Security & Support
How the module protects your clients — and where to get help.
Security model
- CSRF protection — every state-changing request (generate, extend, terminate, delete, mark used, revoke) validates the WHMCS CSRF token via
check_token(). - SQL-injection safe — all queries use parameter binding through the Illuminate query builder; no raw concatenated SQL.
- XSS-safe templates — all user and database values are escaped inside the Smarty templates; dynamic HTML built in PHP uses
htmlspecialchars(). - Transaction-safe state changes — every multi-step mutation runs inside
Capsule::transaction(), so a failure never leaves a half-updated PIN. - Replay protection — a used or expired PIN can never be verified again; failed attempts are recorded for review.
- Hide PIN mode — the client area can mask the PIN to its last two digits; admins always see the full code for verification.
- Full accountability — every action (including automated cron actions and failed verifications) is written to the audit trail with client, user, action and detail.
Hardening recommendations
- Keep Enable PIN Expiry ON with a short expiry window (default 12 hours) — a PIN that dies quickly is a PIN that cannot be reused.
- Keep Remove Expired PINs ON so old codes disappear from the database automatically.
- Enable Mark PIN as Used and train agents to confirm it after every verification.
- Use Hide PIN if clients share screens or work in public spaces.
- Leave Allow PIN Generation ON only when you want fully self-service verification; turn it OFF to issue PINs staff-side only.
- Keep Owner Notification ON when sub-users are allowed, so the primary account holder always knows when a PIN was generated.
Support
- Vendor: HardSoftCode
- Website: hardsoftcode.com
- License: hardsoftcode.com/license-agreement
For bug reports, feature requests or assistance, please contact HardSoftCode through the official website.