9.1 Release Notes
- Release Highlights
- Version History
- Upgrade Requirements
- New Features
- Updates and Improvements
- Improved Invoice Behavior
- Setup Tasks Widget
- Improved Staff Online Menu
- ionCube Loader Requirement
- BitPay Payment Gateway Configuration Changes
- Plesk XML API Protocol Requirement
- WP Toolkit Password Generation for cPanel Servers
- Expanded Sensitive Directory Check
- Nexus Cart Upgrade Display and Removal
- Admin Remember Me Sessions on Multiple Devices
- Admin API Session Cookie Removal
- URL Validation for Module Settings
- Deprecations
- Removals
- For Developers
Download Now or go to Utilities > Update WHMCS
Release Highlights
WHMCS 9.1 introduces an admin-configurable Invoice Immutability setting with full credit and debit note management, unattended automatic updates, a preview of the new Iris Admin Area theme, automatic MarketConnect account registration, and PHP 8.4 support.
Version History
| Latest Update | Version | Release Type |
|---|---|---|
| 2026-09-30 | 9.1.0 | Beta |
Upgrade Requirements
Before upgrading to this WHMCS version, make certain that your system meets the following requirements:
| Dependency | Minimum Requirement | Recommended |
|---|---|---|
| ionCube® Loader | ionCube Loader 15.0.0 | ionCube Loader 15.0.0 |
| MySQL® | MySQL 5.2 | MySQL 8.0 |
| PHP | PHP 8.2 | PHP 8.4 |
- You must upgrade to ionCube Loader 15.0.0 before you attempt to update to WHMCS 9.1. If you attempt to update to WHMCS 9.1 first, you will experience serious problems.
- You must upgrade to WHMCS 9.1 before you attempt to update to PHP 8.4. If you attempt to update to PHP 8.4 first, you will experience serious problems.
- Updates only appear at Utilities > Update WHMCS if you are running a compatible PHP version.
- For more information and a list of required PHP extensions and other requirements, see System Requirements.
New Features
Credit and Debit Notes and Invoice Immutability Compliance
WHMCS 9.1 adds tools and settings for managing credit and debit notes.
Invoice Immutability Setting
The new Invoice Immutability setting in the Invoices tab at Configuration () > System Settings > General Settings allows you to choose your WHMCS installation’s behavior for invoice immutability and credit and debit notes.
Credit and Debit Notes in the Client Area
View and Download Credit and Debit Notes
You can now can now view and download credit and debit notes in the Client Area. To view a specific credit or debit note, select an invoice from the list in My Invoices and click the note. From there, you can click Download to download the credit or debit note PDF file.
New Custom PDF Invoice Templates
We have introduced two new template files that you can use to customize PDF credit and debit notes:
billingnotepdf.tplviewbillingnote.tpl
Credit and Debit Notes in the Admin Area
We have improved the ability to view, search for, and manage credit and debit notes in WHMCS:
- You can view a list of all of the credit and debit notes across a WHMCS installation at Billing > Credit and Debit Notes.
- You can view a list of the credit and debit notes for a specific client in the Credit and Debit Notes tab in the client profile.
- Users can view a list of all of the client account’s credit and debit notes in the Client Area at Billing > My Credit and Debit Notes.
Admin Role Permissions
We have added the following new admin role permissions for credit and debit notes:
List Credit and Debit Notes— Allow admins to view lists of credit and debit notes.Create Credit or Debit Note— Allow admins to create credit or debit notes for a client.View Credit or Debit Note— Allow admins to view details of a credit or debit note.Manage Credit or Debit Note— Allow admins to publish a credit or debit note, and edit a note while it is in Draft status.Delete Credit or Debit Note— Allow admins to delete a credit or debit note from the system.
Invoice Balance Column
We have added a new, sortable Balance column to invoice lists in both the Client Area and Admin Area. This column displays the remaining balance for each invoice.
You can see this new column in the following interfaces:
- In the Admin Area:
- In the Client Area at Billing > My Invoices.
Unattended Automatic Updates
WHMCS can now apply maintenance releases automatically on a schedule that you set. The system backs up the files it will replace before each update, restores those files if the update fails, and sends an email to your admins after every attempt.
Update History Table
A new Update History table at Utilities > Update WHMCS lists every attempt and its status.
Role Permissions
We have also added a new Unattended Automatic Updates role permission, which allows admins to view the update schedule and the update history.
Stripe Dynamic Payments
Migrate Legacy Stripe Modules
You can now migrate stored payment methods from the Stripe, Stripe ACH, and Stripe SEPA payment gateway modules to Stripe Dynamic Payments without requiring your clients to re-enroll. Use the new Migrate from Legacy Stripe Payment Gateways button at Configuration () > System Settings > Payment Gateways, or run the modules/gateways/stripe_dynamic/bin/migrate.php script for large migrations.
This script requires file access on self-hosted installations. WHMCS Cloud customers should contact support for help with large migrations.
Redirect Payment Methods
Authenticated clients can now use redirect payment methods, such as PayPal®, Amazon Pay, iDEAL, Bancontact, and BLIK, during checkout and invoice payment with the Stripe Dynamic Payments payment gateway module.
Automatic MarketConnect Account Registration
WHMCS MarketConnect is a platform that makes it easy to resell products from leading service providers with almost no additional effort from you.
If your installation isn’t currently linked to a WHMCS Marketplace account, WHMCS now attempts to automatically create one for you when you upgrade to WHMCS 9.1.
Admins with the Full Administrator role see a message in the Admin Area and receive an email describing the outcome of this attempt.
MarketConnect Onboarding for New Installations
On new WHMCS installations, you must connect a WHMCS Marketplace account before you can access the Admin Area for the first time. You can no longer skip or dismiss the Getting Started Wizard’s MarketConnect steps.
PHP 8.4 Support
WHMCS supports PHP 8.4 for installations of WHMCS 9.1 and higher. If you want to move to PHP 8.4, make certain that you update to WHMCS 9.1 before updating PHP.
New Iris Admin Area Template
WHMCS 9.1 introduces a preview of Iris, our newest Admin Area template, featuring a modernized look and improved navigation. Iris is optional in WHMCS 9.1. We plan to make it the default Admin Area template in a future release.
To try Iris, choose Iris for Template in your admin account settings at Account () > My Account.
Password Requirements
We have made the following improvements to password requirements in WHMCS:
Minimum Password Length
WHMCS now enforces a minimum password strength requirement everywhere you or your clients set a password:
- Passwords must contain at least one letter and one number.
- Passwords must meet a minimum length that defaults to 12 characters (the required minimum for PCI DSS 8.3.6 compliance).
You raise the minimum length by configuring the new Minimum Password Length setting in the Security tab at Configuration () > System Settings > General Settings.
Password Reuse Limit
WHMCS now refuses new passwords that match any of an account’s most recently used passwords.
- This restriction applies to both admins and users.
- By default, the system refuses the last four passwords (the required minimum for PCI DSS 8.3.7 compliance).
You can raise this limit by configuring the Password Reuse Limit setting in the Security tab at Configuration () > System Settings > General Settings.
Initial Administrator Password Requirements
The installation process for self-hosted WHMCS installations now enforces its own password requirements for the initial administrator account.
The password that you configure while installing WHMCS must:
- Contain between 12 and 64 characters.
- Be no more than 72 bytes long.
- Contain at least one letter and one number.
Updates and Improvements
Improved Invoice Behavior
We have adjusted several invoicing behaviors:
- Cancelling an invoice with partial payments or applied credit now automatically returns them to the client’s credit balance.
- Removing credit from an invoice that credit had fully paid no longer changes the invoice’s status to Refunded. Instead, the invoice remains in the Paid status and the system recalculates the balance to reflect the uncollected amount.
- Refunding a partial payment no longer changes the invoice’s status.
- The Mark Unpaid action is now available only for invoices in the Payment Pending or Collections statuses.
- Bulk Mark Paid, Mark Unpaid, and Mark Cancelled actions now report invoices that the system was unable to transition to the corresponding statuses.
Setup Tasks Widget
The Admin Dashboard now includes a Setup Tasks widget that displays your progress through WHMCS’s initial setup tasks.
Improved Staff Online Menu
The Staff Online menu in the Admin Area header now lists all enabled staff members and when each admin was last active, including admins who have never signed in.
When you update to WHMCS 9.1, the system will add a lastvisit column to the tbladmins database table and fill it once from your existing Admin Log at Configuration () > System Logs. On installations with a large Admin Log, this step may take longer.
ionCube Loader Requirement
We have updated the required ionCube Loader version for PHP 8.2 and PHP 8.3 to ionCube Loader 15.0.0.
BitPay Payment Gateway Configuration Changes
We updated the BitPay payment gateway module to use BitPay’s current SDK. As a result, the module’s configuration settings have changed:
- Your BitPay configuration now uses a BitPay Point of Sale (POS) token instead of an API key.
- You can now set a separate testnet token when you enable Test Mode.
Plesk XML API Protocol Requirement
The Plesk server module now requires XML API protocol version 1.6.9.1.
Make certain that your Plesk servers run Plesk Onyx 17.8 or later, or Plesk Obsidian 18.0 or later, before upgrading.
WP Toolkit Password Generation for cPanel Servers
WP Toolkit now generates and manages the admin password for WordPress installations on cPanel servers.
Expanded Sensitive Directory Check
The Sensitive Directory Check at Configuration () > System Health now also checks your configured storage locations at Configuration () > System Settings > Storage Settings for public readability.
Nexus Cart Upgrade Display and Removal
Service and addon upgrades now appear directly in the Nexus cart.
Clients can also remove upgrades from the cart. When they do, the Order Summary, cart totals, and cart item count update automatically.
Admin Remember Me Sessions on Multiple Devices
The Remember Me option when you log in to the Admin Area now retains an independent remembered session for up to five devices or browsers.
- Logging out, or signing in without selecting Remember Me, now only ends the remembered session on that device.
- Changing your password or disabling an admin still ends every device’s remembered session for that admin account.
Admin API Session Cookie Removal
WHMCS no longer returns a Set-Cookie response header when you send WHMCS API requests through the legacy includes/api.php entrypoint (or its unversioned /api route variants). If you send a session cookie with a versioned /api/v1/ request, WHMCS will ignore it.
Additionally, when you call the ValidateLogin method remotely, it no longer returns a session cookie. However, the method’s userid and passwordhash response values remain the same, and you can still establish a session from the passwordhash value using the login_auth_tk session key.
URL Validation for Module Settings
We updated the following modules to require a valid http:// or https:// URL for their API and submission URL settings:
Deprecations
Legacy Stripe Payment Gateway Modules
We have deprecated the Stripe, Stripe ACH, and Stripe SEPA payment gateway modules.
Legacy Invoice Mutability Configuration Variables
We have deprecated the allow_adminarea_invoice_mutation and allow_api_invoice_mutation variables in the configuration.php file. The Invoice Immutability setting in the Invoices tab at Configuration () > System Settings > General Settings now controls this behavior.
configuration.php file still sets either variable, remove it. WHMCS flags this as a warning at Configuration () > System Health.Removals
N/A
For Developers
Cart API Checkout
The WHMCS REST API v2 now supports a complete checkout path. An API client can take a cart from creation through payment and provisioning, pay an existing invoice, and list, retrieve, or remove a customer’s stored payment methods.
Currently, the Stripe Dynamic Payments, PayPal Payments, and PayPal Card Payments payment gateway modules include server-side support for redirect-free payments.
- New endpoints let an API caller pay an existing invoice and manage stored payment methods without a browser:
GET /user/invoicesGET /user/invoices/{invoice_id}POST /user/invoices/{invoice_id}/payment-sessionPOST /user/invoices/{invoice_id}/payment-session/confirmPOST /user/invoices/{invoice_id}/payment-linkGET /user/paymethodsGET /user/paymethods/{paymethod_id}DELETE /user/paymethods/{paymethod_id}.
- The
POST /cart/{cart_id}/checkoutendpoint now accepts apaymentobject to complete checkout without a browser redirect. If the request body is empty, checkout behaves as before. - The
GET /store/billing/gatewaysendpoint now returns asupports_headless_payment_sessionfield that lists which configured payment gateways support a redirect-free checkout.
Deprecated AdminLog Scope and Attribute
We have deprecated the AdminLog::scopeOffline() scope and the last_visit_formatted attribute on AdminLog. AdminLog no longer includes last_visit_formatted automatically when converting a record to an array. Request it explicitly if your code relies on it.
Library Updates
We updated the following PHP libraries:
guzzlehttp/promises: 1.5 to 2.0phpseclib/phpseclib: 2.0.39 to 2.0.53
Library Removals
We removed the following PHP libraries:
laminas/laminas-validator: Removedlaminas/laminas-zendframework-bridge: Removedtrue/punycode: Removed
Template Changes
For a list of changed files and a graphical view of the exact changes between WHMCS 9.0.3 and WHMCS 9.1.0, see our GitHub® repositories:
Last modified: 2026 September 30