ROTLD Manager for WHMCS
End-to-end automation for the Romanian .ro registry inside WHMCS. Reserves the domain at order time, activates it on payment, manages DNSSEC, nameserver glue records, EPP codes and the registrant correction window, plus a full audit trail, saved registrants database and admin operations console.
Generic registrar modules don’t fit .ro
ROTLD, the Romanian National Top-Level Domain registry, has its own rules: registrant types instead of contacts, mandatory CNP / fiscal code, a strict post-registration correction window, an auth-code that can’t be retrieved through the API, and a two-stage reserve/activate flow if you want to keep your balance untouched until the customer pays. ROTLD Manager builds those rules into WHMCS so your team never has to remember them.
Reserve, then activate
The cart triggers a domain-reserve API call at order time so the name is locked under your customer’s details. The registrar balance is debited only when the invoice is paid and the reservation is activated. If payment fails, the reservation lapses without cost.
Registrant types, not contacts
Forms collect person type (private, authorised, commercial, non-commercial, government, public institution, other) with the right fields for each: CNP for individuals, J-number for companies, fiscal code where applicable. Cart-side validation rejects incomplete entries before the API call.
Correction window aware
The 24-hour customer correction window and the 72-hour support window are first-class concepts. Protected fields (name, type, CNP, registration number) become editable inside the window with a live countdown; once closed, the panel shows them read-only and directs the customer to support.
EPP routing built-in
The .ro EPP / Auth-Code cannot be retrieved over the API. Both the registrar-transfer code and the registrant-transfer code are surfaced with the exact wording, links and explanations that send customers to rotld.ro/domadmin.
DNSSEC self-service
Customers manage their own DS records from the domain panel: key tag, algorithm (RSA, ECDSA, Ed25519), digest type, digest. Real-time hex validation, registry-side errors surfaced inline, no support ticket required.
Glue records, not just NS
The nameserver tab includes a nameserver lookup, a register-new-NS form with IPv4 / IPv6, modify and delete. Everything you used to do over the rotld.ro portal, now available to your customer in the WHMCS client area.
Transaction History: every registry operation, ever
Reserve, activate, register, renew, transfer, trade, contact updates, DNSSEC changes, NS edits. Each call leaves a row with the period, the fee, the registrar balance after the operation, the registrant snapshot and the full API payload. Searchable, filterable, paginated, never silently overwritten.
| # | Domain | Operation | User | Period | Fee | Balance | Expiry | Date | |
|---|---|---|---|---|---|---|---|---|---|
| 1247 | example.ro | register | maria.popescu | 1y | €4.50 | €312.40 | 2027-05-23 | 23.05 14:22 | |
| 1246 | example.ro | activate | maria.popescu | 1y | €0.00 | €312.40 | 2027-05-23 | 23.05 14:22 | |
| 1245 | example.ro | reserve | maria.popescu | 1y | €0.00 | €316.90 | 2027-05-23 | 23.05 14:18 | |
| 1244 | birou-avocat.ro | renew | andrei.ionescu | 2y | €9.00 | €316.90 | 2028-05-23 | 23.05 11:04 | |
| 1243 | tech-srl.com.ro | trade | ADMIN | 1y | €4.50 | €325.90 | 2027-04-12 | 22.05 16:30 | |
| 1242 | studio-design.ro | contact-correct | cristina.dragomir | – | €0.00 | €330.40 | 2026-11-18 | 22.05 09:47 | |
| 1241 | consultanta.ro | contact-update | radu.matei | – | €0.00 | €330.40 | 2027-02-03 | 22.05 08:11 | |
| 1240 | cabinetstomatologic.com.ro | transfer | elena.vasile | 1y | €4.50 | €330.40 | 2027-05-21 | 21.05 19:55 |
One-click access to every .ro feature
The domain details page is augmented with a six-card action row, ROTLD-aware sidebar and inline panels for nameservers, DNSSEC, registrant correction and EPP. Built on the WHMCS Twenty-One theme so it inherits your storefront branding.
Manage example.ro
| Key tag | Algorithm | Type | Digest | |
|---|---|---|---|---|
| 42153 | ECDSA P-256 / SHA-256 | SHA-256 | 8a4b6cf3 21de9871 9a02b3c4 e58fda71 | |
| 19847 | RSA / SHA-256 | SHA-256 | 3f1a2b4d 7c9e8f01 6a5b2c3e 9d8a7f01 |
Saved Registrants
| Name | CNP / CIF | Type | ROTLD CID | |
|---|---|---|---|---|
| Maria Popescu | 2840618400159 | Private person | CID-48217 | |
| Tech Solutions SRL | RO12345678 | Commercial | CID-51904 | |
| Asociatia EduRomania | 38214567 | Non-Commercial | Not synced | |
| Andrei Ionescu PFA | RO34567890 | Authorised person | CID-49862 |
What’s inside
Capabilities grouped by where they live in WHMCS. Every item below is an actual screen, hook, button or template, never roadmap.
Action cards row
Six colour-coded shortcuts above domain details (Overview, Auto Renew, Update Registrant, Nameservers, DNSSEC, Get EPP Code) that activate the matching tab inline or navigate cross-page when the panel lives elsewhere.
Auto-renew toggle
Customers control auto-renewal directly on the domain page with a green / red status badge. WHMCS bills automatically before expiry; the module triggers the renew API call.
Update Registrant panel
Phone, email and address are editable any time. Protected fields (name, person type, CNP/CIF, registration number) are editable only inside the 24-hour correction window with a live HH:MM:SS countdown.
Nameserver editor
One-click between default ROTLD nameservers and custom ns1…ns5. JavaScript enables / disables inputs based on selection; AJAX writes back to the registry.
Nameserver lookup
Look up any FQDN and get IPv4 / IPv6 addresses, registration date, last update, status flags and how many domains use it. Bypasses the rotld.ro portal entirely.
Private NS & glue records
Register, modify and delete private nameservers (ns1.example.ro with IP addresses). Three styled cards (create, modify, delete) with inline validation and registry-side error surfacing.
DNSSEC self-service
Add and remove DS records: key tag, algorithm dropdown (RSA, ECDSA, Ed25519) with “recommended” markers, digest type (SHA-1 / SHA-256), digest with live hex validation.
EPP & transfer info
Two info boxes explaining the registrar-transfer code vs the registrant-transfer code, both with explicit deep-links to www.rotld.ro/domadmin for retrieval, since ROTLD doesn’t expose AuthInfo via API.
Correction window countdown
Two live timers: 24-hour customer-edit window and 72-hour support-edit window. When the customer window closes, protected fields lock and the panel guides them to contact support before the 72-hour ROTLD window expires.
Transaction History
Searchable, filterable audit log of every API operation. Per-operation stat cards, domain / operation / date filters, click-through to a transaction detail modal with the full payload.
Domain Operations console
Run register, reserve, activate, renew, trade, contact-update, contact-correct, get-EPP and domain-info ad-hoc from a single tab. Each action shows the resulting fee, balance after, expiry date and full registry response.
Trade workflow
Initiate, query, confirm or cancel domain trades (change of registrant). Trade IDs are stored against the original transaction so the status (open / closed / cancelled) is always known.
Saved Registrants
Reusable registrant profiles (name, person type, CNP/CIF, phone, address, ROTLD CID, optional default password). Sync individual profiles to ROTLD on demand; pre-populate trade / register forms from a dropdown.
Register / Reserve from admin
Place a domain directly from the admin panel. Bypass the customer checkout, check availability, pick a saved registrant, optionally set the domain password, then register or reserve.
Registry Poll & messages
View, acknowledge and archive ROTLD registry poll messages (expirations, trade confirmations, transfer notifications). Stored in a dedicated log for audit.
Status & health check
One-click registry connectivity test. Shows REGID, REGNAME, environment (test / production), server time, round-trip latency and the list of API methods this registrar account is authorised to call.
Setup TLDs wizard
Three-step onboarding: configure credentials, enable .ro extensions with per-currency / per-year pricing, install the storefront theme tweaks. Status badges show what’s done and what’s pending.
Email template editor
Customise the post-registration confirmation email and the daily registry poll digest with a GrapesJS WYSIWYG / CodeMirror dual-pane editor, live preview, test send and a placeholder sidebar grouped by section. Subject and body are saved independently so an entity-corrupted body can be reset without losing your subject line.
Dashboard widgets
Two admin dashboard widgets bundled out of the box. ROTLD Balance surfaces your current registrar balance with last-fetch timestamp; ROTLD Transactions rolls up the latest registry operations with click-through to the full audit log.
Test Mode toggle
Production and sandbox credentials live side-by-side in the registrar config form. Flip Test Mode on and every operation lands on the ROTLD test endpoint rotest.ro, flip it off and you are back on production. Fresh installs default to Test Mode so accidents are impossible.
Configurable correction window
The customer-edit window is configurable between 1 and 72 hours from the registrar config form (default 24). The 72-hour ROTLD support window remains the hard outer bound. Both timers run live on the registrant page.
Friendly registry errors
Raw ROTLD codes like Exception_ExpirationDateLimitExceeded and field-validation patterns like {REGISTRATION_NUMBER} REQUIRED are rewritten into readable English or Romanian sentences on Renewal Availability, Update Registrant and the register / renew / trade flows.
Reserve on order
Three independent triggers (OrderAdded, InvoiceCreation, InvoiceCreationPreEmail) reserve the name at the registry as soon as the cart is placed. Idempotent, so it fires once even if all three queue up.
Activate on payment
The registrar hook checks for an existing reservation on payment and calls domain-activate instead of domain-register. No double charge, no duplicate contact, balance debited only once.
Post-registration email
Branded confirmation email with registrant details, expiry date, ROTLD contact ID, EPP authcode and assigned nameservers. Suppresses the default WHMCS email so customers get one well-formatted message, not two.
Daily registry poll
Cron hook fetches every unread message from the ROTLD poll queue, stores them in mod_rotld_poll_log, acknowledges them upstream, then emails the admin a single grouped digest. Never spammy, always complete.
Registrant auto-sync
Whenever a customer registers a .ro domain or edits their client profile, the registrant database is updated with their canonical contact data. Future orders prefill from the saved list.
Cart-side validation
The ShoppingCartValidateDomainsConfig hook checks CNP / registration number requirements per person type before the order even reaches the gateway, blocking incomplete .ro registrations early.
Transfer auto-activate
After an inbound transfer succeeds, AfterRegistrarTransfer immediately marks the domain Active in WHMCS, pulls the expiry date back from the registry and optionally triggers a one-year renewal.
ROTLD-aware sidebar
The domain-management sidebar is automatically reordered and relabelled for .ro domains: Overview, Auto Renew, Update Registrant, Nameservers, DNSSEC, Get EPP Code. Non-ROTLD domains keep the WHMCS defaults.
Bilingual lang files
Every storefront-facing string ships in English and Romanian. Cart-side registrant labels follow the customer’s WHMCS language automatically, with no $_LANG overrides to maintain.
- WHMCS
8and9· ionCube core supported, integration is plain PHP- PHP
8.0and newer- Themes
- Twenty-One (full theme integration), Six (sidebar & cart hooks). Other themes inherit the cart-side and admin-side features.
- Registry
- ROTLD REST API v2.7 · Digest auth via
regid:password· Test endpointrotest.ro, production endpoint configurable - TLDs supported
.ro·.com.ro·.net.ro·.org.ro·.info.ro·.biz.ro·.tm.ro·.nom.ro·.nt.ro·.store.ro·.www.ro·.arts.ro·.firm.ro·.rec.ro- Person types
pprivate ·apauthorised ·ncnon-commercial ·ccommercial ·gigovernment institution ·pipublic institution ·oother- DNSSEC algorithms
3DSA ·5RSA/SHA-1 ·6DSA-NSEC3-SHA1 ·7RSA-NSEC3-SHA1 ·8RSA/SHA-256 (recommended) ·10RSA/SHA-512 ·12ECC-GOST ·13ECDSA P-256/SHA-256 ·14ECDSA P-384/SHA-384- Digest types
1SHA-1 (40 hex) ·2SHA-256 (64 hex) · hex-only client-side validation- Renewal periods
- 1 to 10 years · configurable per TLD per currency
- Languages
- English, Romanian · complete mirror, no missing keys
- Database tables created
mod_rotld_transactions,mod_rotld_registrants,mod_rotld_poll_log· auto-migrated on every load- Permissions
- Admin features gated by the standard WHMCS admin role check · client features scoped to the logged-in customer’s own domains
- Cron
- Hooks into the WHMCS Daily Cron Job · no extra cron entry required · optional 5-minute pre-cron mode for fast poll cycles
From install to live in three steps
The Setup TLDs tab walks an admin through credentials, extensions and storefront integration. Each step shows its own progress badge so you always know what’s pending.
Changelog
Reverse-chronological. The module is under active maintenance against the live ROTLD registry; release cadence picks up around registry policy changes.
v1.1.3 May 23rd, 2026
- Fix Internal stability and packaging fixes.
v1.1.1 May 22nd, 2026
- Fix Domain Trade rows in the Transactions tab now show Fee (EUR), Balance After and Expiry instead of dashes. The trade-initiate, trade-confirm and trade-cancel paths capture fee, balance and expiration date from the ROTLD response and persist them on the row.
- Fix Existing trade rows recorded before 1.1.1 are backfilled automatically on the next addon load. Idempotent: only NULL columns are populated.
v1.0.46 May 11th, 2026
- New Uniform page heading style across all 12 admin tabs, with consistent icons, spacing and titles.
- New Friendly bilingual rewrites for registry API errors. Codes like
Exception_ExpirationDateLimitExceededand field-validation patterns like{REGISTRATION_NUMBER} REQUIREDnow render as readable English or Romanian sentences on Renewal Availability, Update Registrant and the register / renew / trade flows. - Improvement Uniform input look across every admin tab (1px ccc border, 4px radius, 13px / 34px box, blue focus ring), scoped to
.rotld-addon. - Improvement Email Customization page flattened to the addon palette; indigo / blue gradients removed.
- Improvement Client area action cards now align flush with the card body on domain-details.
- Improvement Postal Code is now a required field on Create Registrant.
- Fix Editing an email-template subject and clicking Save no longer reverts to factory subject. Subject and body now travel independently.
v1.0.45 May 10th, 2026
- New Theme-payload hook
rotld_action_cards.phpdeployed by the Theme Installer. Injects a small CSS+JS block viaClientAreaHeadOutputso the action-card highlight refreshes every request without touching the Smarty compile cache. - Fix Action cards now highlight the matching card on the Contact Information and EPP pages, not only on the tab-anchored ones (Overview, Auto Renew, Nameservers, DNSSEC).
v1.0.44 May 10th, 2026
- Fix Add-New-Contact and alternative-registrant orders now use the selected contact at ROTLD. The reserve-on-invoice hook reads
tblorders.contactidand pulls firstname, lastname, company, email, address and phone fromtblcontactsbefore callingcontact-create. - Fix Registration Number now appears on the Contact Information page for company registrants provisioned through reserve-on-invoice. The fallback now walks register, activate and reserve rows newest-first.
- Fix Private-nameserver register form no longer trips the validator with all fields filled in (prefix input id realigned with the validator and the modify form).
- Fix Domain Operations Info and Contacts Domain Info now display the real ROTLD status instead of
N/A(readsstatuses[], with fallback to legacy scalarstatus). - Improvement Module Log gains visibility for the client-area nameserver-create path and for raw
domain-inforesponses surfaced by the admin Info forms.
v1.0.43 May 10th, 2026
- Improvement Cart i18n hook now stamps the .ro additional-field labels on every
cart.phprequest under all three key shapes WHMCS may consult (legacyrotld<slug>, CamelCaseCNPFiscalCodeand lowercasecnpfiscalcode/registranttype). Order forms outsidestandard_cart(e.g.nexus_cart) now display the localised labels too. - Improvement Email-template editor (Customization sub-tab) is now fully localised: subtab labels, page heading, mode tabs, action buttons, the placeholder sidebar, modal copy, AJAX status messages, GrapesJS labels and the Syntax Help popup all read from the bundled lang files.
v1.0.42 May 10th, 2026
- Fix Post-registration confirmation email no longer drops supplementary-plane Unicode characters (4-byte UTF-8 emoji like party-popper, globe, calendar icons). The send path now uses
localAPI('SendEmail')withcustomtype/customsubject/custommessage, bypassing the 3-byte collation ontblemailtemplates.message.
v1.0.41 May 9th, 2026
- New Client-area i18n extended to the cart configdomains page and to all three ROTLD-aware client pages (Get EPP, Domain Contacts, Domain Details / Nameservers tab). Switches the registrant contact block, the EPP page warnings, the action cards row, the Current Nameservers card, the DNSSEC manager and the private-nameserver forms into the active WHMCS language.
- Improvement Fresh-install defaults:
Test ModeandReserve domain on ordernow ship ason, so a fresh activation lands on the sandbox API and on the reserve-at-order flow. - Improvement Bundled email defaults now use HTML hex entity codes (e.g.
🎉) instead of literal emoji glyphs, so mail clients that previously dropped or mojibaked them render correctly.
v1.0.4 May 9th, 2026
- Fix Active-language detection on WHMCS 9. The i18n helper now reads
$GLOBALS['language'](the canonical signal WHMCS 9 sets on every request, in both admin and client area) before any other source. Switching the operator UI language or the client locale now actually flips every ROTLD string.
v1.0.3 May 6th, 2026
- New In-module i18n: the registrar, addon, widgets and hooks read their user-facing strings from a bundled lang system at
modules/registrars/rotld/lang/. English is canonical, Romanian is a full mirror. - New Lang overrides at WHMCS root register three key shapes for each .ro additional field: CamelCase (
CNPFiscalCode, WHMCS 8 dist), lowercase slug (cnpfiscalcode/cnporfiscalcode, WHMCS 9 dist) and the legacyrotld<slug>prefixed keys. - Improvement No database schema changes, no removed columns, no removed hooks. All existing customer values still parse.
Will it run on your install?
The module is a regular WHMCS addon plus a registrar module. Drop it in modules/addons/rotld_manager/ and modules/registrars/rotld/, activate from the admin and you’re done. No external services, no message queue, no separate database.
- WHMCS
- WHMCS 8 and 9 · Twenty-One and Six themes officially supported
- PHP
- 8.0 and newer · runs on whichever PHP your WHMCS was tested against
- ROTLD account
- An active accredited-registrar account with the Romanian National Top-Level Domain registry (rotld.ro), plus REGID + password + API endpoint
- Outbound HTTPS
- Your server must reach the ROTLD REST endpoint over HTTPS (TCP/443). Test against
rotest.rofirst - WHMCS cron
- Standard WHMCS daily cron, no extra hooks beyond the standard schedule, no extra schedule needed
- Database
- MySQL 5.7+ or MariaDB 10.3+ · module creates and migrates its own tables
Ready to put .ro on autopilot?
Get in touch and we’ll walk you through the install on a staging WHMCS, point it at the ROTLD test environment and migrate your live extensions when you’re ready. No long-term contract, no per-domain fees on top of the registry tariff.