FraudClient

FraudClient

Developed By FraudClient

Compatible with WHMCS v9.0

FraudClient.com offers a powerful, free WHMCS addon designed to empower web hosting companies with robust tools to manage and mitigate abusive client behavior.

Our addon seamlessly integrates with WHMCS, enabling providers to access real-time reports from a shared database of flagged clients, ensuring informed decision-making. Additionally, it allows users to submit new reports, fostering a collaborative network to maintain a secure hosting environment.

With an intuitive interface and streamlined functionality, FraudClient enhances client management efficiency, helping businesses protect their operations while maintaining exceptional service standards. Join our growing community to leverage this essential tool for a safer, more reliable hosting ecosystem.

 

There are no reviews yet!

Be the first to review FraudClient.

Version Compatibility


Compatible with WHMCS v9.0

Full Version Compatibility


  • Selected versions of WHMCS v9.0
        9.0.0 - 9.0.6
  • Selected versions of WHMCS v8.13
        8.13.0 - 8.13.5
  • Selected versions of WHMCS v8.12
        8.12.0, 8.12.2
  • All versions of WHMCS v8.11
  • Selected versions of WHMCS v8.10
        8.10.0
  • Selected versions of WHMCS v8.9
        8.9.0
  • Selected versions of WHMCS v8.8
        8.8.0
  • All versions of WHMCS v8.7
  • All versions of WHMCS v8.6
  • All versions of WHMCS v8.5
  • All versions of WHMCS v8.4
  • All versions of WHMCS v8.3
  • All versions of WHMCS v8.2
  • All versions of WHMCS v8.1
  • All versions of WHMCS v8.0

Support for this product

The best place to start if you need help with a specific product is to contact the developer. All WHMCS Marketplace developers have both a website and support URL listed.

Developed By FraudClient

Changelog

v1.4.2 Released August 20th, 2026

Latest Version


FraudClient for WHMCS v1.4.2

Release Date: August 20, 2026

FraudClient v1.4.2 is a major cumulative update from v1.2.7. It introduces complete report management inside WHMCS, a redesigned administration interface, faster client screening, improved WHMCS integration, and extensive security and reliability enhancements.

New Overview Dashboard

  • Added a dedicated FraudClient overview inside WHMCS.
  • Added live FraudClient connection status.
  • Added totals for submitted reports, recently checked clients, at-risk clients, and pending removal requests.
  • Added recent-report activity with associated WHMCS client information.
  • Added quick access to client screening, report management, and removal requests.

Complete Report Management

  • Added the ability to manage company-submitted reports without leaving WHMCS.
  • Added searching by report ID, report reason, and report details.
  • Added filtering by report category and associated WHMCS client.
  • Added sorting by newest, oldest, highest fraud points, or lowest fraud points.
  • Added improved report pagination and result totals.
  • Added direct links to view individual reports on FraudClient.com.
  • Added safer report deletion with explicit confirmation.
  • Automatically clears affected cached results when reports are filed, deleted, or removed.
  • Added automatic linking between submitted reports and WHMCS client accounts.
  • Added discovery of WHMCS clients associated with previously submitted reports.

Removal-Request Management

  • Added a dedicated removal-request center inside WHMCS.
  • Administrators can review the requester, removal reason, original report information, and report details.
  • Added approval controls that permanently delete the report and remove its fraud points.
  • Added rejection controls that close the request while keeping the report active.
  • Added server-side confirmation requirements for all removal decisions.
  • Added a pending-request count to the FraudClient navigation and overview.

WHMCS Client Integration

  • Added FraudClient actions directly to WHMCS client summary pages.
  • Added Check Client, File Report, and View Reports shortcuts.
  • Added a compact FraudClient panel to each WHMCS client profile.
  • Opening a client profile does not automatically contact the external API.
  • Added exact numeric WHMCS client-ID searching.
  • Added client-specific report filtering from client summary pages.

Client Screening Improvements

  • Completely redesigned the FraudClient client list.
  • Added support for checking one client or up to 50 selected clients at once.
  • Added faster server-side concurrent processing for multi-client checks.
  • Added configurable local caching to reduce unnecessary API requests.
  • Cached results automatically expire when client identifiers change or the configured cache period is reached.
  • Added forced per-client refreshing when current results are required.
  • Added inline match details, including report category, fraud points, matched identifiers, reporting company, and report details.
  • Reworked Full Results into a secure server-side workflow that performs a fresh query and opens matching reports from all participating FraudClient companies.
  • Improved Refresh, Details, Full Results, and Report actions with a compact single-line layout.
  • Preserved and improved at-a-glance highlighting for clients with fraud points.
  • Improved searching and pagination across the client list.
  • Improved Last Checked timestamps with readable local formatting and the complete timestamp available as a tooltip.
  • Improved handling of empty results, unavailable data, and failed client checks.

Report Filing Improvements

  • Completely rebuilt the report-submission workflow.
  • Report information is now submitted securely through the WHMCS server instead of browser-side API requests.
  • Client information is loaded directly from the authoritative WHMCS client account.
  • Added selectable report identifiers, including name, email address, telephone number, and IP address.
  • Added the client’s existing FraudClient risk summary before submission.
  • Added report-category fraud-point previews.
  • Added report-detail validation and character counting.
  • Added a guided review screen showing exactly what will be submitted.
  • Added a mandatory confirmation step before filing a report.
  • Added server-side enforcement of the review requirement to prevent bypassed or accidental submissions.
  • Added clear success confirmation containing the newly created report ID.
  • Automatically associates newly filed reports with the correct WHMCS client.

Security Enhancements

  • All FraudClient API communication now takes place on the WHMCS server.
  • The FraudClient API key is no longer rendered in Smarty templates or exposed to browser JavaScript.
  • The API key is no longer included in JSON request bodies.
  • API authentication now uses the Authorization header.
  • Added HTTPS-only API URL validation.
  • Added complete SSL certificate and hostname verification.
  • Added CSRF protection to report submissions, report deletions, removal decisions, client refreshes, and Full Results requests.
  • Added stricter server-side validation for client IDs, report categories, report details, selected identifiers, and confirmation values.
  • Added secure random CSRF tokens and timing-safe token comparisons.
  • Added explicit confirmation values for permanent or sensitive actions.
  • Added safer redirects and validated result destinations.
  • API credentials remain entirely on the WHMCS server.

Performance and Reliability Improvements

  • Added concurrent API processing in controlled batches for faster multi-client screening.
  • Added WHMCS database-backed caching for client screening results.
  • Added local report-to-client associations.
  • Added improved handling for API connection failures and timeouts.
  • Added improved handling for invalid or unexpected API responses.
  • Added clearer authentication and rate-limit messages.
  • Added safer user-facing errors while preserving diagnostic information in WHMCS activity logs.
  • Added cache invalidation after report changes to prevent outdated risk totals.
  • Add-on cache data and report associations are preserved when the module is temporarily deactivated.
  • Improved IPv4 and IPv6 handling when reading client login information.
  • Improved API authentication reliability for retrieving and managing reports.

Interface Improvements

  • Introduced a consistent FraudClient navigation bar.
  • Added responsive dashboards, tables, cards, forms, alerts, status indicators, and pagination controls.
  • Added improved empty states and connection-status notices.
  • Added clearer validation feedback and success messages.
  • Added responsive layouts for narrower WHMCS administration screens.
  • Improved report-detail presentation and action placement.
  • Improved form accessibility, labels, review controls, and confirmation workflows.
  • Fixed hidden review controls appearing incorrectly under some WHMCS themes.
  • Fixed report-submission controls that could display in the wrong state.
  • Fixed cramped or wrapping client action buttons.
  • Fixed unclear and malformed Last Checked timestamps.
  • Fixed Full Results losing its intended destination after FraudClient website login or two-factor authentication.

Upgrade Instructions

This is a complete module update, not a single-template patch.

  • Upload the entire v1.4.2 package and overwrite the existing /modules/addons/fraudclient/ directory.
  • Open Configuration > System Settings > Addon Modules in WHMCS.
  • Activate FraudClient or save its existing settings again so WHMCS detects the new module files and client-summary hooks.
  • Verify the HTTPS FraudClient API URL, API key, and preferred cache duration.
  • Grant the appropriate WHMCS administrator roles access to the add-on.

Users upgrading from v1.2.7 should replace the complete module directory because v1.4.2 includes new library files, templates, database-backed caching, report associations, navigation components, and WHMCS hooks.

 

Previous Versions


v1.2.7 Released September 19th, 2025

View/hide detailed changelog

Squashed some bugs.

 

v1.2.6 Released September 12th, 2025

View/hide detailed changelog

FraudClient for WHMCS v1.2.6 Released: UI/UX Improvements & Direct Report Links

We're excited to announce the release of FraudClient for WHMCS version 1.2.6. This update is focused on improving your workflow and making it faster and easier to identify high-risk clients directly from your client list.

Based on valuable community feedback, we've introduced several quality-of-life improvements. Here’s what’s new:

Key Changes in v1.2.6 New Feature: Direct Link to Full Fraud Reports Previously, you could see that a client had reports, but getting to the details required extra steps. Now, when a client has one or more reports, a "View Reports" button will appear. This button links you directly to the full, detailed query results page on FraudClient.com, opening in a new tab for your convenience.

Workflow Improvement: Inline Fraud Point Checking The "Check Fraud Points" button for individual clients is now more intuitive. Instead of opening a modal, it now instantly refreshes the data for that specific client directly in the table row. This makes its behavior consistent with the "Check Selected Clients" button, providing a faster and more seamless experience.

Visual Improvement: At-a-Glance Highlighting To help you immediately spot clients with a history, the "Fraud Points" cell will now automatically turn red with white text whenever a client's fraud point total is greater than zero. This visual cue makes it incredibly easy to scan your client list and identify potential risks without having to click anything.

How to Upgrade To upgrade to version 1.2.6, simply download the latest files and overwrite the existing templates/clientlist.tpl file in your /modules/addons/fraudclient/ directory.

We believe these changes will significantly speed up your fraud-checking process. As always, we welcome your feedback and suggestions. Thank you for being a part of the FraudClient community!

Best regards, The FraudClient Team

 

v1.2.5 Released August 12th, 2025

View/hide detailed changelog

Fixed bug where all client identifiers were not being passed to API.

 

v1.2.4 Released July 17th, 2025

View/hide detailed changelog

FraudClient WHMCS Addon - Version 1.2.4 Release Date: July 17, 2025

This version is a critical maintenance release that addresses several major bugs, enhancing the stability and functionality of the addon, especially for users operating on external domains.

Fixes *Fixed: A critical authentication failure that prevented the addon from submitting reports when used on any external (cross-domain) website. The root cause was an incorrect code execution order in api.php that has been corrected. *Fixed: The "No reports by you" error on the Client List page for external domains. The addon now correctly identifies which reports were filed by your company. *Fixed: Fatal syntax errors in both api.php and fraudclient.php that prevented the scripts from executing properly.

Improvements *Improved: The API key authentication method is now more robust. The key is sent in the request body, bypassing server configurations that might strip the Authorization header. *Improved: IP address detection on the "Report Client" page to correctly parse the data format provided by the WHMCS API, ensuring the field auto-fills correctly. *Improved: The IP address parsing logic has been updated to support both IPv4 and IPv6 address formats.Improved: The API's Cross-Origin Resource Sharing (CORS) and session cookie policies have been modified to be more secure and compatible with cross-domain requests.

 

v1.2.2 Released July 8th, 2025

View/hide detailed changelog

<h2>Key Enhancements and Fixes</h2> <h5>Resolved Pagination Issue in Client List:</h5>

  1. Problem: Previously, the pagination links on the client list page would disappear when navigating to subsequent pages.
  • Solution: The fraudclient.php file has been updated to ensure the totalresults for client pagination is accurately retrieved from the WHMCS local API. A separate API call is now made to fetch the total client count, guaranteeing that the pagination links remain visible and functional across all pages.
  1. Codebase Cleanup and Optimization:
  • Removed Debugging Logs: Extensive console.log statements and debugging-specific comments have been removed from clientlist.tpl and reportclient.tpl JavaScript, and logActivity calls have been removed from fraudclient.php.

  • Streamlined Comments: General development and internal notes have been cleaned up across fraudclient.php, clientlist.tpl, and reportclient.tpl to improve code readability and maintain a production-ready standard.

 

v1.2.1 Released June 25th, 2025

View/hide detailed changelog

Fixed *API Request Method for Client Report Search: Corrected the method used for proxying search_client_reports requests from the WHMCS addon to the FraudClient API. Previously, the addon was sending a GET request, leading to an "At least one client identifier is required" error on the FraudClient API side, even when identifiers were present. This has been updated to use a POST request (fraudclient_api_post), ensuring that client identifiers are correctly sent in the JSON request body, aligning with the FraudClient API's expected behavior. This resolves the issue where client reports were not being displayed in the WHMCS admin area.

 

v1.2 Released June 19th, 2025

View/hide detailed changelog

Version 1.2 (Latest) - June 19, 2025 This update brings significant improvements to the module's usability, reliability, and administrative capabilities.

Key Changes & Improvements:

Enhanced Client Data Pre-filling on Report Page:

*Fix: Resolved an issue where client information fields on the "Report Client" page were grayed out and not automatically populated from the WHMCS client profile. These fields (Name, Email, Phone Number, IP Address) now dynamically pull data from the selected WHMCS client.

*Visibility: Input fields are no longer readonly, allowing for easy viewing and pre-filling.

Improved Readability of Form Fields:

*Enhancement: Increased the font size in all input fields and the "More Information (Details)" textarea on the "Report Client" page (reportclient.tpl) for better readability and user experience.

Robust API Communication (Dashboard & Addon):

*Fix: Addressed the SyntaxError: Unexpected token '<' and 404 (Not Found) issues that occurred during API calls from the dashboard. This was resolved by ensuring Smarty variables ({$api_base_url}, {$company_username}, {$company_password}) are correctly parsed and passed to JavaScript, preventing incorrect URL construction.

*Error Handling: Implemented more specific error logging and on-page error messages for API failures, aiding in quicker debugging.

Flexible WHMCS Admin API Username Configuration:

*Fix: Resolved the "No matching admin user found" error when making localAPI calls within WHMCS. The module now includes a dedicated configuration field (whmcs_admin_api_username) to specify an admin user with API permissions, ensuring seamless operation regardless of the logged-in admin.

*Fallback Logic: Improved getAdminUsername() helper function to prioritize the configured username, fallback to the current session, and then attempt to find any admin user, making the localAPI calls more robust.

Updated Module Metadata:

*Branding: Changed the author and copyright information within the module files to "FraudClient.com" for consistent branding.

*Version Bump: Module version updated to 1.2 to reflect these cumulative improvements.

We recommend all users update to this version for the best experience and improved functionality.

 

See also

FraudLabs Pro Fraud Prevention

Protect your business from fraud, chargebacks, and high-risk transactions

Free
Order Notes

Staff need to make a note

Commercial
WHMCS Order Assistant

Order Assistant helps you to automate order management process. It can automatically accept Pending Orders; send an email or open a ticket with client; and cancel the order if no payment is made still.

Commercial
Product Limiter

Allows you to limit the purchase of an products/services for each client

Commercial
IPQS Fraud Prevention & Order Validation

Accurate risk analysis for orders & users to prevent fraud and minimize chargebacks.

Free