Installation Guide
This guide covers the verified WHMCS addon placement and activation flow for Extendy GeoShield. Product package delivery may vary by release, so use the addon files supplied by Extendy for your version.
Requirements
Extendy GeoShield is built for WHMCS 9+.
Before installation, make sure:
- you have administrator access to WHMCS;
- you can place addon files under the WHMCS
modules/addons/directory; - your WHMCS daily cron is configured and running;
- you have provider credentials ready if you plan to use IPinfo or MaxMind for GeoIP lookup.
Install the addon files
Place the supplied addon directory in your WHMCS installation at:
modules/addons/extendy_geoshield/
The addon directory name must be:
extendy_geoshield
Do not modify WHMCS core files.
Activate the addon
In WHMCS Admin, open the WHMCS Addon Modules area and activate:
Extendy GeoShield for WHMCS
During activation, Extendy GeoShield prepares its own database schema, default settings, and email templates. Activation does not remove existing addon data.
The addon owns these database tables:
mod_extendy_geoshield_events
mod_extendy_geoshield_known_countries
mod_extendy_geoshield_trust_tokens
mod_extendy_geoshield_settings
Initial post-activation checks
After activation:
- Open the Extendy GeoShield addon admin page.
- Review the Settings tab.
- Confirm whether Addon Enabled should remain No or be changed to Yes.
- Select a GeoIP Provider if you want country detection.
- Enter the required provider credentials.
- Configure Client IP Source for your hosting topology.
- Confirm Retention is set to the desired value.
- Use the GeoIP Provider Test Connection form with a public test IP if you have configured a provider.
By default, the addon is installed with Addon Enabled set to No. Login processing starts only after the addon is enabled in its settings.
Cron requirement
Extendy GeoShield uses the WHMCS daily cron hook for retention cleanup. Make sure the normal WHMCS cron automation runs successfully.
When retention is set to 180 Days, old Extendy GeoShield login-event records are cleaned automatically through WHMCS cron. When retention is set to Disabled (Automatic Cleanup Off), automatic cleanup is disabled.
Credential handling
Provider credentials are stored encrypted at rest using WHMCS-supported encryption. The admin page displays stored credential fields as masked values only.
Submitting an empty credential field keeps the existing stored value. Use the explicit clear/remove control in the admin page if you want to remove a stored credential.
Deactivation
Deactivation is not a full uninstall. It does not delete Extendy GeoShield tables, settings, login events, Smart Mode known countries, trust tokens, or email templates.
Full removal is a separate manual procedure and should only be performed after a verified database backup.