WHMCS security
WHMCS Security Audit and Hack Recovery
I audit WHMCS installations for the weaknesses attackers actually use, such as exposed admin areas, missing two-factor, loose file permissions, leaked backups, outdated releases and over-powered API credentials. You get a ranked written report with fixes, and I can apply them. If you were hacked, I handle containment and recovery.
By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated
What does a WHMCS security audit check?
It checks every place where WHMCS lets someone in, leaks data or runs code, from the admin folder to the PHP settings. This is the checklist I work through on each installation.
| Area | What I check |
|---|---|
| Admin folder | Whether the admin path is limited to known IP addresses at the web server. Renaming it with $customadminpath helps against bots but is obscurity, not protection. |
| Staff and two-factor | Two-factor on every staff account, shared logins, accounts of people who left, and who holds the full administrator role. I read the admin log for odd logins. |
| configuration.php | Read-only permissions, no copies such as configuration.php.bak, and the $cc_encryption_hash backed up somewhere other than next to the database dump. |
| Writable folders | Whether attachments, downloads, templates_c and the crons folder sit outside the public web root, with their paths set in configuration.php. |
| PHP hardening | disable_functions for shell-execution functions, open_basedir, display_errors off, and a supported PHP version. I test installed modules before and after, since some need functions you might block. |
| Release level | Whether WHMCS security releases have been applied promptly, whether the install folder was removed, and whether third-party addons are current. |
| Exposed files | Backups (.sql, .zip, .tar.gz), .git folders, .env files, phpinfo pages and error logs that a browser can fetch. |
| API credentials | Every credential, its role, its IP restriction, and whether any integration still uses an admin login. Unused credentials are listed for deletion. |
| Fraud and abuse | Fraud screening, CAPTCHA on login, registration, ticket and domain-checker forms, and login ban settings against password guessing and fake signups. |
| Database | A dedicated database user limited to one database, no MySQL port open to the internet, and backups stored off the server. |
| SSL and headers | HTTPS on the system URL with a redirect, HSTS, X-Content-Type-Options, a referrer policy and clickjacking protection, then a test of checkout and the gateway pages. |
| Server underneath | SSH access, firewall, patching, and other sites sharing the account. This overlaps with server security hardening. |
What is in the audit report?
The report is a written document that ranks each finding as critical, high, medium or low and tells you what to do about it. Every finding carries the same four parts.
- The evidence, such as the file path, setting value or URL I found.
- The realistic risk in plain language, not a generic score.
- The exact fix, including the order to apply it in and what to test afterwards.
- Whether I can apply it, and a rough effort estimate.
The report also lists what was out of scope and what I could not verify. It is a snapshot of the day I looked, and it is not a certificate.
How do attackers usually get into a WHMCS install?
Usually through something that was left open, not through a clever new exploit. These are the routes that come up most often.
- A WHMCS release with a published security fix that was never applied.
- A staff password that was weak, reused or phished, on an account without two-factor.
- A forgotten database dump,
.gitfolder orconfiguration.phpcopy that anyone could download. - A third-party addon, theme or hook with a vulnerability that nobody updates.
- Another site on the same hosting account that was compromised first, with the attacker then reading the WHMCS files.
- An API secret pasted into a script, a chat or a repository.
Each of these has a matching row in the checklist, which is why the audit looks at habits and history as well as settings.
My WHMCS was hacked. What do I do first?
Contain it, copy everything before you clean anything, and only then start removing and replacing. The order matters. I follow it on every recovery.
- Contain. Restrict public access to the site or put it behind an IP allow-list, and block the admin area. If you suspect payment abuse, revoke gateway and API keys at once. Do not wipe the server.
- Snapshot. Copy the full file tree with timestamps, take a database dump, and save the web server and PHP logs before rotation removes them. This is your evidence and your fallback.
- Look for rogue access. Check staff accounts, roles, API credentials, gateway settings, server module credentials and email templates for changes you did not make.
- Find modified code. Compare core files against a clean download of the same version, then read
includes/hooks,modulesandtemplatesby hand. Searchattachments,downloadsandtemplates_cfor PHP files that should not exist. - Restore known-good files. Put back clean core files and only the custom code you have reviewed. If you restore a backup, choose one from before the first sign of compromise, and clean the database too.
- Rotate every secret. Do this after the backdoors are gone, or the new passwords leak through the old ones. Cover the database password, all staff passwords, API credentials, gateway and registrar keys, server module logins, SMTP and SSH.
- Find the entry point. Read access logs for requests to unusual PHP files, check the WHMCS version against published security releases, and look at third-party modules and neighboring sites on the same account.
- Harden and tell people. Apply the checklist above. If client data may have been exposed, your legal duties vary by country, so take advice on notifying clients and authorities.
What can a WHMCS audit not do?
An audit cannot make an installation unhackable, and I make no such promise. It does not replace a formal compliance assessment, and I do not issue certificates of any kind. It does not cover the security of your payment gateway, your registrar or other vendors. Because it is a snapshot, a new vulnerability or a new careless setting next month can undo it. I also do not audit unlicensed or nulled WHMCS copies, since the code cannot be trusted. Ongoing upkeep belongs in support and maintenance, and a backup plan that survives an attack is part of server migration and backup.
What does a WHMCS security audit cost?
I quote a fixed price after a free scoping call of about 30 minutes, or work hourly at $55 to $65 per hour. The price depends on how many servers and modules are involved, whether the server and control panel are in scope, and whether you want me to apply the fixes. Recovery work after a hack is scoped the same way, once I have seen the snapshot. The official WHMCS documentation has a further-security-steps guide, and I treat it as the minimum, not the whole job. If something is already broken rather than exposed, start with WHMCS quick fixes.
Who this is for
- WHMCS owners whose installation has never been reviewed by an outside engineer
- Hosting companies that have grown and now hold more client data than when WHMCS was set up
- Owners who inherited WHMCS from a previous admin or freelancer and do not know what was changed
- Anyone who has seen unknown admin users, strange outgoing emails or modified files
What is included
- Review of admin access: folder protection, staff accounts, roles and two-factor
- Check of configuration.php, file ownership, permissions and writable folders
- Check of where attachments, downloads, templates_c and the crons folder are stored
- PHP and web server settings review, including disable_functions and open_basedir
- Search for exposed backups, .git folders and stray files reachable by URL
- Review of every API credential, its role and its IP restriction
- Ranked written report, fixes applied by me when you approve, and a re-check afterwards
How the work runs
-
1
Scope and access
We agree what is in scope: WHMCS only, or the server and panel beneath it too. I ask for read-only access wherever possible.
-
2
Review
I go through the checklist below by hand and with command-line checks, comparing your files against a clean copy of the same WHMCS version.
-
3
Report
You receive findings ranked by severity, each with the evidence, the risk and the exact fix, so your own admin can act on it if you prefer.
-
4
Fix
After you approve the list, I apply the changes in a staging copy, test checkout, cron and email, then repeat them on production.
-
5
Re-check
I verify every fix and note anything left open, so the report ends with a true picture and not a hopeful one.
Frequently asked questions
How long does a WHMCS security audit take?
A single WHMCS installation typically takes two to four working days from access to written report. Adding the web server, the control panel and other sites on the same account lengthens that. The exact date depends on how many modules, servers and integrations are in play, which I learn on the scoping call.
Will the audit change anything on my live server?
No. The review is read-only: I read configuration, list files and check settings. I change nothing until you have read the report and approved specific fixes. Those fixes go through a staging copy first when they could affect checkout, the cron or emails.
Can you make my WHMCS unhackable?
No. No system is unhackable, and I will not promise otherwise. An audit closes the common routes, limits the damage if one is used, and makes an intrusion easier to spot. The remaining risk comes from things like stolen staff passwords and unpatched third-party modules, which need ongoing attention.
My WHMCS was hacked. Can you help right now?
Yes. Tell me it is urgent when you write. I start with containment and a full snapshot so evidence is kept, then remove the compromise, restore clean files, rotate secrets and find the way in. The recovery steps are set out on this page so you can see the order I work in.
Is this a penetration test?
No. I do not run exploits or load tests against your production system. I review configuration and files from the inside and check what is reachable from outside. If a payment provider or regulator requires a formal penetration test, you need a dedicated testing firm, and I can help prepare for it.
Should I change the encryption hash after a breach?
Not blindly. The $cc_encryption_hash in configuration.php decrypts stored encrypted values, so replacing it without re-encrypting them makes that data unreadable. I first work out what the attacker could read, then decide whether a planned re-encryption is worth it.
Related services
-
Server Hardening Service for Linux and cPanel Servers
I harden Linux and cPanel servers with SSH keys, firewall review, patching, PHP isolation and protected backup...
-
WHMCS Support and Maintenance
Ongoing WHMCS care, hourly or monthly: staged upgrades, PHP changes, cron and backup checks, module updates an...
-
cPanel Server Migration and Backup Setup
I move cPanel accounts, mail and DNS to a new server with a tested cutover, then set up local and off-site bac...
-
WHMCS Blank Page, Cron, Email and Login Fixes
Fix common WHMCS problems: blank page or error 500, cron not running, failed gateway callbacks, invalid licens...
Ready to talk about your project?
Send the details and I reply within one business day with questions, an estimate and a plan.