9.1 Release Notes

This WHMCS version is currently a Beta release and is under Active Development. We recommend this version for testing purposes only.

Download Now or go to Utilities > Update WHMCS

Release Highlights

WHMCS 9.1 introduces an admin-configurable Invoice Immutability setting with full credit and debit note management, unattended automatic updates, a preview of the new Iris Admin Area theme, automatic MarketConnect account registration, and PHP 8.4 support.

Learn about the newest features and most important updates in our 9.1 Release Highlights.

Version History

Latest UpdateVersionRelease Type
2026-09-309.1.0Beta
The anticipated End-of-Life date for this version is 2027-09-30.

Upgrade Requirements

This information only applies to self-hosted WHMCS installations. WHMCS Cloud updates WHMCS for you automatically.

Before upgrading to this WHMCS version, make certain that your system meets the following requirements:

DependencyMinimum RequirementRecommended
ionCube® LoaderionCube Loader 15.0.0ionCube Loader 15.0.0
MySQL®MySQL 5.2MySQL 8.0
PHPPHP 8.2PHP 8.4
  • You must upgrade to ionCube Loader 15.0.0 before you attempt to update to WHMCS 9.1. If you attempt to update to WHMCS 9.1 first, you will experience serious problems.
  • You must upgrade to WHMCS 9.1 before you attempt to update to PHP 8.4. If you attempt to update to PHP 8.4 first, you will experience serious problems.
  • Updates only appear at Utilities > Update WHMCS if you are running a compatible PHP version.
  • For more information and a list of required PHP extensions and other requirements, see System Requirements.

New Features

Credit and Debit Notes and Invoice Immutability Compliance

WHMCS 9.1 adds tools and settings for managing credit and debit notes.

Invoice Immutability Setting

The new Invoice Immutability setting in the Invoices tab at Configuration () > System Settings > General Settings allows you to choose your WHMCS installation’s behavior for invoice immutability and credit and debit notes.

Learn more…

Credit and Debit Notes in the Client Area

View and Download Credit and Debit Notes

You can now can now view and download credit and debit notes in the Client Area. To view a specific credit or debit note, select an invoice from the list in My Invoices and click the note. From there, you can click Download to download the credit or debit note PDF file.

Learn more…

New Custom PDF Invoice Templates

We have introduced two new template files that you can use to customize PDF credit and debit notes:

  • billingnotepdf.tpl
  • viewbillingnote.tpl

Learn more…

Credit and Debit Notes in the Admin Area

We have improved the ability to view, search for, and manage credit and debit notes in WHMCS:

  • You can view a list of all of the credit and debit notes across a WHMCS installation at Billing > Credit and Debit Notes.
  • You can view a list of the credit and debit notes for a specific client in the Credit and Debit Notes tab in the client profile.
  • Users can view a list of all of the client account’s credit and debit notes in the Client Area at Billing > My Credit and Debit Notes.

Learn more…

Admin Role Permissions

We have added the following new admin role permissions for credit and debit notes:

  • List Credit and Debit Notes — Allow admins to view lists of credit and debit notes.
  • Create Credit or Debit Note — Allow admins to create credit or debit notes for a client.
  • View Credit or Debit Note — Allow admins to view details of a credit or debit note.
  • Manage Credit or Debit Note — Allow admins to publish a credit or debit note, and edit a note while it is in Draft status.
  • Delete Credit or Debit Note — Allow admins to delete a credit or debit note from the system.

Invoice Balance Column

We have added a new, sortable Balance column to invoice lists in both the Client Area and Admin Area. This column displays the remaining balance for each invoice.

You can see this new column in the following interfaces:

  • In the Admin Area:
    • In the Invoices tab in the client profile.
    • In the list of invoices at Billing > Invoices.
  • In the Client Area at Billing > My Invoices.

Learn more…

Unattended Automatic Updates

WHMCS can now apply maintenance releases automatically on a schedule that you set. The system backs up the files it will replace before each update, restores those files if the update fails, and sends an email to your admins after every attempt.

Unattended automatic updates apply maintenance releases only. Major and minor version updates continue to require a manual update.

Learn more…

Update History Table

A new Update History table at Utilities > Update WHMCS lists every attempt and its status.

Role Permissions

We have also added a new Unattended Automatic Updates role permission, which allows admins to view the update schedule and the update history.

Stripe Dynamic Payments

Migrate Legacy Stripe Modules

You can now migrate stored payment methods from the Stripe, Stripe ACH, and Stripe SEPA payment gateway modules to Stripe Dynamic Payments without requiring your clients to re-enroll. Use the new Migrate from Legacy Stripe Payment Gateways button at Configuration () > System Settings > Payment Gateways, or run the modules/gateways/stripe_dynamic/bin/migrate.php script for large migrations.

This script requires file access on self-hosted installations. WHMCS Cloud customers should contact support for help with large migrations.

Learn more…

Redirect Payment Methods

Authenticated clients can now use redirect payment methods, such as PayPal®, Amazon Pay, iDEAL, Bancontact, and BLIK, during checkout and invoice payment with the Stripe Dynamic Payments payment gateway module.

Learn more…

Automatic MarketConnect Account Registration

WHMCS MarketConnect is a platform that makes it easy to resell products from leading service providers with almost no additional effort from you.

If your installation isn’t currently linked to a WHMCS Marketplace account, WHMCS now attempts to automatically create one for you when you upgrade to WHMCS 9.1.

Admins with the Full Administrator role see a message in the Admin Area and receive an email describing the outcome of this attempt.

Learn more…

MarketConnect Onboarding for New Installations

On new WHMCS installations, you must connect a WHMCS Marketplace account before you can access the Admin Area for the first time. You can no longer skip or dismiss the Getting Started Wizard’s MarketConnect steps.

Learn more…

PHP 8.4 Support

WHMCS supports PHP 8.4 for installations of WHMCS 9.1 and higher. If you want to move to PHP 8.4, make certain that you update to WHMCS 9.1 before updating PHP.

Support for PHP 8.4 requires ionCube Loader 15.0.0. For more information, see our System Requirements.

Learn more…

New Iris Admin Area Template

WHMCS 9.1 introduces a preview of Iris, our newest Admin Area template, featuring a modernized look and improved navigation. Iris is optional in WHMCS 9.1. We plan to make it the default Admin Area template in a future release.

To try Iris, choose Iris for Template in your admin account settings at Account () > My Account.

Learn more…

Password Requirements

We have made the following improvements to password requirements in WHMCS:

Minimum Password Length

WHMCS now enforces a minimum password strength requirement everywhere you or your clients set a password:

  • Passwords must contain at least one letter and one number.
  • Passwords must meet a minimum length that defaults to 12 characters (the required minimum for PCI DSS 8.3.6 compliance).

You raise the minimum length by configuring the new Minimum Password Length setting in the Security tab at Configuration () > System Settings > General Settings.

Learn more…

Password Reuse Limit

WHMCS now refuses new passwords that match any of an account’s most recently used passwords.

  • This restriction applies to both admins and users.
  • By default, the system refuses the last four passwords (the required minimum for PCI DSS 8.3.7 compliance).

You can raise this limit by configuring the Password Reuse Limit setting in the Security tab at Configuration () > System Settings > General Settings.

Learn more…

Initial Administrator Password Requirements

The installation process for self-hosted WHMCS installations now enforces its own password requirements for the initial administrator account.

The password that you configure while installing WHMCS must:

  • Contain between 12 and 64 characters.
  • Be no more than 72 bytes long.
  • Contain at least one letter and one number.

Learn more…

Updates and Improvements

Improved Invoice Behavior

We have adjusted several invoicing behaviors:

  • Cancelling an invoice with partial payments or applied credit now automatically returns them to the client’s credit balance.
  • Removing credit from an invoice that credit had fully paid no longer changes the invoice’s status to Refunded. Instead, the invoice remains in the Paid status and the system recalculates the balance to reflect the uncollected amount.
  • Refunding a partial payment no longer changes the invoice’s status.
  • The Mark Unpaid action is now available only for invoices in the Payment Pending or Collections statuses.
  • Bulk Mark Paid, Mark Unpaid, and Mark Cancelled actions now report invoices that the system was unable to transition to the corresponding statuses.

Learn more…

Setup Tasks Widget

The Admin Dashboard now includes a Setup Tasks widget that displays your progress through WHMCS’s initial setup tasks.

Learn more…

Improved Staff Online Menu

The Staff Online menu in the Admin Area header now lists all enabled staff members and when each admin was last active, including admins who have never signed in.

When you update to WHMCS 9.1, the system will add a lastvisit column to the tbladmins database table and fill it once from your existing Admin Log at Configuration () > System Logs. On installations with a large Admin Log, this step may take longer.

ionCube Loader Requirement

We have updated the required ionCube Loader version for PHP 8.2 and PHP 8.3 to ionCube Loader 15.0.0.

You must upgrade to ionCube Loader 15.0.0 before you attempt to update to WHMCS 9.1. If you attempt to update to WHMCS 9.1 first, you will experience serious problems.

Learn more…

BitPay Payment Gateway Configuration Changes

We updated the BitPay payment gateway module to use BitPay’s current SDK. As a result, the module’s configuration settings have changed:

  • Your BitPay configuration now uses a BitPay Point of Sale (POS) token instead of an API key.
  • You can now set a separate testnet token when you enable Test Mode.
If you already use BitPay, WHMCS will display an Action Required message until you update your configuration with a POS token.

Learn more…

Plesk XML API Protocol Requirement

The Plesk server module now requires XML API protocol version 1.6.9.1.

Make certain that your Plesk servers run Plesk Onyx 17.8 or later, or Plesk Obsidian 18.0 or later, before upgrading.

If your server runs an earlier Plesk version, upgrade it before upgrading to WHMCS 9.1 or higher.

Learn more…

WP Toolkit Password Generation for cPanel Servers

WP Toolkit now generates and manages the admin password for WordPress installations on cPanel servers.

Learn more…

Expanded Sensitive Directory Check

The Sensitive Directory Check at Configuration () > System Health now also checks your configured storage locations at Configuration () > System Settings > Storage Settings for public readability.

Learn more…

Nexus Cart Upgrade Display and Removal

Service and addon upgrades now appear directly in the Nexus cart.

Clients can also remove upgrades from the cart. When they do, the Order Summary, cart totals, and cart item count update automatically.

Admin Remember Me Sessions on Multiple Devices

The Remember Me option when you log in to the Admin Area now retains an independent remembered session for up to five devices or browsers.

  • Logging out, or signing in without selecting Remember Me, now only ends the remembered session on that device.
  • Changing your password or disabling an admin still ends every device’s remembered session for that admin account.
When you update to WHMCS 9.1, any admin with an existing Remember Me session must log in again.

Learn more…

WHMCS no longer returns a Set-Cookie response header when you send WHMCS API requests through the legacy includes/api.php entrypoint (or its unversioned /api route variants). If you send a session cookie with a versioned /api/v1/ request, WHMCS will ignore it.

Additionally, when you call the ValidateLogin method remotely, it no longer returns a session cookie. However, the method’s userid and passwordhash response values remain the same, and you can still establish a session from the passwordhash value using the login_auth_tk session key.

Learn more…

URL Validation for Module Settings

We updated the following modules to require a valid http:// or https:// URL for their API and submission URL settings:

Deprecations

Legacy Stripe Payment Gateway Modules

We have deprecated the Stripe, Stripe ACH, and Stripe SEPA payment gateway modules.

We strongly recommend using Stripe Dynamic Payments for Stripe payment processing.

Legacy Invoice Mutability Configuration Variables

We have deprecated the allow_adminarea_invoice_mutation and allow_api_invoice_mutation variables in the configuration.php file. The Invoice Immutability setting in the Invoices tab at Configuration () > System Settings > General Settings now controls this behavior.

If your configuration.php file still sets either variable, remove it. WHMCS flags this as a warning at Configuration () > System Health.

Learn more…

Removals

N/A

For Developers

Cart API Checkout

The WHMCS REST API v2 now supports a complete checkout path. An API client can take a cart from creation through payment and provisioning, pay an existing invoice, and list, retrieve, or remove a customer’s stored payment methods.

Currently, the Stripe Dynamic Payments, PayPal Payments, and PayPal Card Payments payment gateway modules include server-side support for redirect-free payments.

  • New endpoints let an API caller pay an existing invoice and manage stored payment methods without a browser:
    • GET /user/invoices
    • GET /user/invoices/{invoice_id}
    • POST /user/invoices/{invoice_id}/payment-session
    • POST /user/invoices/{invoice_id}/payment-session/confirm
    • POST /user/invoices/{invoice_id}/payment-link
    • GET /user/paymethods
    • GET /user/paymethods/{paymethod_id}
    • DELETE /user/paymethods/{paymethod_id}.
  • The POST /cart/{cart_id}/checkout endpoint now accepts a payment object to complete checkout without a browser redirect. If the request body is empty, checkout behaves as before.
  • The GET /store/billing/gateways endpoint now returns a supports_headless_payment_session field that lists which configured payment gateways support a redirect-free checkout.
For full API reference documentation, including request and response schemas, error codes, and rate limits, see our Developer Documentation.

Deprecated AdminLog Scope and Attribute

We have deprecated the AdminLog::scopeOffline() scope and the last_visit_formatted attribute on AdminLog. AdminLog no longer includes last_visit_formatted automatically when converting a record to an array. Request it explicitly if your code relies on it.

Library Updates

We updated the following PHP libraries:

  • guzzlehttp/promises: 1.5 to 2.0
  • phpseclib/phpseclib: 2.0.39 to 2.0.53

Library Removals

We removed the following PHP libraries:

  • laminas/laminas-validator: Removed
  • laminas/laminas-zendframework-bridge: Removed
  • true/punycode: Removed

Template Changes

For a list of changed files and a graphical view of the exact changes between WHMCS 9.0.3 and WHMCS 9.1.0, see our GitHub® repositories:


Last modified: 2026 September 30