WHMCS will never ever be secure. They have a custom PHP Register Global function at their core and localhost.re has told the world about it, so all a blackhat hacker has to do is decode and find a exploit, not tell them on bug crowd and then what? Blesta's was a few XSS what has WHMCS had...