eKYC Guard is the ultimate automated identity verification (KYC/AML) and fraud prevention gate for WHMCS. It stops fraudulent signups, stolen credit cards, phishing, spam VPS networks, and crypto mining abuse at the source by holding product and domain provisioning until the customer verifies their real-world identity.
Whether you want strict verification on high-risk VPS/dedicated servers, or completely frictionless zero-touch checkouts that only trigger KYC when suspicious VPNs, Tor exit nodes, or proxies are detected, eKYC Guard gives you complete, automated control directly inside your WHMCS admin.
strict_only): Friction-free for clean domestic visitors—verification is only enforced if a VPN, proxy, or high risk score is detected.override): Suspicious visitors are immediately gated, even if the product or client was normally excluded from scope.Connect with industry-leading identity verification providers through a single unified engine:
PreModuleCreate, AfterShoppingCartCheckout, ShoppingCartCheckoutComplete, and registrar commands (PreRegistrarRegisterDomain, PreRegistrarTransferDomain).Pending until verified.sendemail=true).AdminAreaViewTicketPage).sodium (optional, for document encryption at rest).modules/addons/ekycguard/. Zero modifications to WHMCS core files.Will this slow down legitimate customers during checkout?
No. Legitimate customers can complete verification in under 2 minutes. Furthermore, using the Dynamic Risk-Based KYC (strict_only) mode, safe direct connections bypass KYC completely, gating only visitors on VPNs, Tor, or suspicious proxies.
Can I offer manual review as a backup?
Yes! You can enable multiple automated providers alongside manual document upload. If an automated provider is unavailable, customers can upload their ID for admin review.
What happens to unpaid orders?
eKYC Guard checks the invoice payment status. Unpaid orders remain safely held until the customer both pays and passes verification, preventing premature provisioning.
Does it work with customized WHMCS themes and order forms?
Yes. eKYC Guard hooks into core WHMCS execution cycles and uses framework-independent styling, ensuring 100% compatibility with standard, Twenty-One, Lagom, and custom order forms.
Be the first to review eKYC Guard — Identity Verification & Fraud Prevention for WHMCS.
The best place to start if you need help with a specific product is to contact the developer. All WHMCS Marketplace developers have both a website and support URL listed.
override mode (forces KYC for high-risk IPs even if out of scope) and strict_only mode (enables frictionless zero-touch checkout for clean IPs, requiring KYC only for risky connections).127.0.0.1) and private subnets (192.168.x.x, 10.x.x.x) to prevent false positives in dev environments.AdminAreaViewTicketPage) with security alerts against unauthorized server changes.AfterShoppingCartCheckout and ShoppingCartCheckoutComplete to guarantee order gating across all order forms.PreModuleCreate and registrar hooks for nested $vars['params'].KycManager::autoProvision to eliminate duplicate ModuleCreate calls and prevent repeat welcome emails.tbladmins for local API background jobs.
sendemail=true) when auto-provisioning services after successful verification.
###Added Aadhaar Demographic Extraction: Automatically extracts verified demographic data (Name, Email, DOB, Gender) and the DigiLocker Reference ID from Aadhaar XML responses in memory. This data is now saved to the verification record and surfaced directly in the Admin review screen, keeping the system fully compliant with UIDAI data storage constraints (the physical file is discarded).
###Added Admin Area Version Badge: Added a dynamic version indicator to the module's "Settings & endpoints" tab. If a new update is available on Arahoster, it displays a red "Update to version X.X.X" button. If running the latest version, it displays a green "Latest version" badge.
###Fixed UIDAI Compliance: Added strict restrictions to block the download and storage of Aadhaar cards from DigiLocker / API Setu, while allowing other approved documents.
###Added #####Auto-Delete Rejected Entries: Added a daily cron routine to automatically purge "Rejected" verification records and their associated uploaded documents after a configurable number of days.
DigiLocker Integration: Implemented a standalone callback page to bypass the MeriPehchaan OAuth gateway ampersand decoding bug and prevent redirect_uri_mismatch errors.
DigiLocker Integration: Automatically fetch and securely download the user's issued documents (e.g., PAN, Driving License) into the Document Store after a successful OAuth exchange. Added support for raw XML document parsing to prevent failures on native Aadhaar profiles.
Fixed DigiLocker Integration: Updated the OAuth endpoint from /authorize to /consent to resolve redirect_uri_mismatch errors.
[1.4.0] — 2026-07-23 Added Didit KYB Support: Added dynamic routing for Know Your Business verifications. If a WHMCS client has a populated companyname and a KYB Workflow ID is configured, they will be seamlessly routed to the Didit KYB flow instead of the standard KYC flow.
New verification providers: - Stripe Identity, Sumsub, Onfido, Persona and Shufti Pro (in addition to Didit, DigiLocker and manual review).
New capabilities: - AML / sanctions / PEP screening - a potential match is sent to manual review instead of being auto-approved. - Require KYC only for specific products or product groups. - Periodic re-verification (re-KYC) after a chosen number of months. - Automatic provisioning of pending services and orders once a customer is verified. - GDPR consent capture before verification starts. - Document encryption at rest, plus automatic document retention/cleanup. - Document-access audit logging. - Multi-language client area: English, Spanish, French and Arabic. - Editable WHMCS email templates (invitation, reminders, approved, rejected). - Mobile camera capture when uploading documents.
Admin improvements: - Bulk approve / reject / email actions on the dashboard. - "Test connection" buttons for each verification provider. - AML result and consent shown on the customer review screen.
Security: - Stronger webhook validation and replay protection.
==============================================================================
Easily generate and change passwords for your clients without the need to send an email
Give your customers the power to unblock themselves from the CSF Firewall! Lessen your staff support ticket load