Develop a WHMCS Domain Reseller Module (Registrar + Addon + REST API, EPP/FRED, TZS)

Job ID: 39774684

Budget: $30 – $250 USD

Project Overview
We need a custom WHMCS Domain Reseller solution comparable to ModulesGarden’s domains reseller concept. The project includes a WHMCS registrar module, a WHMCS addon (reseller panel), and a secure REST API for downstream resellers to automate domain operations. Primary target includes .tz (TZNIC/FRED/EPP) with a generic EPP layer and room to add more TLDs later. Our WHMCS runs latest version on PHP 8.x; default currency TZS.

Scope & Features

WHMCS Registrar Module

Register / Transfer / Renew / Restore

Contacts (create/update/verify), Auth/EPP codes, Host/Nameserver management

Registrar lock, WHOIS privacy toggle (if supported), status sync via CRON

Redemption & grace fees handling; configurable per-TLD rules

WHMCS Addon (Reseller Panel)

Reseller onboarding/approval, KYC fields, status & email notifications

Wallet (prepaid), credit limits, auto top-up via WHMCS gateways (Stripe/PayPal + generic)

Tiered pricing: global price list + per-reseller overrides; margin % or fixed; promo windows

Order list, finance logs, exports, alerts (low balance, failed orders)

Role-based access; audit logs

Reseller API

Endpoints: domain check, register, transfer (in/out), renew, contacts, hosts, lock/unlock, WHOIS privacy, get EPP.

Security: API keys, IP whitelist, rate limit, HMAC signatures (optional), webhooks (order state changes, low balance).

Docs: OpenAPI/Swagger + Postman collection + example scripts (PHP/Python).

TLD/Registry Layer

EPP/FRED support for .tz (TZNIC) with proper commands & flows; configurable mapping (statuses, periods, fees).

Generic EPP adapter interface to add new registries.

TLD import/manager: min/max years, transfer requirements, required docs flags.

Automation & Sync

CRON jobs for status/expiry sync, auto-renew logic, redemption handling, webhooks retry.

WHOIS sync (if supported), registrar lock consistency.

Compliance & Security

OWASP best practices; CSRF/SQLi/XSS mitigations; secure secrets handling.

Robust logging with PII-safe redaction.

GDPR-ready export/delete hooks where applicable.

Deliverables

Source code (unencrypted), Composer project, PSR-4 namespaces.

Installer + config docs, upgrade notes, troubleshooting/FAQ.

Test plan + minimal unit/integration tests for critical actions.

Staging demo prior to production handover.

30–60 days warranty bug-fix window (negotiate).

Environment

WHMCS latest, PHP 8.1/8.2, MySQL, Apache2, Ubuntu (CloudLinux on prod).

Default currency TZS; multi-currency support must work.

Integration with .tz (TZNIC/FRED) should be first-class.

Milestones (suggested)

Design & API Spec (OpenAPI, DB schema, flows) – 15%

Core Registrar + EPP Adapter (register/renew/transfer, contacts/hosts) – 30%

Addon (Reseller Panel) + Wallet/Pricing – 30%

Reseller API + Webhooks + Tests + Docs – 15%

Staging, UAT, Handover – 10%

What to include in your bid

Past WHMCS modules/registrars you built (links or repos).

Approach to EPP/FRED and adding new registries.

Outline of DB schema for wallet & pricing tiers.

Security plan (auth, rate limits, secrets, audit).

Delivery timeline and total cost (fixed-price preferred).

Confirmation of unencrypted source and license/ownership.

Selection Notes

Prior WHMCS registrar/addon experience is essential.

Familiarity with EPP and domain life-cycle (RGP, grace fees).

Strong PHP 8, Composer, PSR-4, MySQL skills.

Tags/Skills
WHMCS, PHP, Registrar Module, Addon Module, EPP, FRED, TZNIC, REST API, OpenAPI, Swagger, MySQL, cPanel/CloudLinux, Payments, Multi-currency, Tanzania.
Related categories: PHP Software Architecture MySQL WHMCS Security Automation REST API