SEO Managerfor WHMCS · Documentation
v1.0.0

Security & Support

How the module protects your admin area — and where to get help.


Security model

  • CSRF protection — every state change (create, edit, delete, enable/disable, save settings, generate sitemap, write robots.txt, reset hits, clear GA cache) validates the WHMCS session token.
  • Native access control — the module uses WHMCS’ native addon role-group permissions; only granted admin groups can open it.
  • Escaped output — all user and database values are escaped in the Smarty templates and in generated markup.
  • Validated redirects — the redirect manager rejects self-loops, duplicate sources and missing targets before anything is saved.
  • Service-account isolation — the Google Analytics connection authenticates server-to-server with a dedicated read-only (Viewer) service account; no OAuth consent screen and no third-party analytics code on your pages.
  • Data-preserving deactivation — deactivating keeps all records unless Delete Module Database was explicitly ticked.

Hardening recommendations

  • Grant module access only to admin groups that genuinely need SEO tooling.
  • Keep Track Redirect Hits on — unexpected hit spikes can reveal broken links or abuse.
  • Use a dedicated Google Cloud project and a read-only service account for the GA4 connection, and rotate keys periodically.
  • Review the SEO Health Check warnings regularly — stale meta records pointing at deleted items are cleaned up only when you fix them.
  • Keep the WHMCS cron configured if you rely on daily sitemap regeneration.

Support