Security & Support
How the module protects your clients — and where to get help.
Security model
- CSRF protection — every admin AJAX action (send, invalidate, delete, save settings) validates the admin session token via
check_token(). - Hashed fingerprints — User-Agent values are stored as SHA-256 hashes, never as readable strings.
- Random tokens — link keys use
random_bytes(32)(256-bit entropy); nothing predictable can be guessed. - No link leakage — magic-link emails are excluded from WHMCS’ email logs via the
EmailPreLoghook. - Enumeration-safe responses — link requests always return an identical generic response, whether or not the email exists.
- Escaped output — all dynamic values in admin pages and JSON responses are HTML-escaped.
- Fail-safe hooks — invalidation and alert emails run in try/catch so a failure can never break WHMCS core flows (login, password change, cron).
- Single-use by default — tokens are consumed on first successful login and never reused; rejection happens before any session is created.
Hardening recommendations
- Keep Strict IP Matching and Bind User Agent enabled unless your users frequently switch networks or devices.
- Keep rate limiting enabled; tighten Max Login Requests for high-risk environments.
- Keep Login Limit Threshold low (the default
5) so a leaked link has minimal usable lifetime. - Keep the Login Security Alert email enabled so users can react to unexpected logins.
- Ensure the WHMCS daily cron is configured so expired tokens and audit rows do not accumulate.
Support
- Website: hardsoftcode.com
- License: hardsoftcode.com/license-agreement