All Activity
- Yesterday
-
landonblake joined the community
-
glycomodebenefits joined the community
-
send21 joined the community
-
horsevitalsite joined the community
-
ittriplegreenfarmsbenefits joined the community
-
A complete passwordless authentication addon for WHMCS that lets your clients log in to the client area with a single click — no password required. Magic Login Link sends a secure, time-sensitive login link straight to the client's email address; opening it signs the user in through WHMCS' native Single Sign-On engine. The module eliminates login friction while keeping accounts thoroughly protected. Every token is single-use, expires automatically, is bound to the requester's IP address and browser fingerprint, and is protected by a built-in rate limiting engine (per-IP and per-email throttling with a configurable decay window). Clients can request a magic link themselves from the login page, and administrators can generate or send one directly from the Client Summary page or the Client Users table. The addon ships with a full analytics Dashboard (token metrics, login trends, security events and system health), a dedicated Activity Logs screen with a filterable, server-side audit trail of every event, two ready-made email templates (Magic Link Request and Magic Link Security Alert) that install into WHMCS' email template editor with registered merge fields, and a single Configuration page for expiry, throttling, fingerprint binding, security alerts and automatic log pruning — everything governed by modern, secure, CSRF-protected admin screens. Owned License ($40.00) - https://www.hardsoftcode.com/cart/link/magic-login-link-for-whmcs/owned Source Code License ($280.00) - https://www.hardsoftcode.com/cart/link/magic-login-link-for-whmcs/source What's new in v2.5 v2.5 adds full observability and tighter admin control on top of the existing passwordless login engine: Module Activity Logs — a new dedicated audit screen (hsc_magiclink_activity_logs) recording every event with a severity level (success / info / warning / danger), the acting user or admin, IP address and browser/device. Events include token requests, admin sends, every email send (and failure), login successes and failures, IP / browser mismatches, rate-limit hits, manual invalidations and record deletions. Analytics Dashboard — metric cards for token counts by status, successful logins with a month-over-month trend, security events, throttled/blocked attempts, top users by logins, recent activity, and a system health panel. Audit table management — the Dashboard audit table now supports per-row Invalidate and Delete actions (AJAX, no page reload), and the Browser & Device column was removed for a cleaner layout. Email send logging — every dispatched email (client request, admin send and security alerts) is recorded in the Activity Logs as email_sent / email_failed. Automatic pruning — the daily cron job now also prunes old activity log rows (PruneActivityLogsDays), in addition to old tokens (PruneLogsDays). Granular admin configuration — strict IP matching, login limit threshold, security alerts, fallback redirect URL and pruning retention are all configurable from the module's own Configuration page. Features Passwordless login Login page button — a "Magic Login Link" button is injected automatically into the client-area login page (or provide your own custom button HTML). Clicking it opens a modal where the visitor enters their email address. Single-use, expiring tokens — every magic link works exactly once and expires after the configured number of hours (default 24; 0 = never expires). Native SSO sign-in — clicking the link logs the user in through WHMCS' CreateSsoToken API and redirects to a configurable destination (default /clientarea.php). Account-enumeration safe — the request form always shows the same generic success response whether or not the email exists. Security engine Strict IP matching — require the login to come from the same IP address that requested the link. Browser/device fingerprint binding — the requester's User-Agent is stored as a SHA-256 hash and must match at login. Consecutive login limit — cap how many times a single token can be used in sequence; the counter resets when the user logs in with their normal password. Rate limiting & cooldown — per-IP and per-email request throttling with a configurable decay window (enabled/disabled, max requests, decay minutes). Automatic token invalidation — all active tokens are expired when the client or user changes their password. Login security alert email — after every magic-link login the user receives a notification with the account, date & time, IP address and browser/device used (toggleable). Sensitive email suppression — the EmailPreLog hook stops the magic-link email (which contains the login URL) from being stored in WHMCS' email logs. Admin tools Send / generate from the admin area — a "Send Magic Link" action link on the Client Summary page and in the Users & Permissions dropdown of the client users table: send the email instantly. Dashboard analytics — token counts by status, lifetime logins with month-over-month trend, security event counts, throttled attempts, top users, recent activity feed and a system health panel (table presence + pruning retention). Audit table actions — invalidate an active token or permanently delete an audit record straight from the Dashboard, with SweetAlert confirmation and AJAX table reload. Activity Logs screen — server-side DataTable with global search, severity and event-type filters, severity badges, actor labels (User / Admin / System) and a per-row AJAX delete. Email integration Two ready-made email templates created on activation: Magic Link Request and Magic Link Security Alert. Custom merge fields registered in WHMCS' email template editor: {$login_link}, {$login_url}, {$expire_time} (request) and {$login_ip}, {$login_time}, {$user_agent} (security alert). Housekeeping Daily cron pruning — old used/expired/invalidated/failed tokens and old activity log rows are removed automatically after the configured retention days.
-
- Magic Login Link
- WHMCS Passwordless Login
- (and 7 more)
-
Absolutely after backlash. Enough so that 8.x remained. 'Recommended' does not mean best suited. We did the 9 upgrade and it's been an admin nightmare for billing. We disabled it early with the config setting but it's been a mess. We will be doing full disable once GA.
-
I get hat, but WHMCS only added that after significant backlash - and all it does is provide previous functionality, and a warning. Using WHMCS with the invoice immutability option set as recommended makes it impossible to work with.
-
It should be an admin option based on this https://docs.whmcs.com/releases/9-1/9-1-release-notes/ https://docs.whmcs.com/9-1/system/general-settings/general-settings-invoices/#invoice-immutability
-
Diazepamtabs joined the community
-
AmyHost joined the community
-
The product page is up now, with the setup steps, screenshots, which blocks clients can and cannot clear, and an FAQ: https://redwaterhost.com/whmcs-modules/firewall-unblocker The Marketplace listing linked above is still waiting for approval, so that link won't open until WHMCS publishes it. Until then the module is free from our store: https://my.redwaterhost.com/store/whmcs-modules/firewall-unblocker
-
Nelfundportal joined the community
-
Ok, so today was the first time I tried WHMCS 9.x - I avoided upgrading due to the reported issues. In my dev install of WHMCS 9.1 The first thing I did was try to edit an unpaid invoice - and found there was zero ability to delete a product, change a price - nothing. Unless im missing somthing, its unworkable in the current form without disabling the feature entirely. Providing a disable feature in the admin area and calling it 9.1 isnt going to cut it?
-
AryanKiJawani joined the community
-
We’re building an MCP Server for WHMCS - looking for feedback We’re currently working on an MCP Server that connects WHMCS with MCP-compatible AI tools. The idea is to make it possible to work with things like clients, services, invoices, domains and WHMCS data through an MCP interface. We’re still deciding what should be included in the first release. For those running WHMCS: What would you actually want to be able to do through MCP? Looking for practical use cases and feedback from people who use WHMCS day to day.
-
- whmcs
- whmcsglobalservices.com
-
(and 3 more)
Tagged with:
-
Yes, please open a ticket for Trail Plan here https://members.whmcsglobalservices.com/submitticket.php?step=2&deptid=5
-
Our WhatsApp Notification Module for WHMCS automates customer communication by sending notifications directly to customers’ WhatsApp numbers. It supports invoice reminders, service activation, domain registration and renewal notifications, transfer status updates, support ticket replies, and more. With 70+ predefined message templates, multilingual support, scheduled custom notifications, and two-way messaging, it helps hosting businesses improve customer engagement and reduce manual work. Learn more: https://whmcsglobalservices.com/whatsapp-notification-whmcs-module/ Top 5 reasons to choose the Whatsapp WHMCS module Immediate Communication Enhance Customer Engagement Increase Sales Opportunities Seamless Integration Marketing Enhancement:
-
With WHMCS 9.1 Beta now available, we've officially started preparing our modules for compatibility with the upcoming WHMCS release. And our first compatible module is already here! Introducing Client Notifications For WHMCS 1.0.0 Our latest module brings targeted communication directly into the WHMCS Client Area, helping administrators keep customers informed through alerts, popups, and bell notifications. Key Features: Targeted alerts, popups, and bell notificationsClient and product-based targetingScheduled messages and notificationsNotification statistics and view trackingCentralized notification management Explore Client Notifications: View Module Details WHMCS 9.1 Compatibility Client Notifications is our first module ready for WHMCS 9.1 Beta. More compatibility updates across our existing product portfolio will follow as testing progresses. You can check individual product changelogs for the latest compatibility information.
-
thedesertsafariindubai joined the community
- Last week
-
How can i remove all content from client area home page and add my own content. Please help me to solve this issue
-
woo, thank you so much 🙂
-
Firewall Unblocker for WHMCS (free): Let clients clear their own CSF and cPHulk blocks, for their current IP only Hi all, Every cPanel host running CSF or cPHulk gets the "server is down" ticket that is really a client's own IP blocked after too many failed logins. Firewall Unblocker is a free WHMCS addon that lets clients check and clear those blocks themselves from the client area: Only the address they are connecting from. There is no field to type an IP into. Only the servers behind their own active services, where you have enabled it. Only blocks that lfd or cPHulk created. Your own blocks, ranges and "do not delete" entries stay, and the client sees "Support required" instead. Every check and removal is recorded in an audit log. WHMCS 8.13 or 9.0, PHP 8.2 or 8.3, cPanel & WHM, ionCube Loader 13 or newer. IPv4 and IPv6. How it works, with screenshots: https://redwaterhost.com/blog/firewall-unblocker-for-whmcs Documentation: https://docs.redwaterhost.com/firewall-unblocker/ WHMCS Marketplace: https://marketplace.whmcs.com/product/9051-firewall-unblocker-for-whmcs (coming soon I hope) Questions and feedback are welcome here.
-
Of course, it's simply not to use the platform. However, as long as people continue to pay after each price increase, they won't change their practices. Personally, I stopped using WHMCS altogether once they dropped owned licenses. That was the end of the line for me, and the only reason I still give WHMCS any money is that they require an active license to download the latest version of WHMCS. I have many clients using my themes, so I can't simply abandon them because I don't like their business practices. But, hey, screw your community, right? I won't go advertising alternatives, but you don't have to search hard to find them.
-
Well Another year another price increase. we just got this email 17.70% price increase thats 180,48 USD Extra per year. Source: WHMCS Customer Licensing Guide 2027 - WHMCS we only use WHMCS as a client management system we dont do payments via WHMCS. There has to be a cheaper alternative to this?
-
That's great news! It should be optional indeed! Thanks, John! 🙌
-
The invoice immutability change definitely makes simple corrections more complicated. I can understand keeping an audit trail, but having an easy way to issue a corrected invoice without manually rebuilding everything would make the process much smoother.
-
Hey everyone, Very soon we are opening up Beta over at Frabs. If you sell VPS / VM’s then we will save your team hours of investigations and admin tasks to resolve bad customers ruining your IP reputation. Frabs handles all bad outgoing traffic from your network, it can be installed to your hypervisor with a single command and fully integrate to WHMCS and other apps to open tickets on attack, suspend customer, rate limit ports and much more. We are releasing some screenshots attached which is the first look at our new platform.
-
I built a free addon called Examen because I couldn't find anything that answers "which of my modules will break on WHMCS 9?". It reads every module, hook and template file in your install and reports: PHP 8.x removals and deprecations (removed functions, ${var} interpolation, dynamic properties…), with file and line legacy WHMCS database helpers (select_query, full_query) and mysql_* Smarty tags WHMCS 9 / Smarty 4 no longer supports ({php}, {include_php}, {fetch}, $smarty.template_object, SmartyBC calls) ionCube / SourceGuardian / Zend Guard files it can't inspect, so you know which vendor to chase a per-module verdict (Ready / Needs review / Blocked / Encoded) and a 0–100 readiness score a short security pass: default admin folder, configuration.php permissions, attachments/templates_c inside the web root, leftover install/, admins without 2FA, API credentials with no IP allowlist, error display left on It never executes the code it scans, makes no outbound connections, and never reads your database credentials. MIT licensed, 140+ unit tests on PHP 8.1–8.4. I don't run a hosting company, so I have no production WHMCS to prove it against. If you're on 8.13 or 9.0 and willing to install it on a staging copy and send me the JSON export (or just a screenshot of the summary), I'll fix whatever it gets wrong and credit you in the changelog — and anyone who reports a real bug gets a free year of our first paid module when it launches. Happy to send the source first if you'd rather read it than run it. Details: https://liquidmonks.com/whmcs-examen — reply here or email info@liquidmonks.com and I'll send the zip with its SHA-256 and a one-page test guide.
-
Thank You!!
-
How can I edit a customer invoice
LittleCreek replied to DeshiNode's topic in Troubleshooting Issues
Thanks so much John. -
Automatic MarketConnect Account Registration
slim replied to zomex's topic in WHMCS 9.1 Beta Discussion
I don’t use market connect either - and have no plan to do so.
