” per-IP and per-email request throttling with a configurable decay window (enabled/disabled, max requests, decay minutes). Automatic token invalidation β€” all active tokens are expired when the client or user changes their password. Login security alert email β€” after every magic-link login the user receives a notification with the account, date & time, IP address and browser/device used (toggleable). Sensitive email suppression β€” the EmailPreLog hook stops the magic-link email (which contains the login URL) from being stored in WHMCS' email logs. Admin tools Send / generate from the admin area β€” a "Send Magic Link" action link on the Client Summary page and in the Users & Permissions dropdown of the client users table: send the email instantly. Dashboard analytics β€” token counts by status, lifetime logins with month-over-month trend, security event counts, throttled attempts, top users, recent activity feed and a system health panel (table presence + pruning retention). Audit table actions β€” invalidate an active token or permanently delete an audit record straight from the Dashboard, with SweetAlert confirmation and AJAX table reload. Activity Logs screen β€” server-side DataTable with global search, severity and event-type filters, severity badges, actor labels (User / Admin / System) and a per-row AJAX delete. Email integration Two ready-made email templates created on activation: Magic Link Request and Magic Link Security Alert. Custom merge fields registered in WHMCS' email template editor: {$login_link}, {$login_url}, {$expire_time} (request) and {$login_ip}, {$login_time}, {$user_agent} (security alert). Housekeeping Daily cron pruning β€” old used/expired/invalidated/failed tokens and old activity log rows are removed automatically after the configured retention days.
  7. Absolutely after backlash. Enough so that 8.x remained. 'Recommended' does not mean best suited. We did the 9 upgrade and it's been an admin nightmare for billing. We disabled it early with the config setting but it's been a mess. We will be doing full disable once GA.
  8. I get hat, but WHMCS only added that after significant backlash - and all it does is provide previous functionality, and a warning. Using WHMCS with the invoice immutability option set as recommended makes it impossible to work with.
  9. It should be an admin option based on this https://docs.whmcs.com/releases/9-1/9-1-release-notes/ https://docs.whmcs.com/9-1/system/general-settings/general-settings-invoices/#invoice-immutability
  10. Seems legit? From the site (emphasis mine): If it never reads the DB credentials, how exactly does it access it to store anything in it? Pass.
  11. The product page is up now, with the setup steps, screenshots, which blocks clients can and cannot clear, and an FAQ: https://redwaterhost.com/whmcs-modules/firewall-unblocker The Marketplace listing linked above is still waiting for approval, so that link won't open until WHMCS publishes it. Until then the module is free from our store: https://my.redwaterhost.com/store/whmcs-modules/firewall-unblocker
  12. Ok, so today was the first time I tried WHMCS 9.x - I avoided upgrading due to the reported issues. In my dev install of WHMCS 9.1 The first thing I did was try to edit an unpaid invoice - and found there was zero ability to delete a product, change a price - nothing. Unless im missing somthing, its unworkable in the current form without disabling the feature entirely. Providing a disable feature in the admin area and calling it 9.1 isnt going to cut it?
  13. We’re building an MCP Server for WHMCS - looking for feedback We’re currently working on an MCP Server that connects WHMCS with MCP-compatible AI tools. The idea is to make it possible to work with things like clients, services, invoices, domains and WHMCS data through an MCP interface. We’re still deciding what should be included in the first release. For those running WHMCS: What would you actually want to be able to do through MCP? Looking for practical use cases and feedback from people who use WHMCS day to day.
  14. Yes, please open a ticket for Trail Plan here https://members.whmcsglobalservices.com/submitticket.php?step=2&deptid=5
  15. Our WhatsApp Notification Module for WHMCS automates customer communication by sending notifications directly to customers’ WhatsApp numbers. It supports invoice reminders, service activation, domain registration and renewal notifications, transfer status updates, support ticket replies, and more. With 70+ predefined message templates, multilingual support, scheduled custom notifications, and two-way messaging, it helps hosting businesses improve customer engagement and reduce manual work. Learn more: https://whmcsglobalservices.com/whatsapp-notification-whmcs-module/ Top 5 reasons to choose the Whatsapp WHMCS module Immediate Communication Enhance Customer Engagement Increase Sales Opportunities Seamless Integration Marketing Enhancement:
  16. With WHMCS 9.1 Beta now available, we've officially started preparing our modules for compatibility with the upcoming WHMCS release. And our first compatible module is already here! Introducing Client Notifications For WHMCS 1.0.0 Our latest module brings targeted communication directly into the WHMCS Client Area, helping administrators keep customers informed through alerts, popups, and bell notifications. Key Features: Targeted alerts, popups, and bell notificationsClient and product-based targetingScheduled messages and notificationsNotification statistics and view trackingCentralized notification management Explore Client Notifications: View Module Details WHMCS 9.1 Compatibility Client Notifications is our first module ready for WHMCS 9.1 Beta. More compatibility updates across our existing product portfolio will follow as testing progresses. You can check individual product changelogs for the latest compatibility information.
  17. You dont own a hosting co, dont have a WHMCS install - but wrote an app for it? It would be a fairly brave admin who took code from a one-time poster and ran it on their WHMCS install.
  18. Last week
  19. How can i remove all content from client area home page and add my own content. Please help me to solve this issue
  20. Firewall Unblocker for WHMCS (free): Let clients clear their own CSF and cPHulk blocks, for their current IP only Hi all, Every cPanel host running CSF or cPHulk gets the "server is down" ticket that is really a client's own IP blocked after too many failed logins. Firewall Unblocker is a free WHMCS addon that lets clients check and clear those blocks themselves from the client area: Only the address they are connecting from. There is no field to type an IP into. Only the servers behind their own active services, where you have enabled it. Only blocks that lfd or cPHulk created. Your own blocks, ranges and "do not delete" entries stay, and the client sees "Support required" instead. Every check and removal is recorded in an audit log. WHMCS 8.13 or 9.0, PHP 8.2 or 8.3, cPanel & WHM, ionCube Loader 13 or newer. IPv4 and IPv6. How it works, with screenshots: https://redwaterhost.com/blog/firewall-unblocker-for-whmcs Documentation: https://docs.redwaterhost.com/firewall-unblocker/ WHMCS Marketplace: https://marketplace.whmcs.com/product/9051-firewall-unblocker-for-whmcs (coming soon I hope) Questions and feedback are welcome here.
  21. Of course, it's simply not to use the platform. However, as long as people continue to pay after each price increase, they won't change their practices. Personally, I stopped using WHMCS altogether once they dropped owned licenses. That was the end of the line for me, and the only reason I still give WHMCS any money is that they require an active license to download the latest version of WHMCS. I have many clients using my themes, so I can't simply abandon them because I don't like their business practices. But, hey, screw your community, right? I won't go advertising alternatives, but you don't have to search hard to find them.
  22. Well Another year another price increase. we just got this email 17.70% price increase thats 180,48 USD Extra per year. Source: WHMCS Customer Licensing Guide 2027 - WHMCS we only use WHMCS as a client management system we dont do payments via WHMCS. There has to be a cheaper alternative to this?
  23. That's great news! It should be optional indeed! Thanks, John! πŸ™Œ
  24. The invoice immutability change definitely makes simple corrections more complicated. I can understand keeping an audit trail, but having an easy way to issue a corrected invoice without manually rebuilding everything would make the process much smoother.
  25. Hey everyone, Very soon we are opening up Beta over at Frabs. If you sell VPS / VM’s then we will save your team hours of investigations and admin tasks to resolve bad customers ruining your IP reputation. Frabs handles all bad outgoing traffic from your network, it can be installed to your hypervisor with a single command and fully integrate to WHMCS and other apps to open tickets on attack, suspend customer, rate limit ports and much more. We are releasing some screenshots attached which is the first look at our new platform.
  26. I built a free addon called Examen because I couldn't find anything that answers "which of my modules will break on WHMCS 9?". It reads every module, hook and template file in your install and reports: PHP 8.x removals and deprecations (removed functions, ${var} interpolation, dynamic properties…), with file and line legacy WHMCS database helpers (select_query, full_query) and mysql_* Smarty tags WHMCS 9 / Smarty 4 no longer supports ({php}, {include_php}, {fetch}, $smarty.template_object, SmartyBC calls) ionCube / SourceGuardian / Zend Guard files it can't inspect, so you know which vendor to chase a per-module verdict (Ready / Needs review / Blocked / Encoded) and a 0–100 readiness score a short security pass: default admin folder, configuration.php permissions, attachments/templates_c inside the web root, leftover install/, admins without 2FA, API credentials with no IP allowlist, error display left on It never executes the code it scans, makes no outbound connections, and never reads your database credentials. MIT licensed, 140+ unit tests on PHP 8.1–8.4. I don't run a hosting company, so I have no production WHMCS to prove it against. If you're on 8.13 or 9.0 and willing to install it on a staging copy and send me the JSON export (or just a screenshot of the summary), I'll fix whatever it gets wrong and credit you in the changelog β€” and anyone who reports a real bug gets a free year of our first paid module when it launches. Happy to send the source first if you'd rather read it than run it. Details: https://liquidmonks.com/whmcs-examen β€” reply here or email info@liquidmonks.com and I'll send the zip with its SHA-256 and a one-page test guide.
  1. Load more activity
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated