Security & Support
How the module protects your admin area — and where to get help.
Security model
- CSRF protection — every state change (create, edit, delete, enable/disable, save settings, generate sitemap, write robots.txt, reset hits, clear GA cache) validates the WHMCS session token.
- Native access control — the module uses WHMCS’ native addon role-group permissions; only granted admin groups can open it.
- Escaped output — all user and database values are escaped in the Smarty templates and in generated markup.
- Validated redirects — the redirect manager rejects self-loops, duplicate sources and missing targets before anything is saved.
- Service-account isolation — the Google Analytics connection authenticates server-to-server with a dedicated read-only (Viewer) service account; no OAuth consent screen and no third-party analytics code on your pages.
- Data-preserving deactivation — deactivating keeps all records unless Delete Module Database was explicitly ticked.
Hardening recommendations
- Grant module access only to admin groups that genuinely need SEO tooling.
- Keep Track Redirect Hits on — unexpected hit spikes can reveal broken links or abuse.
- Use a dedicated Google Cloud project and a read-only service account for the GA4 connection, and rotate keys periodically.
- Review the SEO Health Check warnings regularly — stale meta records pointing at deleted items are cleaned up only when you fix them.
- Keep the WHMCS cron configured if you rely on daily sitemap regeneration.
Support
- Vendor: HardSoftCode — hardsoftcode.com
- License: hardsoftcode.com/license-agreement