Magic Login Linkfor WHMCS · Documentation
v2.5.0

Security & Support

How the module protects your clients — and where to get help.


Security model

  • CSRF protection — every admin AJAX action (send, invalidate, delete, save settings) validates the admin session token via check_token().
  • Hashed fingerprints — User-Agent values are stored as SHA-256 hashes, never as readable strings.
  • Random tokens — link keys use random_bytes(32) (256-bit entropy); nothing predictable can be guessed.
  • No link leakage — magic-link emails are excluded from WHMCS’ email logs via the EmailPreLog hook.
  • Enumeration-safe responses — link requests always return an identical generic response, whether or not the email exists.
  • Escaped output — all dynamic values in admin pages and JSON responses are HTML-escaped.
  • Fail-safe hooks — invalidation and alert emails run in try/catch so a failure can never break WHMCS core flows (login, password change, cron).
  • Single-use by default — tokens are consumed on first successful login and never reused; rejection happens before any session is created.

Hardening recommendations

  • Keep Strict IP Matching and Bind User Agent enabled unless your users frequently switch networks or devices.
  • Keep rate limiting enabled; tighten Max Login Requests for high-risk environments.
  • Keep Login Limit Threshold low (the default 5) so a leaked link has minimal usable lifetime.
  • Keep the Login Security Alert email enabled so users can react to unexpected logins.
  • Ensure the WHMCS daily cron is configured so expired tokens and audit rows do not accumulate.

Support