Sub-50ms webhook ingestion. Zero raw PII storage. HMAC-signed delivery tokens. Audited, documented, and yours to sell under your own brand.
Every component built to SOLID principles, strict typing, and OWASP security standards.
Stripe and LemonSqueezy signatures verified with hash_equals() to prevent timing attacks.
XXXX-XXXX-XXXX-XXXX format using rejection-sampling random_bytes() — no modulo bias.
Time-limited, single-use HMAC tokens. Files are streamed from a web-denied directory.
Buyer emails are HMAC-salted before storage. Without your server secret, hashes can't be reversed.
Duplicate webhook deliveries are caught by a UNIQUE constraint. You'll never issue two licenses for one payment.
Every security event is logged to MySQL with IP, event type, and context. OWASP A09 compliant.
Run install.php, enter your MySQL credentials, and the schema is built in seconds.
Multipart MIME emails with branded HTML and plain-text fallback. Swap mail() for any ESP.
Strict types, single-responsibility classes, dependency injection, and zero global state.
10 findings. 10 resolved. The full report ships with the product.
Each tier includes the full PHP backend. Rights determine what you can do with it.
product_id set to the SKU value in the config.