Skip to content
Shahid Malla

WHMCS troubleshooting

WHMCS Blank Page, Cron, Email and Login Fixes

This is a troubleshooting guide for the WHMCS faults I am asked about most, from blank pages and a stopped cron to failed gateway callbacks, license errors, email that will not send, failed upgrades, admin lockouts and broken hooks. Each section lists likely causes, safe checks you can run, and when to call me.

By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated

Is the problem bigger than a quick fix?

Some faults point to a larger job. These pages cover the follow-on work.

Where should I look first when WHMCS misbehaves?

Look at the logs before you change anything, and take a database and file backup first. Three places explain most faults.

  1. The PHP error log, often an error_log file in the WHMCS folder or the Errors page in your panel.
  2. The Activity Log, Module Log, Gateway Log and Email Message Log under Utilities, plus the Automation Status page, which shows when the cron last ran.
  3. The PHP version the website really uses, and whether ionCube Loader is installed for that exact version.

Why is my WHMCS showing a blank page or error 500?

A blank page or error 500 almost always means PHP hit a fatal error that the server hides. Likely causes, in order: an unsupported PHP version, a missing or mismatched ionCube Loader, a missing extension or low memory limit, a faulty custom hook or module, then an unwritable templates_c folder or a full disk.

  1. Read the newest lines of the PHP error log. The file path in the error names the culprit.
  2. Confirm the PHP version in the panel, such as MultiPHP Manager in cPanel, and that the Loader matches it.
  3. Empty the contents of templates_c and check it is writable and the disk is not full.
  4. Move one custom file at a time out of includes/hooks and reload.

Call me when the error points into encoded core files, follows an upgrade, or mentions missing database tables.

Why is the WHMCS cron not running, or invoices not generating?

The cron line is usually missing, uses the wrong PHP binary or runs as the wrong user, often after a server move or PHP change. Missing invoices can also come from the invoice-generation days in Automation Settings.

  1. Open Automation Status and read when the cron last ran.
  2. Check the crontab of the account that owns the files. It should run crons/cron.php every five minutes with the full path to a PHP binary matching your WHMCS version.
  3. Run that command by hand as the same user and read the output. It performs the real tasks, so run it when you are ready for invoices and emails to go out.

Call me when the manual run stops at the same task each time, invoices appear twice, or runs overlap.

Why do payment gateway callbacks fail in WHMCS?

If the gateway shows a charge but the invoice stays unpaid, the callback is not arriving or is rejected. Likely causes: a firewall or security rule blocking the gateway, a redirect (HTTP to HTTPS or www to non-www) that turns the POST into a GET, a changed System URL or expired certificate, a webhook secret mismatch, or a PHP error in the callback file.

  1. Open the gateway's webhook delivery log and note the HTTP status WHMCS returned.
  2. Search the Gateway Log for the transaction ID, and the server access log for the matching POST to modules/gateways/callback/.
  3. Confirm the System URL is the live HTTPS address and the callback path is not redirected.

Call me when the gateway gets a 200 reply but WHMCS shows nothing, or a payment was recorded twice. Bigger gateway work sits under payment gateway integration.

How do I fix an "Invalid License" message in WHMCS?

The license is almost always still registered to an old IP address or domain after a server move or IP change. Less often the server cannot reach the licensing servers, its clock is wrong, or the license has lapsed.

  1. In your WHMCS client account, compare the IP and domain registered to the license with what the site uses now.
  2. If they differ, reissue the license, then reload the admin area so WHMCS checks again.
  3. From the server, test outbound HTTPS and DNS with curl to the WHMCS website, and check the clock with date.
  4. Confirm the license is active and paid.

Call me when the license looks valid but the error stays, or it comes with other faults after a move, which makes it a migration clean-up job.

Why are WHMCS emails not sending or landing in spam?

Unsent email usually means wrong SMTP settings or a blocked port. Spam placement usually means failing SPF, DKIM or DMARC records, or a sending IP with no reverse DNS or a poor reputation. Also check for a disabled email template and for a cron that has stopped.

  1. Check the Email Message Log to see whether WHMCS tried to send, and the Activity Log for SMTP errors.
  2. Use the test button in Mail settings. If port 25 is blocked, try 587 or 465 with authentication.
  3. Send to a Gmail address, choose "Show original" and read the SPF, DKIM and DMARC results.
  4. Look up the sending IP for reverse DNS and blocklist entries.

Call me when DMARC fails on a domain you also use for staff mail, or the sending IP is blocklisted.

What should I do about a failed or half-applied WHMCS upgrade?

Stop, copy the current state, and do not re-run the upgrade blindly. Half-applied upgrades usually come from an unsupported PHP or ionCube version, partly uploaded files, an interrupted database update, or leftovers such as the install folder.

  1. Dump the database and copy the files as they are.
  2. Read the PHP error log for missing-table or missing-column messages.
  3. Compare the version your files report with the Version row in tblconfiguration, using a read-only query.
  4. Read the release notes for follow-up steps, such as removing install and emptying templates_c.

Call me when the database and files disagree on the version. Restoring the pre-upgrade backup onto a staging copy is usually safest. Planned upgrades are part of support and maintenance.

Why can't I log in to the WHMCS admin area?

The usual causes are the wrong URL (the admin folder may be renamed with $customadminpath), a temporary ban after failed attempts, an IP allow-list that excludes you, or a two-factor code failing because the phone clock is off.

  1. Confirm the admin URL with whoever set up the install, or look for $customadminpath in configuration.php.
  2. Wait for the ban to expire, or ask another administrator to remove your IP from the ban list.
  3. Use the forgotten-password link on the admin login page, and check your authenticator device's clock.
  4. Check the disk is not full and the PHP session folder is writable, because a PHP error or full disk after login looks like a lockout.

Call me when none of that applies. I do not publish ways around the login. If you are the only administrator and are locked out, I need proof that you control the license and server first. Unknown admin accounts or changed passwords may mean a breach, which is a job for the security audit.

Why did a hook or module error appear after a WHMCS update?

A custom hook, addon or theme almost always calls something the new WHMCS or PHP version changed or removed. Common culprits: functions removed in PHP 8, such as each() and create_function(), encoded third-party modules with no build for your PHP version, and old template variables.

  1. Read the PHP error log. The stack trace names the file, usually in includes/hooks or modules.
  2. Move that hook file out of the folder, without deleting it, and reload.
  3. For modules, switch on module debug logging, repeat the action and read the Module Log.
  4. Switch the client area to a default theme to rule your custom theme in or out.

Call me when the hook handles money, provisioning or client data, or a vendor has stopped updating its encoded module.

What if the problem is on the WordPress site or the server?

Then it needs a different fix, and those have their own pages. Plugin conflicts, a hacked marketing site or a slow store belong under WordPress services. A full disk, a web server that will not start, firewall rules and control panel faults belong under server setup.

Which shortcuts do I refuse when fixing WHMCS?

I will not bypass authentication, edit WHMCS core files, work on nulled copies or change production without a backup. If a fix seems to need core edits, I use a supported hook or module instead. System requirements for each release are in the WHMCS documentation.

Who this is for

  • WHMCS admins who hit an error and want to know where to look first
  • Owners who inherited an installation and cannot tell a cron fault from a PHP fault
  • Support staff who want a safe checklist before they escalate
  • Anyone whose billing or client logins have stopped and needs them working again

What is included

  • Reading the PHP, activity, module, gateway and email logs to find the real error
  • Checking the PHP version, ionCube Loader, extensions and memory limit against WHMCS requirements
  • Verifying the cron command, PHP binary path, user and folder permissions
  • Testing gateway callbacks, SMTP delivery and SPF, DKIM and DMARC records
  • A backup before any change, with a rollback path if the fix misbehaves
  • A short written note of the cause, the fix and how to avoid a repeat

How the work runs

  1. 1

    Send the symptom

    Tell me what you see, when it started and what changed just before, such as an upgrade, a server move or a new module. Add error text and screenshots.

  2. 2

    I read the logs

    I look at the PHP error log, the WHMCS activity, module and gateway logs, and the web server access log to find the actual error, not the visible symptom.

  3. 3

    Back up and test

    I take a database and file backup. If the fix could affect live billing, I try it on a staging copy first.

  4. 4

    Fix and verify

    I apply the change and confirm with the real thing: a cron run, a test email, a small payment or a login.

  5. 5

    Write it down

    You get a short note with the cause, the fix and any follow-up that would stop it returning.

Frequently asked questions

Why is my WHMCS showing a blank white page?

A blank page means PHP stopped on a fatal error and the server is hiding the message. The error is almost always in the PHP error log. Common causes are an unsupported PHP version, a missing ionCube Loader, a low memory limit, a broken custom hook or an unwritable compiled-templates folder.

How can I tell whether the WHMCS cron is running?

Open the Automation Status page in the admin area and read when the cron last ran and which tasks finished. A last-run time several hours old means the cron has stopped. The crontab line, the PHP binary path or the cron user is usually the cause, especially after a server move.

Is it safe to empty the templates_c folder?

Yes. It holds compiled copies of templates that WHMCS rebuilds on the next request. Delete the files inside it, not the folder itself, and make sure the folder stays writable by the web server user. Emptying it is a standard step after an upgrade or a theme change.

Should I restore a backup as soon as something breaks?

Not as a first move. Copy the current state of the database and files first, then read the logs. Restoring blindly can wipe invoices and payments created since the backup. A restore is the right call when the cause is clear, such as a failed upgrade, and it is best tried on a staging copy.

What do you need to diagnose a WHMCS problem?

The exact error text, the time it began, and anything that changed beforehand. Log excerpts help most. If I need to go further, I ask for an admin login and SSH or panel access. You can revoke that access when we finish.

How quickly can you fix a WHMCS problem?

I typically reply within one business day. A wrong cron path or a license bound to an old IP can often be fixed quickly once I see the logs. A half-applied upgrade or an unexplained hook error takes longer. I will not promise a fix time before I have seen what is actually failing.

Related services

Ready to talk about your project?

Send the details and I reply within one business day with questions, an estimate and a plan.