eKYC Guard — Identity Verification & Fraud Prevention for WHMCS

eKYC Guard — Identity Verification & Fraud Prevention for WHMCS

Developed By Arahotser

Compatible with WHMCS v9.0

Stop Hosting Fraud, Chargebacks & Server Abuse Before Provisioning

eKYC Guard is the ultimate automated identity verification (KYC/AML) and fraud prevention gate for WHMCS. It stops fraudulent signups, stolen credit cards, phishing, spam VPS networks, and crypto mining abuse at the source by holding product and domain provisioning until the customer verifies their real-world identity.

Whether you want strict verification on high-risk VPS/dedicated servers, or completely frictionless zero-touch checkouts that only trigger KYC when suspicious VPNs, Tor exit nodes, or proxies are detected, eKYC Guard gives you complete, automated control directly inside your WHMCS admin.

Why Web Hosts Choose eKYC Guard

  • Eliminate Chargebacks & Payment Fraud — Fraudsters using stolen cards or fake identities cannot pass biometric KYC. They abandon the cart before costing you chargeback fees.
  • Protect Your IP Reputation & Infrastructure — Prevent your subnets from being blacklisted by stopping phishing hosts, spammers, and abuse networks before a single server is deployed.
  • Dynamic Risk-Based KYC (Zero-Friction Checkout) — Don't add friction for good customers. With built-in IP reputation scoring, direct legitimate customers check out instantly, while visitors using VPNs, Tor, or anonymizers are automatically gated.
  • Support Ticket Agent Warning Badge — Warn your support staff in real time inside the WHMCS ticket interface when a ticket is opened by an unverified customer, blocking social engineering and unauthorized server re-installs.
  • Bank-Grade Compliance & AML Screening — Screen names against global sanctions and PEP watchlists (OpenSanctions). Stay compliant with GDPR, Indian UIDAI guidelines, and payment processor KYC mandates.
  • 100% Set-and-Forget Automation — Automated KYC invitations, reminder cadences, grace periods, auto-suspension, auto-termination, and instant auto-provisioning the moment a customer passes.

Comprehensive Feature Breakdown

1.Dynamic Risk-Based KYC (IP & Proxy Gating) — NEW in v1.5.7

  • ProxyCheck.io & IPQualityScore Integration: Inspects customer IP addresses in real time.
  • Threat Detection: Automatically flags commercial VPNs, Tor Exit Nodes, Public/Private Proxies, and elevated fraud risk scores (0–100).
  • Flexible Enforcement Modes:
    • Strict Only Mode (strict_only): Friction-free for clean domestic visitors—verification is only enforced if a VPN, proxy, or high risk score is detected.
    • Override Mode (override): Suspicious visitors are immediately gated, even if the product or client was normally excluded from scope.
  • Quota-Saving Cache: 24-hour local caching eliminates redundant API lookups and preserves third-party quotas.
  • Admin Risk Panel: Direct visibility into IP risk scores, ASN, country, and detection flags inside the verification audit view.

2.Multi-Provider Verification Suite

Connect with industry-leading identity verification providers through a single unified engine:

  • Didit (Global): 220+ countries, passport/ID scanning, 3D biometric liveness, and dynamic KYB (Know Your Business) workflow routing for corporate accounts.
  • DigiLocker (India): Official government-backed identity verification via OAuth2 + PKCE. Extracts verified demographic data (Name, DOB, Gender) in memory while maintaining strict UIDAI compliance.
  • Stripe Identity: Hosted document and selfie verification backed by Stripe.
  • Sumsub: Full-cycle identity verification with custom KYC levels.
  • Onfido: Enterprise Studio workflows and document validation.
  • Persona: Tailored inquiry templates and fraud risk signals.
  • Shufti Pro: Real-time AI-powered document and facial verification.
  • Manual Review: Secure customer document upload with drag-and-drop admin review and upload-on-behalf tools.

3.Provisioning Firewall & Auto-Provisioning

  • Interception Hooks: Hooks seamlessly into PreModuleCreate, AfterShoppingCartCheckout, ShoppingCartCheckoutComplete, and registrar commands (PreRegistrarRegisterDomain, PreRegistrarTransferDomain).
  • Zero Premature Activation: Free trials, promo codes, and unpaid orders are safely held in Pending until verified.
  • Instant Auto-Provisioning: Once a customer passes verification, pending orders and services are automatically accepted and created, triggering WHMCS Welcome Emails (sendemail=true).
  • Duplicate-Safe: Built-in order-first deduplication prevents duplicate server deployments or repeated welcome emails.

4.Support Ticket Agent Protection Badge

  • Embeds an interactive security banner directly into the WHMCS Admin Support Ticket view (AdminAreaViewTicketPage).
  • Displays instant status: Verified (with provider & document type), Under Review, or Unverified.
  • Actively warns support agents: "Do not process password resets, server re-installs, or EPP transfers without verification."
  • Includes a 1-click KYC Invitation Email trigger for rapid resolution.

5.Precision Scoping Controls

  • Product Scope: Apply KYC to all products, or restrict enforcement to specific packages or product groups (e.g., enforce on Dedicated Servers & Cloud VPS, bypass for shared hosting).
  • Client Scope: Enforce globally, or whitelist/blacklist specific Client IDs or Client Groups.
  • TLD Gating: Filter domain registrations by TLD whitelist or blacklist.

6.Privacy, Security & GDPR Compliance

  • AML & Sanctions Screening: Automatically checks verified customer names against sanctions, PEP, and criminal watchlists. Flagged hits route to manual review.
  • GDPR Lawful Basis: Optional explicit consent checkbox captured with audit timestamp.
  • Libsodium Encryption at Rest: Documents are encrypted on disk with strong cryptography outside the web root.
  • Automated Data Purge: Auto-deletes stored identity documents after your configured retention period (e.g., 30 days) while preserving the audit trail.
  • Auto-Delete Rejected Entries: Daily cron automatically purges rejected records and files after a customizable window.
  • GDPR Right to Be Forgotten: Automatically cleanses verification records upon client deletion in WHMCS.

7.Native, Responsive Client Area

  • Localized Multi-Language Support: Built-in translations for English, Spanish, French, and Arabic (with complete RTL support).
  • Mobile Camera Capture: Mobile-optimized document and selfie uploading directly from smartphone cameras.
  • Animated Banner & Status Badges: Sleek, non-intrusive floating alerts that notify unverified clients without disrupting page navigation.
  • Real-Time Polling: Verification screens automatically refresh the instant an external webhook confirms approval.

Requirements

  • WHMCS: Compatible with WHMCS 7.4 through 8.x and 9.x.
  • PHP: PHP 7.4 to PHP 8.1, 8.2, 8.3+ with cURL.
  • Web Server: HTTPS enabled (mandatory for provider webhooks and redirects).
  • Extensions: sodium (optional, for document encryption at rest).
  • Installation: Clean modular installation into modules/addons/ekycguard/. Zero modifications to WHMCS core files.

Frequently Asked Questions

Will this slow down legitimate customers during checkout?
No. Legitimate customers can complete verification in under 2 minutes. Furthermore, using the Dynamic Risk-Based KYC (strict_only) mode, safe direct connections bypass KYC completely, gating only visitors on VPNs, Tor, or suspicious proxies.

Can I offer manual review as a backup?
Yes! You can enable multiple automated providers alongside manual document upload. If an automated provider is unavailable, customers can upload their ID for admin review.

What happens to unpaid orders?
eKYC Guard checks the invoice payment status. Unpaid orders remain safely held until the customer both pays and passes verification, preventing premature provisioning.

Does it work with customized WHMCS themes and order forms?
Yes. eKYC Guard hooks into core WHMCS execution cycles and uses framework-independent styling, ensuring 100% compatibility with standard, Twenty-One, Lagom, and custom order forms.

 

There are no reviews yet!

Be the first to review eKYC Guard — Identity Verification & Fraud Prevention for WHMCS.

Version Compatibility


Compatible with WHMCS v9.0

Full Version Compatibility


  • Selected versions of WHMCS v9.0
        9.0.0 - 9.0.4
  • Selected versions of WHMCS v8.13
        8.13.0 - 8.13.3

Support for this product

The best place to start if you need help with a specific product is to contact the developer. All WHMCS Marketplace developers have both a website and support URL listed.

Developed By Arahotser

Changelog

v1.5.7 Released September 17th, 2026

Latest Version


  • [New] Dynamic Risk-Based KYC: Integrated intelligent threat scoring using ProxyCheck.io and IPQualityScore to dynamically identify commercial VPNs, Tor exit nodes, and public proxies.
  • [New] Dual Risk Modes: Added override mode (forces KYC for high-risk IPs even if out of scope) and strict_only mode (enables frictionless zero-touch checkout for clean IPs, requiring KYC only for risky connections).
  • [New] Admin Risk Panel: Embedded an IP & Network Risk Assessment card in the verification review screen displaying Risk Score (0–100), ASN/ISP, Country, and risk indicators.
  • [New] Intelligent IP Caching: Added 24-hour local caching to minimize external API quota usage.
  • [New] Private Subnet Bypass: Automatically exempts localhost (127.0.0.1) and private subnets (192.168.x.x, 10.x.x.x) to prevent false positives in dev environments.
  • [New] Support Ticket Agent Badge: Embedded an interactive verification status badge directly into the WHMCS Admin Support Ticket view (AdminAreaViewTicketPage) with security alerts against unauthorized server changes.
  • [Fixed] Dual-Hook Checkout Capture: Intercepts orders on both AfterShoppingCartCheckout and ShoppingCartCheckoutComplete to guarantee order gating across all order forms.
  • [Fixed] Hook Parameter Resolution: Hardened parameter resolution in PreModuleCreate and registrar hooks for nested $vars['params'].
  • [Security] Admin CSRF Protection: Added multi-tier CSRF verification across all administrative actions.
  • [Fixed] Auto-Provisioning Deduplication: Refactored KycManager::autoProvision to eliminate duplicate ModuleCreate calls and prevent repeat welcome emails.
  • [Fixed] Admin User Fallback: Added automatic fallback to active admins in tbladmins for local API background jobs.

 

Previous Versions


v1.5.5 Released September 13th, 2026

View/hide detailed changelog

  • [Fixed] Checkout Email Dispatch: Dispatches KYC invitation emails immediately on checkout completion.
  • [Enhancement] Welcome Emails: Guaranteed WHMCS Welcome Emails (sendemail=true) when auto-provisioning services after successful verification.

 

v1.5.4 Released September 10th, 2026

View/hide detailed changelog

  • [Fixed] Invoice Payment Validation: Ensures invoices are Paid before auto-creating services, preventing premature setup of unpaid orders.

 

v1.5.3 Released August 20th, 2026

View/hide detailed changelog

###Added Aadhaar Demographic Extraction: Automatically extracts verified demographic data (Name, Email, DOB, Gender) and the DigiLocker Reference ID from Aadhaar XML responses in memory. This data is now saved to the verification record and surfaced directly in the Admin review screen, keeping the system fully compliant with UIDAI data storage constraints (the physical file is discarded).

###Added Admin Area Version Badge: Added a dynamic version indicator to the module's "Settings & endpoints" tab. If a new update is available on Arahoster, it displays a red "Update to version X.X.X" button. If running the latest version, it displays a green "Latest version" badge.

###Fixed UIDAI Compliance: Added strict restrictions to block the download and storage of Aadhaar cards from DigiLocker / API Setu, while allowing other approved documents.

 

v1.5.0 Released August 13th, 2026

View/hide detailed changelog

###Added #####Auto-Delete Rejected Entries: Added a daily cron routine to automatically purge "Rejected" verification records and their associated uploaded documents after a configurable number of days.

 

v1.4.3 Released August 9th, 2026

View/hide detailed changelog

Fixed

DigiLocker Integration: Implemented a standalone callback page to bypass the MeriPehchaan OAuth gateway ampersand decoding bug and prevent redirect_uri_mismatch errors.

Added

DigiLocker Integration: Automatically fetch and securely download the user's issued documents (e.g., PAN, Driving License) into the Document Store after a successful OAuth exchange. Added support for raw XML document parsing to prevent failures on native Aadhaar profiles.

 

v1.4.1 Released August 8th, 2026

View/hide detailed changelog

Fixed DigiLocker Integration: Updated the OAuth endpoint from /authorize to /consent to resolve redirect_uri_mismatch errors.

 

v1.4.0 Released July 23rd, 2026

View/hide detailed changelog

[1.4.0] — 2026-07-23 Added Didit KYB Support: Added dynamic routing for Know Your Business verifications. If a WHMCS client has a populated companyname and a KYB Workflow ID is configured, they will be seamlessly routed to the Didit KYB flow instead of the standard KYC flow.

 

v1.0.0 Released June 3rd, 2026

View/hide detailed changelog

============================================================================== eKYC Guard for WHMCS - Changelog

Version 1.1.2

  • Security: hardened the customer verification page against malicious input (defense-in-depth). No action required after updating.

Version 1.1.1

  • Licensing reliability improvements.

Version 1.1.0

New verification providers: - Stripe Identity, Sumsub, Onfido, Persona and Shufti Pro (in addition to Didit, DigiLocker and manual review).

New capabilities: - AML / sanctions / PEP screening - a potential match is sent to manual review instead of being auto-approved. - Require KYC only for specific products or product groups. - Periodic re-verification (re-KYC) after a chosen number of months. - Automatic provisioning of pending services and orders once a customer is verified. - GDPR consent capture before verification starts. - Document encryption at rest, plus automatic document retention/cleanup. - Document-access audit logging. - Multi-language client area: English, Spanish, French and Arabic. - Editable WHMCS email templates (invitation, reminders, approved, rejected). - Mobile camera capture when uploading documents.

Admin improvements: - Bulk approve / reject / email actions on the dashboard. - "Test connection" buttons for each verification provider. - AML result and consent shown on the customer review screen.

Security: - Stronger webhook validation and replay protection.

Version 1.0.0

  • First release.
  • Block product / service and domain provisioning until the customer passes identity verification.
  • Providers: Didit (global), DigiLocker (India) and manual document review.
  • Automated verification invitations and reminders.
  • Grace-period auto-suspend, terminate and account-disable - automatically reversed when the customer verifies.
  • Admin dashboard with review, approve / reject and an activity log.
  • Client-area verification page, status badge and banner.

==============================================================================

 

See also

The SSL Store™ WHMCS SSL Reseller Module

Sell 110+ SSL and website security products in WHMCS

Free
Client Password Changer

Easily generate and change passwords for your clients without the need to send an email

Free
Abuse Manager Pro

Creating & managing abuse reports just got easier!

Commercial
CSF Unblocker v4

Give your customers the power to unblock themselves from the CSF Firewall! Lessen your staff support ticket load

Commercial
Phone Verification

Automated Phone Verification. Protect your business and your users

Commercial