Money has to be right
A conversion, a streak bonus and a cashout all touch the same balance. If two requests can credit it at once, or a rejection does not claw the money back, the ledger drifts and never recovers.
Release 3.2.1 · Laravel 12 on PHP 8.2+
A self-hosted rewards business, in full. Members earn coins from offerwalls, streaks, a spin wheel, tasks and leaderboards, then request a cashout that you review and pay. You get the member storefront, the admin panel, the offer-network plumbing and the money ledger — as source code, with no vendor between you and your own balance.
Counts are of the files and schema in the release you receive. Offer-network accounts, payout accounts and mail credentials are deliberately not included — you supply your own.
The demo is the product on a public domain, seeded with sample data so every screen has something in it. Register an account, claim the daily bonus, spin the wheel, and open the offers.
There are no demo credentials to hand out. The release ships an empty user table on purpose, so register your own account in the demo — which is also the fastest way to see the captcha and the verification step working. The demo is a shared environment: its balances, members and offers are not yours, and nothing on it is a promise about earnings.
The members see coins and a spin wheel. You are running a ledger.
A conversion, a streak bonus and a cashout all touch the same balance. If two requests can credit it at once, or a rejection does not claw the money back, the ledger drifts and never recovers.
Farming is the default failure mode. Registration needs a captcha, a throttle, and enough friction that a scripted signup is not cheaper than a real member.
Each network posts conversions back with its own parameter names and its own signature scheme. Each one is a separate parser to write, and an unsigned parser is a way to mint coins from the internet.
You need a reviewed queue, a per-request fee calculation, an audit trail, and a decision about which accounts to pay.
Each of these is solved in the box, with the code in front of you rather than a vendor between you and your own balance.
Grouped by the job each part of the system performs. Five tabs, and every card on this page is a shipped screen.
The core loop, and the mechanics that bring a member back tomorrow. Build an offerwall business, a daily-habit product, a gamified site, paid tasks and promo campaigns off this one tab — each mechanic has its own admin screen and writes its own ledger row.
One balance to eight decimal places, and a transaction row for every movement with its type, source, running balance and reference. Eight decimal places is not decoration: it is what stops a fractional reward from being rounded into a comparison error.
One endpoint, /api/postback/{endpoint}, dispatches to the
parser for the network that owns it. Each parser implements that
network's own signature: MD5 and SHA-256 hashes, HMAC-SHA1, a
signed query string, a password comparison, or a source-IP allowlist.
Each network declares which credential its parser actually reads. If that credential is blank, the network is refused at the save step and at the callback, before the parser runs — on the credit path and on the clawback path both. One network has no verification at all and cannot be activated by design.
The admin screen prints the exact postback URL for each connected network with its macro list, ready to paste into that network's dashboard.
Fire a synthetic conversion at any of your connected networks from the admin, with a chosen member, reward and status. You can prove an integration works without waiting for real traffic.
Six of the networks can have their offer list pulled in on a schedule. The sync refuses to delete a catalogue when the upstream response is too small to be real, so an outage cannot wipe your offers.
Toggle fetched offers on and off, and create your own offers against any connected network. Filter by country, device and category.
Seven escalating rewards, claimed once a day. The claim is re-checked inside a row lock, so a double-click cannot pay twice.
Rules on either earnings or completed offers, claimable once each per day. Six are seeded and every one is editable.
A weighted wheel drawn from a cryptographically secure source, once a day, with a five-times wedge once the streak is complete. Wedge values and weights are yours to configure; the total weight must equal 100.
Dynamic per-task submission fields, image uploads stored outside the public web root, and an approve-or-reject decision. Rejection after approval takes the reward back.
XP accrues on credited income and a level-up pays a bonus. The threshold and the bonus are set in code, so you can adjust them to fit your own economy.
Daily and monthly tables by earnings, with the prize for each placing set as a tier. Six tiers ship seeded, and the payouts run from the scheduler rather than from a page load.
Single-use-per-member codes with an expiry and a global redemption cap, for launches, partners and newsletters. Disabled until you enable it, and redemption is rate limited so a brute-forced code cannot drain a balance.
Three commission tiers seeded at 3%, 5% and 7% at 1, 25 and 200 referrals, every tier editable and the whole programme behind one switch. Commission is a share of the referred member's offer earnings, paid on each credited conversion, and a referred member starts on a higher opening balance than one who arrives cold.
Everything between a member asking for money and you paying it: methods you define, a fee the server recalculates, a risk panel beside the approve button, and a queue that records who decided what.
Each method carries its own minimum, maximum, fixed fee, percentage fee, exchange rate, currency, payout delay, and the exact fields a member must supply. Four are seeded and all four ship disabled.
The amount leaves the balance when the request is made, and the fee is recalculated from the locked method record at that moment, not taken from anything the member sent. Rejecting a request returns the full amount and writes the refund to the ledger.
Four checks — account age, device fingerprint, 24-hour earnings velocity, and whether the member's registration, withdrawal and conversion IPs agree — summarised as one label next to the approve control.
A pending queue, a full history with per-admin filtering, and batch approval grouped by payout address for when you are paying many members to the same destination.
Crypto rates can be pulled from a spot-price feed on the scheduler, and an exchange rate can be set per payout method. The rate refresh is a separate scheduled job, so a spot feed going quiet does not stall a queue you are working through.
Registration is where a rewards site is won or lost, and money is where it is stolen. Four captcha providers, a throttle on every entry point, abuse controls behind switches, and a signed installer lock.
reCAPTCHA, hCaptcha, Cloudflare Turnstile and a built-in arithmetic captcha. The built-in one is on for registration out of the box, so you are protected before you configure anything. Remote verification fails closed.
Login at five a minute, registration at three, two-factor at five, coupon redemption at ten, and per-provider postback limits keyed on both the network and the source IP. A forwarded header cannot spoof the IP a limit is counted against.
Single-account-per-IP, device-fingerprint blocking, country blocking, VPN and proxy detection through an IP-quality provider, and automatic banning of duplicate accounts. All off until you turn them on, and all keyed to a provider key you supply.
The installer writes a lock bound to your application key and database identity. A missing or forged lock does not expose the installer; the application checks the database and fails closed, and a repair command is included.
A real TOTP implementation. The QR code is generated on your own server, so the secret is never sent to a third party. Required at cashout once a member has enabled it.
A twelve-character minimum, with optional complexity and breach checks. Banned email domains and offer keywords are both configurable.
Support attachments and withdrawal documents are written outside the public web root and served only through a permission-checked, rate limited route.
Error pages are tested not to leak paths, keys or stack traces, and admin responses are marked non-cacheable so a shared browser cannot read an admin screen out of its cache.
The screen you will live in. Roles and permissions, per-network reporting, a redacted postback log, the page and email editors, and a scheduler screen that prints the exact commands to run.
Administrator, staff and member. Staff accounts get a named permission list, every sensitive screen re-checks it at the point of the write rather than only on load, and admin responses are marked non-cacheable.
A dashboard, offer analysis, per-network conversion reporting, a redacted postback log, an error-log viewer, and a member view showing every transaction, withdrawal, login and commission.
A page editor, an announcement marquee, a navbar-button manager, an ad rotator, twelve email templates with editable variables, and a send log. Four shortcodes expand the site name, domain, email and URL wherever content is written.
The admin prints the exact scheduled commands to run, with your token filled in, for offer sync, pending-offer settlement, leaderboard payouts, level recomputation and crypto rate refresh.
Site name, logo, small logo, favicon, loading image, social share image, meta description and keywords, nine social links, and raw code injection into the head and footer. The React app ships pre-built, so there is no build step to run.
A translation table with a language manager and RTL support, so every UI string is editable without a deploy. A public community page and a member chat sit behind admin switches, which makes the site more than a task list. English ships populated.
Two complete member storefronts, five social sign-ins, and a member lifecycle that handles verification, privacy and self-service deletion. Pick the theme in the admin; it is one setting, not a rebuild.
A React single-page app and a classic Blade and Livewire theme, both covering the whole member experience. The React theme is the default; switching is one setting.
Google, Facebook, Twitter, Discord and Telegram, each behind its own toggle and credentials. All ship disabled with blank keys.
Login history with IP and country, email and TOTP verification, a public-profile privacy toggle, and self-service account deletion that anonymises retained financial rows.
The same member experience is available over REST, authenticated by Sanctum — a session for the web client, a bearer token for a native one. One response envelope throughout, so a client never has to guess which shape it got.
A translation table and a language manager with right-to-left support. Every UI string is editable without a deploy, and the English set ships populated with 462 keys.
Every step below is a real code path, and every one of them writes to the same ledger.
Captured from the release. Filter by area, then select any image to open it full size.
Names, balances and offer artwork visible in these captures are demo data from a seeded installation. Your installation starts with no members, no offers and no ledger history.
Standard Laravel and MySQL, with a pre-built frontend. Nothing exotic to host.
The operator's path, then the member's.
Point a vhost at the release, make the storage directory writable, and open the site. A six-step installer checks the server, writes the environment file, imports the schema and creates your administrator account.
Site name, logo, favicon, social image, meta tags, social links and theme choice, all from the admin. Then send yourself a test offer to prove the loop works before you invite anyone.
Create a provider record, paste in your credentials, copy the postback URL into that network's dashboard, and let the activation check tell you the connection is verifiable.
Turn on catalogue sync for the networks that support it, or add offers by hand. Toggle each one active when you are ready for members to see it.
Flip the registration switch, point your mail transport at a real server so verification codes send, and let members in. The captcha is already on.
Wire the commands from the admin's scheduler screen into your cron. Offer sync, pending settlement and leaderboard payouts all depend on them running.
Checked automatically by the installer, which will not continue until they pass.
| Requirement | Detail |
|---|---|
| PHP | 8.2.0 or newer |
| Extensions |
openssl, pdo, pdo_mysql,
mbstring, tokenizer, xml,
ctype, json, bcmath,
fileinfo, curl, and
gd or imagick
|
| Writable paths | The project root, the storage directory and the bootstrap cache directory |
| Database | MySQL, reachable with the credentials you enter in the installer |
| Web server | Anything that can serve a Laravel application, with .htaccess support if you use Apache. An IIS configuration file ships with the release. |
| Cron | Required — offer sync, pending settlement, leaderboard payouts and rate refreshes are HTTP jobs you schedule |
| Outbound HTTPS | Required to reach offer networks, captcha providers, OAuth endpoints and the IP-reputation service |
| A real transport is required to send verification codes and notifications. The installer's default writes mail to a log file instead. | |
| Node.js | Not required. The React storefront ships pre-built. |
This is the buyer documentation set, written against this release and versioned with it. It is included in the archive you receive.
Introduction, installation, requirements, configuration, the full environment reference, deployment, and a troubleshooting guide.
Core features end to end, the rewards mechanics, offerwalls and all 23 postback parsers, and payments and cashout.
The admin guide, every settings screen, social login and captcha setup, the member guide, and a verification checklist to run before launch.
The API reference, customization and branding, legal and data handling, a changelog, and an honest FAQ.
Plain statements, including the parts that are limited.
You receive the complete source code and the right to run it on a server you control and modify it for your own operation.
The product is sold as a regular licence for a single installation. You cannot resell or redistribute the source as a competing product. The full terms are presented and accepted during installation, so they are recorded on your own instance as well as here.
You get an upgrade guide and a changelog, and the source is yours to maintain. The release is built from committed source rather than from a vendor's working copy, so the archive you hold matches the documented version.
Future releases are a commercial question for the vendor at the point of purchase. This page does not promise a lifetime update commitment, because none has been contracted.
HansalDev provides support on a commercial basis, and you can raise a request through the contact form before or after purchase.
This page deliberately makes no response-time or 24/7 availability promise. The shipped documentation says the same thing: no support policy, response time, channel or contact has been committed, so none is quoted here.
Answered from what the release actually does.
A single Regular licence. No per-member fees and no revenue share to us.
One commercial licence for one installation. The full Laravel application, both member themes, the admin panel, the schema and 23 pages of documentation.
$99.00
$
85
USD one-time
One-time payment. Taxes, if any, are added at checkout. The archive is delivered against your order, and the licence is presented and accepted again during installation so it is recorded on your own instance.
None of this is held back from you deliberately — it is not yours to resell, and some of it can only be issued to you personally.
No default administrator credentials and no demo content ship with the release. The schema has an empty user table, an empty offer catalogue and an empty ledger; your administrator is created during installation with a twelve-character password minimum, and a release test asserts that no credential value is present in the seed.
You pay once for the source. There is no per-member charge, no revenue share to us, and no subscription to renew.
The licence covers one site you operate. Running several public instances is outside it, and that question is easier settled before you buy.
The source is yours to host, modify and maintain. Future releases are a commercial question with the vendor.
Offerwall & App Monetization Platform
Monetise your website or app with offerwall and content-locker integrations, postback tracking and monthly payout invoices.
Get the source code, install it, connect a network you already have an account with, and start earning from your own traffic.