Personally If SpookedOut could *prove* that a hosted version of WHMCS on his servers would be more secure than a version on one of my servers then I would be all up for this.
MACscr, you say that you could hack another account on the server, if SpookedOut would agree to it why doesnt he set up a server exactly how the server would be set up if he was hosting WHMCS on it now and he lets you try. If you are sucessfull then SpookedOut will have to think again on his security.
Jordan, by your defination of a "Joe-Schmoe" that would make Matt a "Joe-Schmoe" yet you are using a program that Matt has developed.
This is only my 2p so take it as you want.
Paul