WH4U Domains
Domain reseller plugin for searching, registering, and transferring domains via the DomainsReseller API.
Use with caution
WH4U Domains works, but test it on a staging site before relying on it in 2026. Was last updated 5 months ago, and scores 46/100 on our health check.
- Small user base (<10 active installs)
- Very few reviews so far
- Only tested up to WordPress 6.9 (latest is 7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where WH4U Domains stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| domain registration | >100 |
| domain search | >100 |
| domains | >100 |
| reseller | #49 |
| TLD | #30 |
About WH4U Domains
From the official readme · v1.5.6Description
WH4U Domains is a WordPress plugin that allows website owners and resellers to offer domain name services directly from their WordPress site. It integrates with the DomainsReseller API to provide real-time domain availability checking, registration, and transfer capabilities.
Features
- Domain Search — Visitors can search for domain availability via a shortcode or Gutenberg block
- Public Registration & Transfer — Anonymous visitors can submit domain registration and transfer requests that admins review and approve
- Admin Dashboard — Full admin panel for managing orders, viewing API status, and monitoring the retry queue
- Reseller Support — Per-user API credentials allow multi-reseller setups
- Retry Queue — Failed API calls are automatically retried with exponential backoff
- Shopping Cart Redirect — Optional redirect to WHMCS, Blesta, ClientExec, Upmind, or custom cart URL with the domain pre-filled when visitors click Register or Transfer
- Internationalization — Fully translatable; Greek translation included
How It Works
- Install and activate the plugin
- Configure your DomainsReseller API credentials under Domains > Settings
- Add the
[wh4u_domain_lookup]shortcode or the “Domain Lookup” block to any page - Visitors search for domains — available domains can be registered, and taken domains can be transferred through the frontend form (or, if configured, sent to your WHMCS/Blesta/ClientExec/Upmind cart with the domain in the URL)
- Admins review and approve/reject public orders from the WordPress admin
Third-Party Service
This plugin connects to the DomainsReseller API provided by WebHosting4U to perform all domain-related operations.
What data is sent
- Domain lookups: The domain name being searched is sent to check availability
- Domain registration: Registrant contact information (name, email, phone, address, company, country), the domain name, registration period, nameservers, and addon preferences are sent to process the registration
- Domain transfer: Domain name, registration period, and EPP code are sent
- TLD queries: Requests for available TLDs are sent
When data is sent
- When a visitor performs a domain search on the frontend
- When an admin approves a public domain registration order
- When an admin submits a registration or transfer order from the admin panel
- When TLD lists are loaded (cached locally for 12 hours)
Service details
- Service provider: WebHosting4U
- Service URL: https://webhosting4u.gr
- Terms of Service: https://webhosting4u.gr/terms-of-service.php
- Privacy Policy: https://webhosting4u.gr/privacy-policy.php
Cloudflare Turnstile (optional)
When Turnstile bot protection is enabled in Settings, this plugin loads the Cloudflare Turnstile JavaScript widget on pages with the domain lookup form and sends the challenge response token to Cloudflare for server-side verification before processing public orders.
- Service provider: Cloudflare, Inc.
- Service URL: https://www.cloudflare.com/products/turnstile/
- Terms of Service: https://www.cloudflare.com/terms/
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
Data stored locally
This plugin stores the following data on your WordPress installation:
- Order records: domain name, registration period, status, and encrypted registrant contact details (encrypted with AES-256-CBC + HMAC at rest)
- Public order submissions: stored as a custom post type with encrypted contact data until an administrator approves or rejects them
- API logs and notification records: request/response entries and email/webhook dispatch history with secrets redacted. A daily WP-Cron task prunes rows older than 30 days; the retention period is filterable via the
wh4u_log_retention_daysfilter. - Retry queue: failed API calls scheduled for exponential-backoff retry via WP-Cron
- Rate-limit counters: short-lived transients keyed by user ID or a salted SHA-256 hash of the visitor IP; used only for abuse protection and expire within minutes
- Reseller settings: per-user API credentials, with the API key and optional webhook secret encrypted at rest
No data is sent to any third party other than the services listed above.
Installation
- Upload the
wh4u-domainsfolder to/wp-content/plugins/ - Activate the plugin through the Plugins menu in WordPress
- Go to Domains > Settings > Credentials and enter your DomainsReseller API email and API key
- Set your default nameservers under the same Credentials tab
- Go to Domains > Settings > General to choose between Real-time or Notification-only registration mode
- (Optional) Under General, set Shopping Cart Redirect to WHMCS, Blesta, ClientExec, Upmind, or Custom and enter your cart URL so visitors are sent to your cart with the domain pre-filled
- Add
[wh4u_domain_lookup]to any page, or use the “Domain Lookup” Gutenberg block
Frequently asked questions
Do I need a DomainsReseller account?
Yes. You need valid API credentials from WebHosting4U to use this plugin. Without credentials, the domain search will not function.
Can visitors register domains without logging in?
Yes. The frontend form allows anonymous visitors to submit registration and transfer requests. These are stored as pending orders that an admin must approve before the domain is processed through the API.
What happens if the API is temporarily unavailable?
Orders that fail due to temporary API issues (timeouts, server errors) are automatically queued for retry with exponential backoff. The retry queue processes items via WP-Cron.
Can I send customers to my WHMCS (or other) cart instead of the built-in form?
Yes. Under Domains > Settings > General, use the Shopping Cart Redirect section. Choose WHMCS, Blesta, ClientExec, Upmind, or Custom URL template, and enter your cart base URL (or full URL templates with {domain}, {sld}, {tld}). When a visitor clicks Register or Transfer, they will be redirected to your cart with the domain pre-filled.
Is the plugin translatable?
Yes. The plugin is fully internationalized. A Greek translation is included. Additional translations can be added via .po/.mo files in the languages/ directory.
Changelog
1.5.6
- Fix: Custom shopping-cart URL templates that used only
{sld}and{tld}placeholders (the pattern shown in the admin example) were treated as “not configured”, so visitors clicking Register or Transfer always saw the built-in plugin form instead of being redirected.WH4U_Cart_Redirect::is_configured()now accepts any of{domain},{sld}, or{tld}. - Improved: Shopping Cart Redirect settings page rewritten with clearer, novice-friendly help text — explains when to use each cart type, what each placeholder means, and which fields apply to which cart type.
1.5.5
- Removed: TLD Pricing admin page and all pricing-related code paths. The upstream DomainsReseller API
/tlds/pricingendpoint returnsregistrationPrice: nullfor TLDs whose registry enforces multi-year registration minimums (notably.gr, which requires a 2-year minimum), so a pricing table rendered from this endpoint cannot reliably display prices for every reseller-enabled TLD. Rather than half-showing data, the “View Pricing” tile on the dashboard now links out to the authoritative WHMCS pricing page athttps://webhosting4u.gr/customers/index.php?m=DomainsReseller&mg-page=Prices - Removed:
admin/class-wh4u-admin-pricing.php,rest-api/class-wh4u-rest-pricing.php, the/wh4u/v1/tlds,/wh4u/v1/tlds/pricing,/wh4u/v1/tlds/pricing/cache, and/wh4u/v1/pricing/(register|transfer)REST endpoints, thewh4u_tld_pricing_v2transient, theloadPricing()admin JS routine, the frontendprefetchPricing()/getPriceForTld()code path, theshow_pricingappearance setting, theshowPricingblock attribute, thedata-show-pricingshortcode data attribute, and the.wh4u-domains__result-priceCSS rules - Changed: dashboard “View Pricing” quick link is now an external link (opens the WHMCS pricing page in a new tab with
rel="noopener noreferrer")
1.5.4
- Fix: TLD pricing page left the register column blank for ccTLDs whose upstream response emits an empty
registrationPricefield because they have no 1-year tier (notably.gr, whose registry enforces a 2-year minimum).extract_price()in the REST pricing controller now skips empty scalars/arrays instead of accepting the first matching key, recurses into nested period-keyed arrays picking the lowest numeric period (so{"2":"24.00","4":"48.00"}surfaces the 2-year price), and as a last resort scans period-suffixed variants likeregister2orregistrationPrice_2y - Added: “Refresh Cache” button on the TLD Pricing admin page, backed by a new
DELETE /wh4u/v1/tlds/pricing/cacheendpoint (gated by thewh4u_manage_domainscapability) that clears both thewh4u_tld_pricing_v2andwh4u_tlds_cachetransients; needed because the previous normalization was cached for 12 hours and existing sites would otherwise keep serving stale empty prices after upgrade
1.5.3
- i18n: reinstated
load_plugin_textdomain()on theinithook so self-hosted installs load translations correctly under WordPress 6.7+ (where gettext calls beforeinitno longer resolve the user locale) - i18n: replaced string concatenation patterns (
__( 'API call failed: ' ) . $msg,$label . ' ' . __( 'Contact' ),$period . ' ' . __( 'year(s)' )) withsprintf/_nagainst%s/%dplaceholders in admin-dashboard, admin-domains, admin-history, and notifications; word order can now be reordered per locale without code changes - i18n: replaced the hardcoded English
' yr'unit in the order history period column with a proper_n( '%d year', '%d years' )plural form - i18n: added translator comments (
/* translators: ... */) on every newsprintf/_ncall per the WordPress handbook - i18n: regenerated
wh4u-domains.pot(412 strings) from the updated source, merged intowh4u-domains-el.po, and translated the remaining 77 previously-untranslated Greek strings (Frontend Appearance panel, Shopping Cart Redirect, Turnstile, Reverse Proxy / Trusted IPs, Public Orders post type + status plurals, block editor title/description/keywords, encryption key notices) - i18n: rebuilt
wh4u-domains-el.moand the JSON translation file consumed bywp_set_script_translations(); removed two orphan JSON files whosesourcefield held malformed artifacts ((JS,i18n)) from a prior tooling run
1.5.2
- Security: encryption key management rewrite — removed the auto-generate-to-wp_options fallback so decryption keys are never created in the database; added a one-shot idempotent migration (guarded by a 5-minute transient lock) that re-encrypts reseller settings, order contacts, site settings, and public-order PII postmeta under the preferred WH4U_ENCRYPTION_KEY / AUTH_KEY-derived key and only deletes the legacy wp_options key after every row migrates successfully
- Security: webhook delivery now passes
redirection => 0towp_remote_post(), closing a redirect-based SSRF bypass where a crafted 3xx response could divert a webhook away from the validated/pinned host - Security:
save_reseller_settings()in the admin reseller screen now re-verifies thewh4u_reseller_settings_nonceinside the save handler (defense-in-depth alongside the existingcheck_admin_referer()wrapper) - Security: defense-in-depth
(int)cast on$item->order_idin the retry queue before it reaches$wpdb->prepare()with a%dplaceholder, eliminating any theoretical type-confusion path regardless of upstream callers - Security: removed the unused
WH4U_Logger::get_logs()method so the admin-only log reader no longer exists as latent attack surface (no callers in the plugin)
1.5.1
- i18n: compiled Greek .mo binary from the existing .po catalogue so WordPress gettext loads translations at runtime without relying on a language pack
- i18n: all public-facing form labels (First Name, Last Name, Email, Phone, Address, City, State/Province, Country Code, Zip/Postal Code, Registration Period, Transfer Period, EPP/Auth Code, etc.) now render in Greek on el locale sites
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best WH4U Domains alternatives
All domain registration plugins →| Rank | Plugin | Active installs |
|---|---|---|
| 1 |
|
200+ |
FAQ
WH4U Domains: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 29, 2026
Is WH4U Domains free?
Yes. WH4U Domains is free to download and use from the official WordPress.org plugin directory.
Is WH4U Domains safe to use in 2026?
WH4U Domains works, but test it on a staging site before relying on it in 2026. Was last updated 5 months ago, and scores 46/100 on our health check.
How many websites use WH4U Domains?
WH4U Domains is active on <10 WordPress websites and has been downloaded 509 times since it launched in April 2026. It was downloaded 53 times in the last 30 days.
Does WH4U Domains work with WordPress 7.1?
WH4U Domains is officially tested up to WordPress 6.9.9, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does WH4U Domains need?
WH4U Domains requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was WH4U Domains last updated?
The latest version, 1.5.6, was released on April 26, 2026 (5 months ago).
Who makes WH4U Domains?
WH4U Domains is developed and maintained by webhosting4ugr.
What are the best alternatives to WH4U Domains?
The most popular alternatives to WH4U Domains are Domain Search for WHMCS (200+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card


