🔒 Independently Audited — All Findings Resolved

The Only PHP Licensing Backend
Sold with Full Resale Rights

Sub-50ms webhook ingestion. Zero raw PII storage. HMAC-signed delivery tokens. Audited, documented, and yours to sell under your own brand.

<50ms
Webhook Ingestion
0
Raw PII Stored
10/10
Audit Findings Fixed
PHP 8.x
Pure Stack — No Composer
100%
Shared-Hosting Compatible

Enterprise Architecture. Shared-Hosting Deployable.

Every component built to SOLID principles, strict typing, and OWASP security standards.



🔐

HMAC-Verified Webhooks

Stripe and LemonSqueezy signatures verified with hash_equals() to prevent timing attacks.

🔑

Cryptographic License Keys

XXXX-XXXX-XXXX-XXXX format using rejection-sampling random_bytes() — no modulo bias.

📦

Signed Download Tokens

Time-limited, single-use HMAC tokens. Files are streamed from a web-denied directory.

🛡️

Zero PII at Rest

Buyer emails are HMAC-salted before storage. Without your server secret, hashes can't be reversed.

♻️

Idempotent Processing

Duplicate webhook deliveries are caught by a UNIQUE constraint. You'll never issue two licenses for one payment.

📋

Structured Audit Log

Every security event is logged to MySQL with IP, event type, and context. OWASP A09 compliant.

1-Click Installer

Run install.php, enter your MySQL credentials, and the schema is built in seconds.

📧

HTML Email Delivery

Multipart MIME emails with branded HTML and plain-text fallback. Swap mail() for any ESP.

🏗️

SOLID Architecture

Strict types, single-responsibility classes, dependency injection, and zero global state.

Independently Audited — Not Just Claimed

10 findings. 10 resolved. The full report ships with the product.



10/10
Security Audit — All Findings Resolved
Independent review of webhook, license, and delivery flow
Critical — Fixed
Path traversal in file delivery
High — Fixed
Timing-safe signature comparison
High — Fixed
Raw PII in audit logs
Medium — Fixed
Modulo bias in key generation
Medium — Fixed
Missing idempotency gate
Medium — Fixed
Unbounded file-read in delivery

Choose Your Rights Tier

Each tier includes the full PHP backend. Rights determine what you can do with it.

Tier 1
Foundations Package
Personal Use
$149
one-time
  • Core system guide
  • Citation & source database
  • Raw research notes
Get Foundations Package
Tier 3
Mission Mastermind MRR
MRR — Resell As-Is
$997
one-time
  • Master Resell Rights — sell as-is and keep 100% of profits
  • Signed license key access
  • Full funnel system included
Get Mission Mastermind MRR
Tier 4
Done-For-You Setup
MRR — Resell As-Is
$2,500
one-time
  • Full server and site provisioning
  • SSL + domain routing configuration
  • Stripe/LemonSqueezy webhook setup
  • MRR rights included
Get Done-For-You Setup
Tier 5
Managed Support Retainer
n/a
$508
/month
  • Priority email support
  • Uptime monitoring
  • Monthly security review
Get Managed Support Retainer

Common Questions


What exactly can I do with a PLR license? +
With PLR, you can edit the source files, rebrand them under your own name, and sell the result to end customers. You cannot resell the original unedited files or grant PLR/MRR rights to your own buyers — only the edited/rebranded version.
What does MRR mean and what passes through to my customers? +
MRR (Master Resell Rights) lets you sell the product as-is and keep 100% of the sale price. By default, your customers receive personal-use rights only — they cannot resell it unless you explicitly grant pass-through MRR. Review the MRR license agreement in the templates/ folder for exact terms.
Does this run on Hostinger shared hosting? +
Yes. The entire stack is pure PHP 8.x with MySQL — no Composer, no Node.js, no VPS required. Run install.php through your browser after uploading, and the database tables are created automatically.
Which payment processors are supported? +
Stripe and LemonSqueezy are both supported out of the box. The webhook handler auto-detects which processor sent the event based on the signature header.
Can I add my own products? +
Yes — edit config/products.php to add products, then drop the corresponding files into assets/deliverables/. Create matching products in Stripe with a metadata key of product_id set to the SKU value in the config.