paypal now requires that all certs used be 2048 sha-2 you should check your OS and sever , see that it is SHA-2 compliant.
check your SSL cert to be sure it is 2048
your cert should say this in SSL/TLS management
Description
2,048 bits, created 12/24/14 9:09 AM UTC
ID ( I have altered mine here )
b2fb2_fb299_3a788a9dab6a6db9868351b4b
Size
2048
also if your cpanel allows for creation of smaller size than 2048 bits , I forget what that was now, but that will mean you need to upgrade cpanel and or your OS.
the best way to set up whmcs is on multiple servers clustered in a master / slave config.
where whmcs is housed in its own server and makes accounts on a slave IE: no hosting accounts on master just whmcs with Data base any hosting accounts are on slave , so master talks to slave but slave cannot talk to master.
further if you are experiencing lots of Bruteforce attacks I have IP list for all recently know bad IPs after implementation
we have had NO entrys in master and only 2 or 5 a month on slave. you may contact me here for list to add in blacklist.
servers@nrwebus.com