Support Pin Profor WHMCS · Documentation
v2.0.0

Security & Support

How the module protects your clients — and where to get help.


Security model

  • CSRF protection — every state-changing request (generate, extend, terminate, delete, mark used, revoke) validates the WHMCS CSRF token via check_token().
  • SQL-injection safe — all queries use parameter binding through the Illuminate query builder; no raw concatenated SQL.
  • XSS-safe templates — all user and database values are escaped inside the Smarty templates; dynamic HTML built in PHP uses htmlspecialchars().
  • Transaction-safe state changes — every multi-step mutation runs inside Capsule::transaction(), so a failure never leaves a half-updated PIN.
  • Replay protection — a used or expired PIN can never be verified again; failed attempts are recorded for review.
  • Hide PIN mode — the client area can mask the PIN to its last two digits; admins always see the full code for verification.
  • Full accountability — every action (including automated cron actions and failed verifications) is written to the audit trail with client, user, action and detail.

Hardening recommendations

  • Keep Enable PIN Expiry ON with a short expiry window (default 12 hours) — a PIN that dies quickly is a PIN that cannot be reused.
  • Keep Remove Expired PINs ON so old codes disappear from the database automatically.
  • Enable Mark PIN as Used and train agents to confirm it after every verification.
  • Use Hide PIN if clients share screens or work in public spaces.
  • Leave Allow PIN Generation ON only when you want fully self-service verification; turn it OFF to issue PINs staff-side only.
  • Keep Owner Notification ON when sub-users are allowed, so the primary account holder always knows when a PIN was generated.

Support

For bug reports, feature requests or assistance, please contact HardSoftCode through the official website.