Skip to main content

Product Overview

Extendy GeoShield is a WHMCS 9+ addon module for monitoring client-area login activity by country and sending security notifications when a login appears unusual according to the configured alert mode.

It is designed for WHMCS administrators and operators who want better visibility into account-access patterns without turning the addon into a login firewall.

What Extendy GeoShield monitors

When enabled, Extendy GeoShield monitors WHMCS client-area user logins. For each normal login event, the addon can record safe metadata such as:

  • the WHMCS User that logged in;
  • the safely resolved Client Account context, when available;
  • the login IP address, when a public client IP can be safely resolved;
  • the detected country, when GeoIP lookup succeeds;
  • the alert decision;
  • the email notification outcome;
  • IP-source resolution metadata.

Admin Login as Client / masquerading behaviour is excluded from normal login alerting where applicable, so administrator impersonation does not create normal customer security alerts or Smart Mode trusted-country changes.

Key capabilities

Extendy GeoShield provides:

  • country-aware login monitoring for WHMCS client-area logins;
  • configurable alert modes;
  • global trusted countries;
  • Smart Mode known countries for user/client account contexts;
  • Smart Mode trust links that require authenticated WHMCS access;
  • GeoIP lookup through supported external providers;
  • WHMCS email-template based notifications;
  • a read-only Login Events admin page;
  • configurable client IP source handling for direct, Cloudflare, and trusted-proxy deployments;
  • automatic login-event retention cleanup through the WHMCS daily cron hook.

Trusted countries

A trusted country is a country that should not normally trigger a security alert in certain alert modes.

Extendy GeoShield supports global trusted countries configured by the administrator. In Smart Mode, the addon can also remember countries for a specific WHMCS User and Client Account context after a valid authenticated trust action.

Alerting model

Extendy GeoShield is notification-only. It evaluates login events and may send alerts depending on the selected alert mode and settings.

In the current product behaviour, alert emails are sent to the primary WHMCS Client Profile email address for the safely resolved Client Account. The WHMCS User email that performed the login is included in the alert content as the login actor.

If no safe Client Account context is available, Extendy GeoShield logs the event but does not send an alert email. It does not guess a Client Account and does not silently notify unrelated contacts or other client accounts.

GeoIP provider concept

Extendy GeoShield uses a configured GeoIP provider to convert a public client IP address into country information. Provider credentials are stored encrypted at rest and are not displayed in plaintext in the admin interface.

If country detection fails, the event is still logged. Whether a client email is sent for a country-detection failure depends on the configured detection-failure alert setting.

Login event logging and retention

The addon stores login event metadata in its own Login Events table and displays it in a read-only WHMCS admin page.

The default retention setting is 180 days. When WHMCS daily cron runs, old Extendy GeoShield login-event records are automatically removed according to the retention setting. Retention cleanup affects login event records only; it does not remove Smart Mode known countries, trust tokens, settings, email templates, or unrelated WHMCS data.

What this product does not do

Extendy GeoShield does not:

  • block logins;
  • deny access by country;
  • replace WHMCS authentication controls;
  • act as a firewall or WAF;
  • validate commercial licences or billing status;
  • send alerts when the Client Account context is ambiguous;
  • silently send alerts to unrelated contacts or additional recipients;
  • automatically trust a country just because a trust link was opened while logged out.

Smart Mode trust links require WHMCS authentication and strict user/client validation before a country can be trusted.