Skip to content
Shahid Malla

WHMCS care

WHMCS Support and Maintenance

I look after live WHMCS installations for hosting companies and online businesses. That covers staged upgrades, PHP changes, cron and backup monitoring, module and gateway updates, a monthly health review and ad-hoc fixes. You pay by the hour or through a monthly arrangement, and I typically reply within one business day.

By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated

What does WHMCS support and maintenance include?

It covers everything needed to keep an installation that already works running safely, plus fixes when something breaks. The routine work falls into five groups.

  • Upgrades. WHMCS version updates, planned, rehearsed and applied in a quiet window with a rollback path.
  • Platform changes. PHP version moves, ionCube Loader updates and database settings, with an eye on what your hosting provider is retiring.
  • Automation. The cron, the daily run and outgoing email, checked on the agreed schedule so a silent stop is caught early.
  • Safety nets. Backups that are checked, restored on staging and kept off the server.
  • Integrations. License status, addons, payment gateways, registrar modules and the notices their providers publish.

Ad-hoc fixes sit on top of that. If you want to try a fix yourself first, WHMCS quick fixes lists the usual causes and safe checks.

What does a monthly WHMCS health check cover?

A monthly health check is a read-through of the parts of WHMCS that fail quietly, ending in a written summary. These are the checks I run.

CheckWhat I look atWhat I do with it
Cron and automationThe automation status page: last run time, each task finishing, no overlapping runs.Correct the PHP path, user or schedule.
BackupsLatest database and file backups exist, are stored off the server, and the encryption hash is kept safely.Restore one into staging on the schedule we agree and confirm it opens.
Version and securityInstalled release against current releases and security notices.Apply security releases promptly; plan the rest.
PHP and ionCubeThe active PHP version, the Loader build and the provider's retirement dates.Schedule a tested PHP change before support ends.
LicenseStatus, plus the IP and domain it is bound to.Reissue it after any server or IP change.
LogsPHP error log, activity log, module log and gateway log for repeating errors.Fix the source of repeats instead of ignoring them.
EmailFailed sends in the email log, SMTP errors, and the SPF, DKIM and DMARC records.Repair SMTP settings or DNS records.
Gateways and registrarsFailed callbacks, module update notices and API deprecation warnings.Update the module and test with a small live payment.
Data growthDisk space, size of the activity and email logs, and the templates_c folder.Archive or prune only after a fresh backup.
AccessStaff accounts, two-factor status and API credentials.Remove stale accounts and unused credentials.

How do you upgrade WHMCS without breaking anything?

I upgrade on a staging copy first and touch production only after the copy passes a fixed test list. The sequence is the same every time.

  1. Take a fresh database dump and file copy, and confirm both can be restored.
  2. Clone the site to staging with the same PHP version and ionCube Loader as production.
  3. Run the upgrade there, then test checkout, invoice generation, a gateway payment in test mode, a provisioning action, the client area theme, your hooks and outgoing email.
  4. Repeat on production in a quiet window, empty the template cache, and run the cron by hand.
  5. Watch the logs through the first daily run and keep the rollback copy until you approve its removal.

Security releases follow the same path on a shorter clock. The staging test is trimmed to the checks that matter most, because leaving a known hole open is a risk too. Feature releases can wait for a calmer week.

What happens when PHP, modules or gateways change?

Each change is treated as its own small project, because a provider can retire something with little warning. When a host drops an old PHP version, I check that the newer version has a matching ionCube Loader, that every encoded third-party module and theme has a build for it, and that custom code does not use functions PHP has removed. When a gateway or registrar publishes an API change, I update or patch the module and test it with a small live transaction. If a vendor no longer supports its module, I tell you early and we choose between a replacement and a small custom build.

Should I pay hourly or monthly?

Pay hourly if your needs are occasional, and monthly if you want routine checks and planned upgrades. Hourly work costs $55 to $65 per hour and only runs when you ask for it. A monthly arrangement is quoted per scope and covers the health check and upgrade planning, with the scope written into the quote. You can start hourly and move to monthly later, with the baseline review already done.

What counts as an ad-hoc fix, and how fast will I hear back?

An ad-hoc fix is any single problem you report between scheduled checks, and I typically reply within one business day. Typical jobs are a gateway callback that stopped marking invoices paid, an error after a module update, a server module that cannot reach cPanel, emails that stopped arriving, or a slow admin area. A good report makes it faster. Send what you saw, when it started, the exact error text and anything that changed just before, such as an upgrade, a PHP switch or a new addon. I work billing-stopping problems first, then checkout and client-facing faults, then everything else.

What is not included?

New feature builds are quoted separately, whether a module (custom module development), a new integration or a theme change. A move to another server is a migration project. Operating-system administration and monitoring of the server underneath fall under server monitoring and performance. I do not answer your customers' tickets, give legal or tax advice, or work on unlicensed WHMCS copies. For a deeper review of exposure and access, order the security audit. The official WHMCS documentation covers release notes and system requirements.

What do I need from you?

  • An admin login and SSH or panel access, which you can revoke at any time.
  • A list of installed addons, custom modules and who built them, if known.
  • Someone who can approve upgrade windows and spending on new work.

Who this is for

  • Hosting companies and resellers whose every invoice depends on WHMCS and who want someone watching it
  • Owners whose original developer has moved on and who need a careful pair of hands for upgrades and fixes
  • Businesses with custom modules or hooks that must keep working after each WHMCS or PHP change
  • Teams that would rather find problems in a monthly check than through a client complaint

What is included

  • Planned WHMCS upgrades, rehearsed on a staging copy before production
  • PHP version changes, with ionCube Loader and extension checks
  • Cron and automation monitoring, including the daily run
  • Backup checks and restore tests
  • License, addon and third-party module update handling
  • Review of gateway and registrar notices and API changes
  • Monthly health review on a monthly arrangement, and ad-hoc fixes at the hourly rate

How the work runs

  1. 1

    Baseline

    I record your WHMCS version, PHP version, modules, hooks, cron setup and backup method, and flag anything risky, such as edited core files or no tested restore.

  2. 2

    Clear the urgent items

    Problems that threaten billing, such as a stopped cron or failing callbacks, come first. Lower risks go on a short list with my recommended order.

  3. 3

    Set the routine

    We agree an upgrade calendar, what gets monitored and who receives the monthly summary, if you choose the monthly arrangement.

  4. 4

    Handle requests

    You email what is wrong. For anything bigger than a quick fix I tell you the likely hours before I start.

  5. 5

    Report

    I note every change in writing, so the next admin, or you in a year, can see what was done and why.

Frequently asked questions

How much does WHMCS support cost?

Hourly work is $55 to $65 per hour. A monthly arrangement is quoted per scope, because a small reseller with stock WHMCS and a host with a dozen custom modules need very different amounts of attention. I send a written quote within one business day of a short scoping call.

How quickly do you respond?

I typically reply within one business day. I am based in India and work with clients worldwide, so time zones differ. If billing is stopped, put that in the subject line and describe the symptom. I read those first, but I do not promise round-the-clock cover.

Should I choose hourly support or a monthly arrangement?

Choose hourly if you only need help now and then. Choose monthly if you want scheduled checks, planned upgrades and a person who already knows your setup. If you have used more than a few hours of fixes in each of the last few months, monthly is usually the better fit.

Do you answer tickets from my customers?

No. I support your WHMCS system, not your end customers. If a client ticket reveals a fault in billing, cron or a module, send me the technical details and I will fix the cause. Your own team keeps the conversation with the customer.

Can you take over an installation another developer built?

Yes. I start with a baseline review and write down what I find, including edited core files, unsupported modules and missing backups. I then fix the risky items first. I cannot work on unlicensed or nulled copies of WHMCS.

Do you upgrade WHMCS the day a release comes out?

Security releases are applied promptly. Other releases wait until I have read the release notes and run the upgrade on a staging copy with your modules, hooks and theme. A few days of waiting costs little, and a bad upgrade on a live billing system costs a great deal.

Related services

Ready to talk about your project?

Send the details and I reply within one business day with questions, an estimate and a plan.