Revenue
One revenue number everywhere
The dashboard and the reports now count revenue the same way, with a 13-month chart, correct gateway attribution, and new Refund Rate and Customer Satisfaction widgets.
ERPStore v26.9.1 — by MrZaKaRiA IT Solutions
ERPStore is self-hosted subscription management software that runs a recurring-revenue business end to end on hosting you own. It is built for digital-subscription resellers — streaming and IPTV lines, VPN, hosting, software licences — and for agencies running a branded store per client. Your customers, payments and ledger stay in your own MySQL, the licence is per domain with no per-seat or per-transaction fee, and it installs on ordinary shared hosting with a working cron.
Per-seat fees, per-transaction fees and commission on your sales. The licence is bound to a domain, not to your headcount or your revenue.
Tables on a recorded v26.6.6 upgrade against a live customer database: 31 migrations applied, and 1,023 users, 354 orders and 483 payments came through unchanged.
Language packs covering the interface and the client portal. All layouts are left-to-right, including Arabic, Farsi and Urdu.
Email transports — SMTP, Amazon SES v2, Brevo, Resend, MailerSend, Mailtrap — with health reporting and auto-failover, so deliverability is not tied to one vendor.
Definition
ERPStore is self-hosted subscription management software: a storefront, billing ledger and CRM in one PHP application that a business installs on its own hosting to sell, renew and account for recurring products. ERPStore is built and licensed by MrZaKaRiA IT Solutions, and the current release is version 26.9.1, published on 1 September 2026.
It is built for digital-subscription resellers selling streaming and IPTV lines, VPN, hosting or software licences; for agencies deploying a branded store per client; and for small recurring-revenue businesses that have outgrown spreadsheet renewal tracking but do not want an enterprise ERP. It is aimed at operators in Morocco, MENA, wider Africa and Europe, and the interface ships in 32 languages — all of them in a left-to-right layout.
The backend is a custom PHP 7.4+ REST API with 76 endpoint files over MySQL or MariaDB. The frontend is a Vue 2.7 single-page application with 134 page components and 44 shared components. Deployment is an upload plus one visit to /install, which inspects the live database, shows what it intends to do and applies only what is missing. Both of those stack choices carry a real cost to you, and both are set out plainly further down this page.
Product pages: ERP Store (this one), River ERP and Rain Store. Custom builds are covered under ERP and CRM systems, and delivered work sits in the portfolio.
New since August
The production-hardening work (pull request #4, 66 commits) was merged and released as 26.9.1 on 1 September 2026, and the test suite grew from 963 to 1,406 passing tests with none failing.
Revenue
The dashboard and the reports now count revenue the same way, with a 13-month chart, correct gateway attribution, and new Refund Rate and Customer Satisfaction widgets.
Refunds
Choose which subscriptions a refund covers, with automatic cancel or stop and revenue netting, in a dedicated Refunded tab.
Search
Search covers cancelled, ended and deleted records too, with status badges, matching on activation details such as part of a MAC address.
Security
All 12 high-severity findings fixed, including an unauthenticated PDF endpoint and a session-token leak, plus four layers that refuse crawlers and AI trainers.
Clients
A staff-only WhatsApp or Telegram number per client with its country flag, and one image adjuster for logos, favicons, avatars and product pictures.
Upgrades
The installer keeps the store's name, currency and timezone, and old stores now complete every migration.
Modules
Every module below is in the released 26.9.1 package that a licence build is cut from.
Catalogue
Product types, packages, per-currency prices, coupons with usage limits, sort order, and audience restriction so resellers and retail clients can see different catalogues.
Orders
Nine statuses — New, Processing, Pending, Canceled, Active, Stopped, To Stop, Deleted and Needs Details — each with its own admin board, plus an activation queue and per-order activation fields.
Payments
Stripe, PayPal, Paymentwall, Payssion, a Whop webhook, and manual or offline methods. Abandoned checkouts are resumable, and payment fees and per-method keys are configurable.
Money
A ledger with Products, General and Refund entry types, payment reconciliation against the gateway record, and CSV plus accounting export for whoever files the accounts.
Documents
Full or partial refunds recorded against a payment code, optionally stopping the subscriptions they paid for. Clients download their own PDF invoices, generated with mPDF, from the portal.
CRM
A client pipeline running New, Verified, Active, Expiring, Expired and Win-back, a renewal board, CRM tasks, and client notes and tags kept on the same customer record.
A background campaign worker with open, click, bounce and spam tracking, suppression lists and unsubscribe handling, plus a reminder engine with before, after and after-range rules that skips clients who already renewed.
Portal
24 client pages: dashboard, product list, reorder, order boards, payments with invoice download, threaded support requests, active-session management, email preferences, client-side 2FA and subscription pause.
Operations
Bulk operations, incidents with a public status page, outbound webhooks, email log, audit log viewer, online users, admin revoke of client sessions, one-click database backup and scheduled Dropbox backups with retention.
Vertical
Paste a raw M3U URL and the structured activation payload is generated for you — M3U URL, xTream username and password, base URL and URL:Port — with matching parsing on the server side.
Growth
Referral programme, free trials, checkout upsell, a reseller prepaid credit wallet (top-ups are recorded; orders do not draw on the balance yet), and payment recovery and dunning. Every one is gated behind a setting and disabled until you turn it on.
Languages
32 locale files covering the whole interface and the client portal; the English file alone holds 1,531 leaf strings, and 11,819 strings were translated in v26.6.4 to bring 27 languages up to complete.
Included
The parts most platforms sell as connectors are part of the same application and the same database.
SMTP, Amazon SES v2 with SigV4 signing, Brevo, Resend, MailerSend and Mailtrap, with per-stream sender routing for system, campaign and news mail, a health endpoint reporting UP, DOWN, LIMITED or INACTIVE, auto-failover, and admin alerts forced through SMTP so a provider outage cannot silence them.
18 tools including pipeline, revenue report, product performance, campaign health, cron reminder health, client search, client profile, draft renewal message, chart and report generation. Point it at Ollama, LM Studio, llama.cpp or vLLM on your own hardware and no customer data leaves your server. Point it at OpenAI, Groq, Gemini, DeepSeek, Mistral, Together, xAI or OpenRouter — 12 presets ship, plus custom OpenAI-compatible endpoints — and the data does reach that vendor. Live lookups and per-client lookups can each be switched off. Under GDPR, the sane setup is a local model with per-client tools disabled, and the decision written down.
Nine named permission scopes gate the API — manageAccounting, manageOrders, managePayments, manageProducts, manageRequests, manageSearch, manageSettings, manageSystem and manageUsers — alongside an all wildcard, with TOTP two-factor authentication available for staff and for clients.
Per-IP and per-identity rate limiting answering 429 with Retry-After, configuration-driven Turnstile or reCAPTCHA, origin-checked CORS, security headers, denied server-side paths, and a JSON 500 carrying a greppable reference instead of a blank page.
GET /api/health returns 503 when the database is unreachable or migrations are pending. Email log, login history, audit log and activity log each have retention sweeps, where a value of 0 means keep forever. Server-side pagination on orders, users and payments caps at 500 per page.
HubSpot and Twenty contact sync exists as an API endpoint, keyed on email, with no admin screen yet — we run it for you during setup — with a dry-run preview reporting create, update and skip counts before anything is written. Import only fills blank local fields unless you explicitly ask for overwrite.


Money paths
Gateway dashboards and your own books drift apart the moment refunds, fees and cost of goods enter the picture. The released build keeps one ledger and reconciles it against the payment record. The wider reporting rebuild — money counted once with refunds separated, cost of goods split out of expenses, MRR, ARR, ARPU, cohort retention, gross margin by product — shipped in 26.9.1. It is the newest part of the product, so check its numbers against your gateway for the first months.
Renewals and recovery
Renewal dates live in the database, not in a calendar reminder. The reminder engine runs from cron on before, after and after-range rules, and skips anyone who has already renewed. Because there is no card-on-file auto-renew, the reminder and recovery layer is doing the work that stored-card billing does elsewhere — so it is worth configuring properly on day one rather than later.
Install and upgrade
The installer inspects the live database, prints what it intends to do, and applies only what is missing — tables, columns, column types, nullability, indexes, settings, resources and foreign-key rules. It is safe to re-run and it does not drop data. It is not a substitute for a backup, and the history here is not spotless: stores on MySQL 5.x-era hosting could not upgrade at all until 26.6.6.
Honest status
The released version is 26.9.1, and real stores run on ERPStore. Per-domain builds have been issued for live customer domains, and an earlier upgrade against a real customer database is on record: 31 migrations applied, 36 tables to 51, and 1,023 users, 354 orders and 483 payments carried through unchanged.
The production-hardening work that was still a pull request in August was merged and released on 1 September 2026. The suite stands at 1,406 passing tests and none failing, and a verified audit of 87 findings has all 12 high-severity ones fixed.
Two things to price in. Since the payment-path changes, a real transaction has not yet been run through every gateway, so plan one live transaction on your own install before you take customers. And about 54 medium and low audit findings remain open; they are on the list, not hidden from it.
Straight answers
Refunds are recorded, not executed. You issue the refund in Stripe or PayPal, then record it against the payment code. The admin panel will not move money out through a gateway API. That is a deliberate refusal, and it costs you one manual step an integrated platform would automate.
There is no card-on-file automatic renewal. Renewals are reminder-and-repurchase driven: the reminder engine chases the expiry, the customer buys again. If your model depends on silently charging a stored card each month, that is a structural gap, not a setting.
Self-hosted means you are operations. You provide PHP, MySQL or MariaDB, Apache or nginx, TLS, a cron that actually fires, and backups. There is no hosted tenant to fall back on, and no SaaS option exists.
Some documented features are plans, not code. The Gold Panel integration described across 640 lines of planning document is not implemented, and it is not sold. Neither is a Vue 3 or Laravel rewrite; those plans exist and were rejected on purpose.
The stack is frozen and past upstream end of life. Vue 2.7 reached end of life in December 2023, and the build also pins Element UI 2, Chart.js 2 and Bootstrap 4. No security patches come from upstream for any of them. PHP 7.4 is the floor and is itself past upstream security support, so deploy on a currently supported PHP release and ask which versions are tested. A future rewrite is a real cost, not a hypothetical one.
The backend is hand-rolled, not Laravel or Symfony. Routing, authentication and the data layer sit on Medoo and custom code. That buys a small, readable codebase. It costs you upstream security maintenance on the backend too, and a much smaller pool of developers who could pick it up if the vendor were unavailable.
Translation stops at the interface. 32 language packs cover the UI and the client portal. API error messages and form validation are English-only, and 35 open findings track exactly that. Arabic, Farsi and Urdu are translated but render in a left-to-right layout; there is no RTL layout support. A non-English customer will meet English text on failure paths.
It is one person and one company. All authorship traces to a single developer at MrZaKaRiA IT Solutions. No SLA, support terms, escrow arrangement or reference customer list appears anywhere in the product materials. Bus factor is a fair question and it should be asked out loud.
Compare
The three things buyers actually weigh this against. Grades reflect each product's publicly documented positioning as of August 2026, and where a rival's capability was unclear it has been graded in their favour. Vendor terms change more often than this page does, so confirm current details with each of them. Six of the fourteen rows go against ERPStore.
| Capability | ERPStore | WHMCS (self-hosted licence) | Hosted billing SaaS (Chargebee, Recurly) | Spreadsheet + manual invoices |
|---|---|---|---|---|
| Runs on your own server and your own database | ✓ | ✓ | — | ✓ |
| Customer list and payment history stay out of a vendor cloud | ✓ | ✓ | — | ✓ |
| Cost does not scale with your revenue or your headcount | ✓ | Partial | — | ✓ |
| Storefront, client portal, accounting ledger and email campaigns in one application | ✓ | Partial | Partial | — |
| Client portal interface in 32 languages included | ✓ | Partial | Partial | — |
| AI assistant that can run entirely on a local model | ✓ | Partial | Partial | — |
| Card-on-file automatic renewal | — | ✓ | ✓ | — |
| Refunds executed through the gateway from the admin panel | — | ✓ | ✓ | — |
| Vendor-managed hosting, patching and uptime | — | Partial | ✓ | — |
| Large third-party module and developer ecosystem | — | ✓ | Partial | — |
| Published pricing you can evaluate without a sales call | — | ✓ | ✓ | ✓ |
| Contractual support SLA available | — | ✓ | ✓ | — |
| Named reference customers you can check | — | ✓ | ✓ | — |
| Zero software cost to start | — | — | Partial | ✓ |
Fit check
There is no demo tenant, no trial and no public price list, so here is the self-qualification instead. If two or three of these go the wrong way, do not book — you would not enjoy the deployment and neither would we.
Next step
One call covers products, currencies, gateways, languages, and the real state of the data you would be bringing across. No number comes before that look. You get a written quote covering the per-domain licence, the migration and the deployment.
Commercials
There is no public price list, because scope sets the number: how many products, which gateways, how many languages, how much data has to come across, and whether the deployment is run for you. The model, though, is fixed, and it is worth understanding before the call.
ERPStore is licensed per domain by MrZaKaRiA IT Solutions. A build is produced for one hostname or one wildcard domain and signed with an Ed25519 key; your install verifies that token against its own hostname. The licence is perpetual or dated, and a dated one has to be renewed. There is no per-seat charge, no per-transaction fee and no commission on your sales — so a good year for you is not a bigger invoice from us. That is the whole economic argument: a platform that bills per seat or per transaction costs more every time you grow, and a fixed per-domain licence does not. The shipped package carries only the Ed25519 public key, so a leaked download can verify a licence but can never mint one.
Three consequences to price in, stated before you ask. Moving to a new domain, adding a second store, or renewing a dated licence all need a newly signed token, and only the vendor holds the private key. If the key holder became unavailable, existing installs would keep running on the licence they already carry, but nothing new could be licensed and no install could change domain. Escrow and a perpetual unbound fallback are not documented anywhere in the product materials — they are a fair ask on a single-vendor product, so put both on the table at scoping and get the answer in writing.
The same goes for support: no support terms are published, so do not assume any. Agree scope, response expectations and upgrade handling in writing during scoping. The software is proprietary — Copyright © 2026 MrZaKaRiA, all rights reserved. You own the deployment and the data; you licence the code. Book a scoping call for terms in writing, or send the question in writing first.
Risk reversal
Self-hosted software fails differently from SaaS. These are the protections that are real, each stated with its limit.
Delivery
The sequence does not change. No timeline is quoted before your data has been looked at.
Catalogue, currencies, gateways, languages, and an honest look at what your current system will actually export. Bring your product list and your renewal list. The output is a written quote for licence, migration and deployment.
A package is built and signed for your domain or wildcard domain, perpetual or dated. Development hosts need no licence, so the whole install is rehearsed before it touches production.
Upload, then one visit to /install. The installer inspects the database, shows its plan, and applies only what is missing. Cron is set up for reminders, campaigns and backups.
286 settings across 26 sections: payment methods and keys, email transports and per-stream senders, reminder rules, captcha policy, retention periods, and which optional features to switch on.
Accounts, products, subscription history and payment records brought across by CSV import plus manual reconciliation against the ledger. Priced as work, because import quality is where these projects usually go wrong.
Run a real payment through each gateway you will use, end to end on your own install, and check it lands correctly in the ledger. No code has been through a live gateway on the hardening branch, so this step is yours to insist on.
You run the hosting, MySQL, TLS, cron and backups, or that is scoped as a separate engagement. Upgrades are re-runs of the same idempotent installer, with a full backup taken first.
Clients
Named clients, on the engagements they actually ran with us — build, ERP and hosting work rather than reviews of this specific product.
FAQ
Hosting, ownership, pricing model, production readiness and migration — answered before the call rather than on it.
ERPStore is self-hosted subscription management software built by MrZaKaRiA IT Solutions: storefront, checkout, client portal, order lifecycle, payment gateways, accounting ledger and CRM in one application. The backend is a custom PHP 7.4+ REST API with 76 endpoint files over MySQL or MariaDB. The frontend is a Vue 2.7 single-page app with 134 page components. The released version is 26.9.1, licensed per domain rather than per seat.
ERPStore is a self-hosted alternative to WHMCS for selling and renewing subscriptions, and like WHMCS it runs on your own server and your own database. ERPStore bundles an accounting ledger, six email transports with health status and auto-failover, a 32-language client portal, and an AI assistant that can run on a local model. WHMCS is older and larger, with published pricing, support contracts and a big third-party module ecosystem. ERPStore has none of those three.
ERPStore was built for digital-subscription resellers, including IPTV and streaming lines, VPN, hosting and software licences. Pasting a raw M3U URL auto-generates the structured activation payload — M3U URL, xTream username and password, base URL and URL:Port — with matching parsing on the server side. The nine-status order lifecycle carries an activation queue and per-order activation fields, so a paid order and its activation stay on one record.
ERPStore runs on PHP 7.4 or newer, MySQL or MariaDB, Apache 2.4 or nginx, TLS, and a cron that fires on schedule for reminders, campaigns and backups. It installs on ordinary shared hosting, but budget hosts often throttle cron, so check that first. PHP 7.4 is the floor and is itself past upstream security support, so deploy on a currently supported PHP release. MySQL 5.x-era stores could not upgrade at all before 26.6.6.
ERPStore keeps every customer, payment, ledger entry and email record in your own MySQL database, on hosting you control. There is no vendor cloud and no hosted tenant. The one upgrade on record finished at 51 tables, all plain MySQL, so a standard mysqldump gives you everything without vendor involvement. CSV export, accounting export, one-click database backup and scheduled Dropbox backups with retention ship in the product.
ERPStore has no public price list, because scope sets the number: catalogue size, gateways, languages, how much data migrates, and whether the deployment is run for you. The model is fixed. A licence is bound to one domain or one wildcard domain, perpetual or dated, with no per-seat charge, no per-transaction fee and no commission on sales. Development hosts need no licence at all. Book a scoping call for a written quote.
ERPStore 26.9.1 is the released version and real stores run on it. The production-hardening work was merged and released on 1 September 2026, with 1,406 tests passing and all 12 high-severity audit findings fixed. What to plan for: since the payment-path changes, not every gateway has carried a real transaction yet, so run one live payment on your own install before you take customers.
ERPStore migration is scoped as work, not a click. The tooling is a CSV importer, plus a HubSpot and Twenty contact sync endpoint we run during setup, with a dry-run preview that reports create, update and skip counts before anything is written. The CSV importer can create revenue-bearing subscriptions with no matching payment record, so accounts, subscriptions and payments are reconciled against the ledger by hand as a priced migration step.
Get a quote
What has been through a live gateway, escrow, support scope, and what your migration actually looks like. Those are the right things to ask of a single-vendor, self-hosted product, and they are what the scoping call is for. You get a written quote covering the per-domain licence, the migration and the deployment.