Version 1.4.0 · For WHMCS administrators and Arahoster staff
This guide takes you from download to a working installation, explains every part of the module in plain English, and covers the Human Support Agent in detail. If something here does not match what you see in your WHMCS, contact us (see Support).
New in 1.4.0: the module is now called Arahoster Ultimate Suite for WHMCS (formerly Arahoster AI Ultimate Tools) and adds 15 tools — AI Command Center, Database Manager with bulk client deletion, Payment Gateway Fees, Expense Manager, Monthly Statements, Consolidated Monthly Invoice, WhatsApp Notifications, Staff Clock In / Out, Service Renewal Notices, Hosting Quota Alerts, Verify E-mail Before Activation, Payment Gateways by Country, Hide Old Services and exclusions for Payment Reminders. The dashboard now shows your version with Up to date or Update to vX. Every tool is explained in the feature guide; upgrading is covered in section 9.
Contents
- Overview
- Requirements
- Download & licence
- Installation
- First-time setup
- How it works (every tool) — see the separate Feature Guide article
- Human Support Agent
- Security & privacy notes
- Upgrading
- Troubleshooting
- Uninstalling
- Support
1. Overview
What it is
Arahoster Ultimate Suite for WHMCS is a WHMCS addon module that adds AI-assisted support, marketing, security, billing and maintenance tools to your WHMCS admin area. Everything runs inside your own WHMCS installation: the module stores its data in your WHMCS database (tables starting with arahoster_ai_), uses WHMCS's own APIs and email system, and runs its background work from the normal WHMCS cron.
The AI features use your own API key from one of four providers: DeepSeek (recommended), OpenAI, Anthropic Claude or Google Gemini. You pay the provider directly for what you use; the module shows you the cost.
The 7 categories
The module Dashboard groups the tools into seven categories:
| Category | What it covers |
|---|---|
| Core AI | AI provider and keys, AI Brain (knowledge index and custom prompts), Livechat, AI Usage Logs, Settings, License |
| Support Automation | Ticket replies, Human Support Agent, approvals, canned responses, SLAs, tagging, assignment, translation, summaries, surveys and more |
| Growth & Marketing | CMS & SEO, blog scheduler, email campaigns, newsletters, cart recovery, win-back, referrals, affiliates, reviews, landing pages, A/B tests, SMS, social posting |
| Security & Fraud | Login protection, IP rules, brute-force bans, CAPTCHA, 2FA, fraud scoring, VPN/geo checks, account-takeover detection, domain abuse monitoring |
| Optimization | Churn risk, server health, storage and database maintenance, cron monitor, upsell/plan recommendations, revenue analytics, AI cost optimisation |
| Billing & Finance | Invoice branding, payment reminders, dunning, late fees, refunds, FX rates, tax/VAT, reconciliation, financial reports and forecasts |
| Operations & Admin | Setup Wizard, Cost & Budget, Health Check, Updates, Audit Trail, Role Access, Webhooks, Backup & Restore, Risk Disclaimer |
Safety-first defaults
The module is built so that installing it changes nothing for your customers until you decide otherwise:
- Automations that email customers, touch money or delete data ship switched OFF. Examples: payment reminders, late fees, smart dunning, cart recovery, win-back, newsletters, CSAT surveys, auto-pruning, log cleanup, Auto Ticket Reply and the Human Support Agent.
- When you switch an automation on, it only acts on new data — tickets, invoices, orders or events that happen after the moment you enabled it. Switching on payment reminders, for example, does not email every customer with an old overdue invoice.
- Auto Ticket Reply requires human approval by default, and the Human Support Agent starts in Off mode.
- Each automatic action is recorded once (so overlapping cron runs never repeat an email or a money action) and is written to the module's Audit Trail.
- Security protections such as Brute-Force Protection, Disposable Email Filter, Geo-Anomaly, Account Takeover Detection, Chargeback Predictor and Domain Abuse monitoring default to disabled; blacklist enforcement is a separate opt-in.
2. Requirements
| Component | Requirement |
|---|---|
| WHMCS | 8.9 or later (tested on WHMCS 9.0) |
| PHP | 8.1 or later, with the cURL, OpenSSL, mbstring and json extensions |
| ionCube Loader | v14 or later — WHMCS itself runs on ionCube, so it is normally already installed |
| Database | MySQL 5.7+ or MariaDB 10.3+ |
| WHMCS cron | Running every 5 minutes (the standard WHMCS setup) |
| AI provider | At least one API key: DeepSeek (recommended), OpenAI, Anthropic Claude or Google Gemini |
One package for every supported PHP version. The same download runs on PHP 8.1, 8.2, 8.3 and newer.
Outbound connections. Your server must be able to make HTTPS (port 443) requests to:
- your AI provider:
api.deepseek.com,api.openai.com,api.anthropic.comorgenerativelanguage.googleapis.com; - the Arahoster licence server
me.arahoster.com(licence checks and the daily update check); - any optional third-party service you configure (for example CAPTCHA, Twilio, Google Safe Browsing, MaxMind, Telegram/WhatsApp).
The Human Support Agent (optional) also connects to your cPanel/WHM servers on port 2087, to your customers' websites on ports 80/443, and performs public DNS lookups.
3. Download & licence
Order a plan
Order the plan you want — Free, Pro or Enterprise — at:
https://me.arahoster.com/store/arahoster-ultimate-suite-for-whmcs
| Plan | Price |
|---|---|
| Free | $0 |
| Pro | $9.99 / month |
| Enterprise | $19.99 / month |
Download the files
After ordering, log in to the Arahoster client area at https://me.arahoster.com. You can download the module from either:
- Downloads → Arahoster Marketplace → Arahoster Ultimate Suite for WHMCS (login required), or
- the download button on your licence (your service in the client area).
There is one package for every supported PHP version.
Your licence key
Your licence key is shown with your service in the client area. You enter it inside the module under License (see First-time setup). Without a validated key the module runs on the Free plan.
What each plan unlocks
The module checks your plan with the licence server and unlocks tools accordingly. Locked tools stay visible in the sidebar and on the Dashboard with a lock icon and the plan they need.
Free includes:
- Core AI: AI Brain (knowledge index, custom prompts, AI test console), Livechat with the client-area chat widget, AI Usage Logs, Settings, License.
- Support Automation: Canned Responses, Ticket Tagging Engine, First Response Tracker, Resolution Time Tracker, KB Suggestion.
- Growth & Marketing: CMS & SEO, Promo Codes, Reviews & Testimonials.
- Security & Fraud: Login Guard, IP Allow / Block List, Brute-Force Protection, Disposable Email Filter, CAPTCHA Integration.
- Optimization: Churn Risk Dashboard, Server Health Score, Storage Audit, Session Cleanup, WHMCS Cron Monitor.
- Billing & Finance: Invoice PDF Customizer, Payment Reminders, Recurring Invoice Monitor, Currency Display.
- Operations & Admin (every plan): Setup Wizard, Cost & Budget, Health Check, Updates, Audit Trail, Role Access, Webhooks, Backup & Restore, Risk Disclaimer, plus the Dashboard and the AI First-Run Audit.
Pro adds everything in Free plus:
- Support Automation: Training Data, AI Content Tools, Auto Ticket Reply, Human Support Agent, Approval Queue, Department Config, SLA Management, Auto-Assignment, AI Translation, AI Thread Summariser, KB Auto-Generator, Workload Balancer, Ticket Merge Suggestions.
- Growth & Marketing: AI Blog Scheduler, SEO Auditor, Keyword Research, Marketing Suite (email campaigns), Newsletter Builder, Cart Recovery, Social Auto-Post.
- Security & Fraud: 2FA Challenge, Geo-Anomaly Detection, VPN / Proxy Detection, Velocity Checks, Suspicious Activity Log, Staff Activity Log, Session Manager.
- Optimization: Disk Upsell Predictor, Suspended Revenue Recovery, DB Table Optimizer, Log Cleanup Automation, Orphan Record Cleanup, Slow Query Analyzer, Cache Monitor, Backup Verifier.
- Billing & Finance: FX Rate Sync, Tax Rules Manager, VAT Number Validator, Late Fee Manager, Partial Payments, Smart Dunning, Refund Manager, Aged Receivables Report, Gateway Health Monitor, Volume Discounts.
Enterprise adds everything in Pro plus:
- Support Automation: Ticket Intelligence, AI Quality Score, Escalation Detector, Solution Recommender, AI Chatbot Pre-Ticket, CSAT / NPS Surveys, PII Redaction, Multi-Channel Inbox, Voice-to-Text, AI Agent Coach.
- Growth & Marketing: Drip Sequences, Win-Back Campaigns, Affiliate Manager, Referral Program, Landing Page Builder, A/B Testing Studio, SMS Marketing.
- Security & Fraud: Security & Fraud rules page (event log, login history, country restriction, content protection, fraud config), Order Fraud Score, Chargeback Predictor, AI Phishing Detector, Account Takeover Detection, External Reputation, Security Webhooks, Domain Abuse Monitoring.
- Optimization: Auto-Pruning Execution, Performance Tuning, Index Recommender, Lifetime Value Calculator, Pricing Optimizer, Product Mix Analyzer, Renewal Forecaster, MRR / ARR Dashboard, Token Usage Optimizer, Model Selection Advisor, Hosting Plan Recommender, CDN Recommendation Engine.
- Billing & Finance: Gateway Fee Analyzer, Crypto Payments overview, Gateway Rotation, Bank Reconciliation, AI Financial Analyst, Cash Flow Forecast, P&L Statement, Chargeback Dispute Helper, Financial Anomaly Detection, Tax Audit Export, AI Quote Generator.
If the licence server cannot be reached, the last successful check is honoured for a 7-day grace period. After that the module falls back to the Free plan until the server can be reached again. Your data and settings are never deleted when a plan changes.
4. Installation
Take a full backup of your WHMCS files and database before you start. We also recommend installing on a staging copy first.
Step 1 — Check PHP and the ionCube Loader
The module needs PHP 8.1 or later with the cURL, OpenSSL, mbstring and json extensions, and the ionCube Loader v14 or later — the same PHP and loader WHMCS itself runs on, so both are normally already in place. Check them under Utilities → System → PHP Info in your WHMCS admin area (search the page for ionCube). If the loader is missing or older than v14, ask your host to enable it for the PHP version WHMCS uses (on cPanel/WHM: EasyApache 4 → PHP Extensions → ioncube).
Step 2 — Upload the files
- Unzip the archive on your computer. It contains a
modules/addons/arahoster_ai_ultimate_tools/folder. - Upload it into your WHMCS root directory so the folders merge. The result must be:
/path/to/whmcs/modules/addons/arahoster_ai_ultimate_tools/arahoster_ai_ultimate_tools.php
The folder also contains hooks.php, hooks/, lib/, assets/ and templates/, plus INSTALL.md and DOCUMENTATION.md.
Step 3 — Set permissions
Use the same owner as the rest of your WHMCS files, with directories at 755 and files at 644:
cd /path/to/whmcs/modules/addons/arahoster_ai_ultimate_tools/
chown -R USER:GROUP .
find . -type d -exec chmod 755 {} \;
find . -type f -exec chmod 644 {} \;
Replace USER:GROUP with the account WHMCS runs as (for example your cPanel user, www-data, apache or nginx).
Step 4 — Activate the module
- Log in to the WHMCS admin area as a Full Administrator.
- Go to System Settings → Addon Modules.
- Find Arahoster Ultimate Suite for WHMCS and click Activate.
Activation creates the module's database tables (all prefixed arahoster_ai_), adds default settings and runs a first licence check. You should see "Arahoster Ultimate Suite for WHMCS activated successfully. Configure your AI provider in Settings."
Step 5 — Give admin roles access
- Still on System Settings → Addon Modules, click Configure next to the module.
- Under Access Control, tick the admin roles that should be able to open the module (at least Full Administrator).
- Optionally enter your AI provider and API key here as well (you can also do it later on the module's own Settings page).
- Click Save Changes.
The module now appears under Addons → Arahoster Ultimate Suite for WHMCS. Only roles ticked here can open it or see the AI panel on ticket pages. Inside the module you can restrict sections further with Role Access (see First-time setup).
Step 6 — First run: accept the disclaimer
The first time you open the module you are taken to the Risk Disclaimer. Until it is accepted, only the disclaimer and the License page can be used. Read it, tick the confirmation box and click I Understand & Accept. The acceptance is recorded with your admin name, time and IP address.
Step 7 — Run the Setup Wizard
Open Setup Wizard in the sidebar. It walks you through:
- Pick an AI provider — opens Settings.
- Test your API key — opens Health Check.
- Activate license — opens License.
- Map departments — opens Department Config (Pro and Enterprise only; the step is not shown on the Free plan).
- Set monthly budget — opens Cost & Budget.
- You're ready — click Finish Setup.
You can hide the wizard at any time with Hide this wizard. The next section explains each step in more detail.
5. First-time setup
AI provider and API keys
Go to Addons → Arahoster Ultimate Suite for WHMCS → Settings.
- Under AI Provider Configuration, choose the Active AI Provider: DeepSeek (Recommended), OpenAI, Anthropic Claude or Google Gemini.
- Paste the API key for that provider and choose a model. Defaults:
| Provider | Where to get a key | Default model | Other models |
|---|---|---|---|
| DeepSeek | https://platform.deepseek.com |
deepseek-chat (DeepSeek-V3) |
deepseek-reasoner, deepseek-coder |
| OpenAI | https://platform.openai.com |
gpt-4o |
gpt-4o-mini, gpt-4-turbo, gpt-3.5-turbo |
| Anthropic Claude | https://console.anthropic.com |
claude-sonnet-4-6 |
claude-opus-4-7, claude-haiku-4-5-20251001 |
| Google Gemini | https://aistudio.google.com |
gemini-1.5-pro |
gemini-1.5-flash, gemini-2.0-flash |
- Other settings on this page: Max Response Tokens (default 2048), System Prompt (use
{company_name}as a placeholder), Monthly Token Limit (default 1,000,000; 0 = unlimited), the chat widget's title, welcome message, position and colour, AI Brain/RAG options, SEO auto-submission (Google Indexing service-account JSON path, Bing Webmaster API key) and the marketing Daily Email Send Limit (default 500; 0 = unlimited). - Click Save All Settings.
Saved keys are never shown again on the page — the field says "saved — leave blank to keep". Leave it blank to keep the stored key.
Master switches in the WHMCS Configure dialog. Three feature switches live only in System Settings → Addon Modules → Arahoster Ultimate Suite for WHMCS → Configure: Enable AI Livechat, Enable Ticket AI and Enable Security & Fraud Protection. They are off on a new install. After changing them, open the module once so it picks up the new values. What they control:
- Enable AI Livechat — shows the chat widget in the client area and enables the public chat endpoint.
- Enable Ticket AI — background AI reply suggestions on new tickets and replies; required by Auto Ticket Reply.
- Enable Security & Fraud Protection — required by the client-area security checks (login protections, fraud scoring at checkout and related hooks).
The SEO and marketing tools have no master switch: each automation is switched on on its own page.
Health Check
Open Health Check and click Re-run checks. It tests:
- module files (unchanged since release), PHP version and cURL / outbound HTTPS;
- the database schema (core tables present);
- each AI provider that has a key — "Invalid API key (HTTP 401/403)" means the key is wrong, "No API key configured" means none is saved;
- the licence server (reachable, or "No license key set — Free tier only");
- the WHMCS cron (when it last ran);
- whether the module folder is writable (informational only — a read-only folder is fine, because the module never writes there and never updates itself).
You can also test the AI directly in AI Brain → AI Test Console.
Cron
The module uses the normal WHMCS cron — no extra cron job is needed. WHMCS should already run:
*/5 * * * * php -q /path/to/whmcs/crons/cron.php
Background work (scheduled replies, Human Support Agent drafting and posting, reminders, scans, reports) runs on these cron ticks. Health Check warns if the cron has not run for more than an hour, and the WHMCS Cron Monitor (Optimization) shows every WHMCS task in detail.
Licence key
Open License, paste your key into License Key and click Save & Verify. The status shows your plan (Free, Pro or Enterprise) and when it was last checked. The licence is re-checked automatically every 24 hours; click Refresh Now to check immediately — for example right after upgrading your plan.
Role Access
By default every admin role that has access to the addon in WHMCS can open every section. To restrict sections per role:
- Open Role Access (only Full Administrators can change it).
- Switch role-based access on.
- For each admin role, tick the sections it may open, or tick "all".
- Save.
Full Administrators always have full access, so you cannot lock yourself out. Hidden sections disappear from the sidebar and Dashboard, and their actions are refused on the server as well.
Cost & Budget (and the hard cap)
Open Cost & Budget to see this month's AI spend, a provider breakdown and a 30-day chart. Under Budget Settings:
- Monthly Budget (USD) — default 0 = no limit.
- Alert Email — budget alert emails are sent at 80%, 100% and 110% of the monthly budget (once each per month). WHMCS admins who receive system notifications always get them; this address gets an extra copy.
- Enable hard cap — off by default. When on and the budget is reached, new AI requests are blocked until the next month: the chat widget hides itself, AI tools return an error, and the Human Support Agent hands tickets to staff instead of replying.
The Monthly Token Limit in Settings is a second, token-based limit and is enforced for every AI call as well.
6. How it works
A tool-by-tool guide to all seven categories (AI Core, Support Automation, Growth & Marketing, Security & Fraud, Optimization, Billing & Finance, Operations & Admin) is in the companion article Arahoster Ultimate Suite for WHMCS — Feature Guide (How Every Tool Works): open the Feature Guide.
7. Human Support Agent
Plan: Pro or Enterprise · Where: sidebar → Human Support Agent · Default: Off
What it does
The Human Support Agent answers customer tickets the way an experienced member of your support team would. For every new customer message it:
- waits a natural, random delay (default 15–45 minutes);
- reads the whole ticket thread, the client's services, domains, unpaid and overdue invoices, their last 5 tickets, the ticket's private notes and relevant content from your AI Brain knowledgebase;
- looks inside the customer's cPanel account, read-only (see below);
- analyses the request, writes one careful reply in the customer's own language, then reviews its own draft;
- posts the reply as the admin you choose — or, if anything is risky or uncertain, hands the ticket to your staff with a private note instead of replying.
It handles tickets from clients and guests. It never touches tickets or messages from before you switched it on.
The three modes
Set the mode on the Settings tab, panel Mode:
| Mode | What happens |
|---|---|
| Off (default) | The agent does nothing. |
| Review | The agent prepares the reply with its analysis and account findings and puts it in the Approval Queue. It is posted at its scheduled time only after a staff member approves it. |
| Automatic | The agent posts the reply itself at the scheduled time. Risky or uncertain tickets are still handed to staff and never answered. |
Switching from Off to Review or Automatic records the time; only customer messages after that time are handled.
While the agent is on, it owns the tickets of the departments it handles: Auto Ticket Reply and the background AI reply suggestions stand down for those departments, so customers never get two answers. Departments outside its list behave as before, and switching the agent off restores the old behaviour everywhere.
Settings and defaults
Who replies
| Setting | Default | Notes |
|---|---|---|
| Reply as admin | Automatic | Automatic = an active admin named "Support Team", otherwise the first Full Administrator. |
| Sign-off line | Support Team |
Added under the reply — unless the selected admin has a signature in their WHMCS profile, in which case WHMCS adds that one and the sign-off is skipped. |
| Ticket status after the reply | Answered | Also: Open, In Progress, On Hold, Customer-Reply. |
| Add a short private note after each reply | On | "Handled by Human Support Agent — analysis #…". |
Timing
| Setting | Default | Notes |
|---|---|---|
| Reply after at least (min) | 15 | A random delay in this range is picked for every customer message. |
| and at most (min) | 45 | |
| Only reply during business hours | Off | Off = around the clock. |
| From / To (HH:MM) | 08:00 / 22:00 | Server time; shown on the page. |
| Days (1=Mon…7=Sun) | 1,2,3,4,5,6,7 |
Which tickets
| Setting | Default | Notes |
|---|---|---|
| Departments | None ticked = all | |
| Skip tickets assigned (flagged) to another admin | On | |
| Stay out of a ticket once a staff member has replied or it was handed to staff | On | |
| VIP client groups | None | Tickets from these client groups are always handed to staff. |
Safety
| Setting | Default | Notes |
|---|---|---|
| Minimum confidence to reply | 75 | Below this, the ticket is handed to staff. |
| Hand off when anger ≥ | 70 | |
| Max agent replies per ticket per day | 4 | |
| Hand off after N replies without progress | 3 | Replies in a row without the customer confirming progress. |
| Inspect the customer's cPanel account before replying (read-only) | On | Account diagnostics. |
| Verify the WHM server's TLS certificate | On | Turn off only for a self-signed WHM certificate on a trusted network. |
Hand-off to staff
| Setting | Default | Notes |
|---|---|---|
| Notify | E-mail the support admins of the ticket's department | Or "No e-mail (note + webhook only)". |
| Assign (flag) handed-off tickets to | Nobody | Optionally flag the ticket to a chosen admin. |
House rules & persona notes — a text box with what the agent must know about your company and must never do. {company_name} and {client_area_url} are filled in automatically. When the box is empty, built-in default house rules are used. The built-in defaults use your WHMCS company name and describe a typical cPanel hosting support policy (no phone support, staff handle refunds, cancellations and account changes). Review them before you switch the agent on and paste your own rules if anything differs: your services, what support you offer, your client area menu paths, and what staff must always handle. The core persona can be replaced entirely with a custom prompt for feature human_agent under AI Brain → Custom AI Prompts.
Click Save settings at the bottom of the tab.
What it checks on the cPanel account (read-only)
When account diagnostics is on and the client has a cPanel hosting service on a WHM server configured in WHMCS (with a WHM API token or password stored in the server settings), the agent checks the relevant service — the domain mentioned in the ticket, otherwise the client's active cPanel services, at most 2:
- account summary and bandwidth (WHM);
- domains, disk quota, installed SSL certificates, mailbox names and counts, database names (cPanel API, as the user);
- the last 60 lines of
error_log/*.logfiles inpublic_html(max 1 MB per file); - DNS (A/AAAA/NS/MX compared with the server IP, Cloudflare-aware), HTTPS status, the served TLS certificate and the http→https redirect.
It is strictly read-only: only a fixed whitelist of read calls is allowed, it never reads configuration files and never changes anything. WHM is always contacted over TLS on port 2087 with short timeouts (5–8 seconds per call, 25 seconds in total). A check that fails is recorded as "unavailable" and the agent will not claim it checked it. Results are cached for 10 minutes.
If no cPanel/WHM server with credentials is found, the page shows a notice and replies still use WHMCS data and public DNS/SSL checks.
When it hands over to staff
The agent never replies — it adds a private note with its analysis, findings and a suggested (unsent) draft, notifies staff as configured, optionally flags the ticket, and fires the Ticket Escalation webhook — when:
- the ticket is about refunds, chargebacks or payment disputes; cancellations; abuse, DMCA or legal matters; account ownership, access or contact changes;
- the customer asks staff to change passwords, DNS, files or settings, restore backups, unsuspend, migrate or perform any action on the server;
- there is a hacked site, malware or another security incident; or a discount or price negotiation;
- the customer asks for a human, or asks whether they are talking to a bot or AI;
- the client is in a VIP group;
- anger is at or above the threshold, confidence is below the minimum, the analysis says a person is needed, or the self-review fails;
- the daily cap or the "replies without progress" limit is reached;
- the monthly AI budget hard cap (or token limit) is reached.
It also skips (without replying) tickets opened by staff, closed or merged tickets, departments it does not handle, tickets flagged to another admin, tickets where staff replied after the customer, tickets a human already handles, and messages it classifies as spam. If the customer writes again before the reply is posted, the pending draft is discarded and one new reply is scheduled from the latest message. If a staff member replies or the ticket closes, any pending draft is withdrawn.
Test it safely: the dry run
The Test on a ticket tab runs the full pipeline on any ticket without posting or writing anything to the ticket (AI usage is counted).
- Enter a ticket number (public number like
ABC-123456, or the internal ID). - Optionally tick Simulate: treat the latest customer message as unanswered — this ignores staff replies after the customer's latest message, so you can test on tickets that were already answered or closed.
- Click Dry run.
You see the outcome (draft, hand-off, skip or error) with the reason and confidence, the draft, the analysis, the self-review, every account check with its data, the gathered context, an audit of each AI call (bytes, SHA-256, tokens), and the exact redacted context that was sent to the AI.
The Queue and Activity tabs
- Queue lists scheduled and recent replies: ticket, client, when the reply is due, status and confidence. View shows the analysis, account findings, draft, self-review and AI-call audit. Post now prepares and posts immediately (in Review mode it still requires approval). The × button cancels a scheduled reply.
- Activity is the agent's recent log (scheduled, drafted, posted, handed off, and so on).
Drafts are prepared up to 10 minutes before the reply is due and posted by the WHMCS cron at or after the due time. Posting goes through WHMCS's own ticket-reply function, so the customer gets the normal WHMCS email, and a reply is only marked as posted after WHMCS accepted it. Overlapping cron runs can never post the same reply twice.
Recommended rollout
- Prepare. Make sure an AI key works (Health Check), the WHMCS cron runs every 5 minutes, and your house rules describe your company. Optionally create an admin named "Support Team" to reply as.
- Dry run. Use Test on a ticket with Simulate on 10–20 real past tickets of different kinds. Check the drafts, the hand-off decisions and the account findings. Adjust house rules and thresholds.
- Review mode for a few days. Switch to Review. Every reply waits in the Approval Queue; approve the good ones and reject the rest. Watch the hand-off rate and confidence values in the Queue.
- Automatic. When you are happy with the quality, switch to Automatic. Start with one or two departments if you prefer, and keep checking the Queue and Activity tabs.
Cost per ticket
Each reply normally takes three AI calls — analysis, draft and self-review — and up to five when a retry is needed. Tickets stopped by the built-in pre-checks (for example a refund request or a VIP client) cost nothing. As a rough guide, a typical ticket uses about 10,000–25,000 tokens in total. Using the prices built into the module, that is approximately:
| Model | Approx. cost per answered ticket |
|---|---|
DeepSeek deepseek-chat |
under $0.01 |
OpenAI gpt-4o |
$0.04 – $0.08 |
Anthropic claude-sonnet-4-6 |
$0.05 – $0.10 |
These are estimates; long threads cost more. The exact tokens for each reply are shown under View → AI calls in the Queue, and all usage is logged under feature human_agent in AI Usage Logs and counted in Cost & Budget.
Honesty
The agent writes as a member of your support team and signs with the team sign-off. It is instructed never to claim to be a human, never to invent personal details about itself, never to say it did something it did not do, and never to promise refunds, timelines or outcomes. If a customer asks whether they are talking to a bot or AI, or asks for a human, the ticket is handed to your staff.
Note that WHMCS shows the selected admin as the author of the reply. If you want replies to appear from the team rather than a named person, reply as an admin named "Support Team" (the automatic default) and give that admin no personal signature.
8. Security & privacy notes
- Your data stays on your server. All module data (settings, logs, queues, analyses) is stored in your own WHMCS database. Nothing is sent to Arahoster except the licence check (your licence key, your WHMCS system URL, the module name and version) and the daily update check (your system URL and module version).
- What is sent to the AI provider. Only the text a feature needs is sent to the provider you selected: for example the chat message and matching knowledgebase content for livechat, the ticket thread (and, for Auto Ticket Reply, the client context options you tick) for ticket replies, and the redacted context for the Human Support Agent. API keys are your own; the provider's own data policy applies.
- Redaction. The Human Support Agent always redacts before anything reaches the AI: passwords, tokens and API keys, card/IBAN/SSN patterns, email addresses that are not the customer's, credentials in URLs and absolute home-directory paths. Each AI call is audit-logged with the SHA-256 hash and size of what was sent. For tickets in general, PII Redaction (Enterprise) can remove card numbers, IBANs, SSNs and similar data from new tickets automatically, before AI drafting.
- API keys. Keys are stored in the module's settings table in your WHMCS database and are never printed back on the Settings page. Protect your database backups accordingly. Backup & Restore exports exclude secrets unless you tick Include secrets.
- CSRF protection. Every admin form and AJAX action in the module carries a per-session security token and is rejected without it.
- Roles. Only admin roles with access to the addon in WHMCS can open it or see the ticket AI panel. Role Access can restrict sections further; restrictions are enforced on the server, not just hidden in the menu. Full Administrators always have full access.
- Public endpoints (chat, unsubscribe, survey, referral and review pages) are rate-limited and/or signed, and survey and unsubscribe links never record anything on a simple page load.
- Disclaimer and audit. The module requires accepting the Risk Disclaimer, and every settings change and automatic action is written to the Audit Trail.
9. Upgrading
- Back up your WHMCS database and files.
- Download the new version from the Arahoster client area.
- Upload the files over the old ones, so
modules/addons/arahoster_ai_ultimate_tools/is replaced with the new contents. - Open Addons → Arahoster Ultimate Suite for WHMCS once. WHMCS detects the new version and runs the module's upgrade: new tables and columns are created automatically and missing default settings are added. Your existing settings are kept.
- Hard-refresh your browser (Ctrl+F5 / Cmd+Shift+R) and run Health Check.
Upgrading to 1.4.0
- The new name, Arahoster Ultimate Suite for WHMCS, appears everywhere. The folder
modules/addons/arahoster_ai_ultimate_tools/, your licence key and all settings stay the same — upload over the old files as usual. - All new tools are installed switched off: nothing e-mails clients, charges money or changes data until you turn it on.
- If you used the separate Arahoster Gateway Fee Manager, open Payment Gateway Fees, click Import these rules, deactivate the old addon, then switch fees on. Never run both, or clients pay the fee twice.
- Release files carry an integrity check. If a shipped PHP file is changed, the module runs on the Free tools only and the License page lists the changed files; upload the full package again to fix it.
- The dashboard header shows your version with Up to date or Update to vX; Module Updates checks for new releases once a day.
Upgrading to 1.4.0 renames the module to Arahoster Ultimate Suite for WHMCS and adds 15 tools, all switched off — see Upgrading to 1.4.0 below.
Upgrading to 1.3.0 adds the Human Support Agent (its queue table is created automatically; the agent stays Off) and fixes the "Security token mismatch" error on admin forms.
10. Troubleshooting
The License page says module files were changed, and only the Free tools work One or more of the module's PHP files differ from the release (for example after an incomplete upload or a manual edit). Upload the complete package from the client area again, over the old files, then press Refresh Now on the License page. The templates in lib/Admin/views/ are not checked, so restyling them is fine.
A blank module page after upgrading Usually an incomplete upload. Upload the whole modules/addons/arahoster_ai_ultimate_tools/ folder again and open the addon once.
"Security token mismatch" on every form This happened on version 1.2.0 and earlier in live WHMCS installations. Upgrade to the latest version. If it still appears once, reload the page — your admin session may have expired.
Health Check shows "Invalid API key (HTTP 401/403)" The key for that provider is wrong, revoked or has no credit. Create a new key at the provider, paste it in Settings, save and re-run Health Check. "No API key configured" means no key is saved for that provider.
A section shows a lock or "not included in your current plan" Open License and click Refresh Now — this is needed right after you upgrade your plan. Check that the status shows your plan. If the licence server cannot be reached, check outbound HTTPS to me.arahoster.com.
"Your administrator role does not have access to this section" A Full Administrator can grant it in Role Access. If the module does not appear at all, tick your role under System Settings → Addon Modules → Configure → Access Control.
Cron not running / scheduled actions never happen Health Check shows when the cron last ran. Make sure the WHMCS cron runs every 5 minutes (*/5 * * * * php -q /path/to/whmcs/crons/cron.php) and check WHMCS Cron Monitor and WHMCS's own automation status for failures.
Emails are not sent The module sends through WHMCS's own email system, so first check WHMCS mail settings and System Logs → Email Message Log. Then check that the automation's switch is on, that the record is newer than the moment you switched it on, that the client opted in to marketing email (for marketing tools), and that the Daily Email Send Limit in Settings (default 500) is not reached. Campaigns, newsletters and growth emails are sent in batches by the cron.
Human Support Agent is not replying — checklist
- Mode is Review or Automatic (the badge next to the title shows OFF / REVIEW / AUTO).
- Your plan is Pro or Enterprise and the licence is valid (License → Refresh Now).
- An AI key is set for the active provider (the page warns if not) and Health Check shows it as OK.
- The WHMCS cron runs every 5 minutes.
- The message arrived after you switched the agent on; older messages are never handled.
- The ticket's department is in the agent's list (or the list is empty).
- The ticket was not opened by staff, is not closed or merged, and is not flagged to another admin.
- No staff member has replied, and the ticket was not handed off earlier ("stay out" setting).
- The delay has not yet passed, or it is outside business hours — check "Reply due" in the Queue.
- In Review mode the reply waits in the Approval Queue until approved.
- Look at the Queue status and reason (handed off, skipped, failed) and the Activity tab — they say exactly why.
- The monthly budget hard cap or token limit has not been reached (Cost & Budget).
- Run Test on a ticket with Simulate to see the full decision for that ticket.
Where to find logs Module events: Audit Trail and AI Usage Logs. Hook errors are written to the WHMCS Activity Log (System Logs). Livechat and Human Support Agent activity has its own views in their sections.
11. Uninstalling
- Export anything you want to keep: Backup & Restore (settings, training data, prompts, departments, canned responses, webhooks) and any reports or CSV exports you need.
- If you added the invoice footer include to your theme's
invoicepdffooter.tpl, or a menu link to the Account Security page, remove them. - Go to System Settings → Addon Modules and click Deactivate next to Arahoster Ultimate Suite for WHMCS.
- Delete the folder
modules/addons/arahoster_ai_ultimate_tools/.
What is kept: deactivating does not delete any data. All module tables (prefixed arahoster_ai_) and their contents stay in your database, so reactivating later restores your setup — and reactivation never resets your existing settings. Content the module created inside WHMCS itself — announcements, knowledgebase articles, promotions, ticket replies and notes, quotes, account credits, tax rules — is normal WHMCS data and also stays.
What is removed: once deactivated, WHMCS no longer loads the module, so its hooks, cron tasks, client-area widget and pages stop working.
To remove all module data permanently (cannot be undone — back up first), list the tables with:
SHOW TABLES LIKE 'arahoster\_ai\_%';
and drop them in your database tool.
12. Support
- Email: support@arahoster.com
- Ticket: open a support ticket in the Arahoster client area at
https://me.arahoster.com
When you contact us, please include:
- your WHMCS version and PHP version (Health Check shows them);
- the module version (shown at the top of the dashboard, e.g. v1.4.0) and your plan;
- the exact error message or a screenshot;
- what you did just before the problem appeared.