Skip to content

Release 3.2.1 · Laravel 12 on PHP 8.2+

Launch your own rewards and offerwall platform in minutes

A self-hosted rewards business, in full. Members earn coins from offerwalls, streaks, a spin wheel, tasks and leaderboards, then request a cashout that you review and pay. You get the member storefront, the admin panel, the offer-network plumbing and the money ledger — as source code, with no vendor between you and your own balance.

  • Regular licence, single installation
  • 23 offer-network parsers, 2 member themes, 33 admin permissions
  • One-time payment — no per-member fees, no revenue share
VibeCash · Member
The VibeCash member dashboard showing balance, earn ways and featured offers

Why buyers pick this over a starter package

Full unencrypted source Laravel app, both themes, admin panel and schema. No encoder, no lock-in.
23 offer networks wired One signed parser each. Six can sync their catalogue on a schedule.
Fraud controls in the box Captcha, throttles, device fingerprinting, VPN and proxy detection.
Reviewed cashout queue Fees recalculated server-side, a risk panel, and an audit trail.

What ships in the box

46 tables in the shipped schema
23 offer-network postback parsers
33 admin permissions across three roles
359 automated test methods in the suite
2 complete frontend themes included
12 PHP extensions the installer verifies
73 admin settings keys
4 captcha providers, one enabled by default

Counts are of the files and schema in the release you receive. Offer-network accounts, payout accounts and mail credentials are deliberately not included — you supply your own.

Live Demo

Walk it before you buy it

The demo is the product on a public domain, seeded with sample data so every screen has something in it. Register an account, claim the daily bonus, spin the wheel, and open the offers.

  • The React member storefront, which is the default theme on a fresh install.
  • The earn ways: offers, offerwalls, surveys, streak, tasks and referrals.
  • The registration flow, including the built-in captcha that is on by default.
  • The classic Blade and Livewire theme is in the package too, if you prefer it to the React app.
Open the live demo

There are no demo credentials to hand out. The release ships an empty user table on purpose, so register your own account in the demo — which is also the fastest way to see the captcha and the verification step working. The demo is a shared environment: its balances, members and offers are not yours, and nothing on it is a promise about earnings.

vibecash.hansaldev.com
The VibeCash referral screen showing commission tiers and a member referral link
The Problem

A rewards site is a money system, not a landing page

The members see coins and a spin wheel. You are running a ledger.

Money has to be right

A conversion, a streak bonus and a cashout all touch the same balance. If two requests can credit it at once, or a rejection does not claw the money back, the ledger drifts and never recovers.

Anyone can sign up and claim

Farming is the default failure mode. Registration needs a captcha, a throttle, and enough friction that a scripted signup is not cheaper than a real member.

Every offer network speaks differently

Each network posts conversions back with its own parameter names and its own signature scheme. Each one is a separate parser to write, and an unsigned parser is a way to mint coins from the internet.

Paying out is the part you cannot automate on day one

You need a reviewed queue, a per-request fee calculation, an audit trail, and a decision about which accounts to pay.

Each of these is solved in the box, with the code in front of you rather than a vendor between you and your own balance.

Core Features

What the platform actually does

Grouped by the job each part of the system performs. Five tabs, and every card on this page is a shipped screen.

The core loop, and the mechanics that bring a member back tomorrow. Build an offerwall business, a daily-habit product, a gamified site, paid tasks and promo campaigns off this one tab — each mechanic has its own admin screen and writes its own ledger row.

The coin ledger

One balance to eight decimal places, and a transaction row for every movement with its type, source, running balance and reference. Eight decimal places is not decoration: it is what stops a fractional reward from being rounded into a comparison error.

23 postback parsers

One endpoint, /api/postback/{endpoint}, dispatches to the parser for the network that owns it. Each parser implements that network's own signature: MD5 and SHA-256 hashes, HMAC-SHA1, a signed query string, a password comparison, or a source-IP allowlist.

A provider cannot be activated unsafely

Each network declares which credential its parser actually reads. If that credential is blank, the network is refused at the save step and at the callback, before the parser runs — on the credit path and on the clawback path both. One network has no verification at all and cannot be activated by design.

Postback URL templates per network

The admin screen prints the exact postback URL for each connected network with its macro list, ready to paste into that network's dashboard.

A postback simulator

Fire a synthetic conversion at any of your connected networks from the admin, with a chosen member, reward and status. You can prove an integration works without waiting for real traffic.

Catalogue sync for six networks

Six of the networks can have their offer list pulled in on a schedule. The sync refuses to delete a catalogue when the upstream response is too small to be real, so an outage cannot wipe your offers.

Offer management

Toggle fetched offers on and off, and create your own offers against any connected network. Filter by country, device and category.

Daily login streak

Seven escalating rewards, claimed once a day. The claim is re-checked inside a row lock, so a double-click cannot pay twice.

Daily challenges

Rules on either earnings or completed offers, claimable once each per day. Six are seeded and every one is editable.

Spin wheel

A weighted wheel drawn from a cryptographically secure source, once a day, with a five-times wedge once the streak is complete. Wedge values and weights are yours to configure; the total weight must equal 100.

Mini tasks with review

Dynamic per-task submission fields, image uploads stored outside the public web root, and an approve-or-reject decision. Rejection after approval takes the reward back.

Levels from XP

XP accrues on credited income and a level-up pays a bonus. The threshold and the bonus are set in code, so you can adjust them to fit your own economy.

Leaderboards

Daily and monthly tables by earnings, with the prize for each placing set as a tier. Six tiers ship seeded, and the payouts run from the scheduler rather than from a page load.

Coupon campaigns

Single-use-per-member codes with an expiry and a global redemption cap, for launches, partners and newsletters. Disabled until you enable it, and redemption is rate limited so a brute-forced code cannot drain a balance.

Referral programme

Three commission tiers seeded at 3%, 5% and 7% at 1, 25 and 200 referrals, every tier editable and the whole programme behind one switch. Commission is a share of the referred member's offer earnings, paid on each credited conversion, and a referred member starts on a higher opening balance than one who arrives cold.

Referral commission is single-level. It is not paid on streak bonuses, spin wins, task approvals or leaderboard prizes, and there is no second tier of referrers. Both limits are stated because nothing inside the product states either of them, and a buyer reading the marketing shorthand would assume multi-level. Stated here because nothing inside the product says it

Everything between a member asking for money and you paying it: methods you define, a fee the server recalculates, a risk panel beside the approve button, and a queue that records who decided what.

Methods you define

Each method carries its own minimum, maximum, fixed fee, percentage fee, exchange rate, currency, payout delay, and the exact fields a member must supply. Four are seeded and all four ship disabled.

Fees recalculated on the server

The amount leaves the balance when the request is made, and the fee is recalculated from the locked method record at that moment, not taken from anything the member sent. Rejecting a request returns the full amount and writes the refund to the ledger.

A risk panel on every request

Four checks — account age, device fingerprint, 24-hour earnings velocity, and whether the member's registration, withdrawal and conversion IPs agree — summarised as one label next to the approve control.

Queue and batch approval

A pending queue, a full history with per-admin filtering, and batch approval grouped by payout address for when you are paying many members to the same destination.

Crypto rates, refreshed

Crypto rates can be pulled from a spot-price feed on the scheduler, and an exchange rate can be set per payout method. The rate refresh is a separate scheduled job, so a spot feed going quiet does not stall a queue you are working through.

Cashout is processed by you, not by the software. VibeCash has no automated payout adapter for any provider — no Stripe, no PayPal, no Paystack. The four seeded methods are described in the product as manual payouts, and that is accurate: the software calculates the fee, holds the balance, queues the request and audits it, then an admin approves and pays out of band. Writing an adapter for your own provider is a development task. Stated here because nothing inside the product says it

Registration is where a rewards site is won or lost, and money is where it is stolen. Four captcha providers, a throttle on every entry point, abuse controls behind switches, and a signed installer lock.

Four captcha providers

reCAPTCHA, hCaptcha, Cloudflare Turnstile and a built-in arithmetic captcha. The built-in one is on for registration out of the box, so you are protected before you configure anything. Remote verification fails closed.

Throttles on every entry point

Login at five a minute, registration at three, two-factor at five, coupon redemption at ten, and per-provider postback limits keyed on both the network and the source IP. A forwarded header cannot spoof the IP a limit is counted against.

Abuse controls behind switches

Single-account-per-IP, device-fingerprint blocking, country blocking, VPN and proxy detection through an IP-quality provider, and automatic banning of duplicate accounts. All off until you turn them on, and all keyed to a provider key you supply.

A signed install lock

The installer writes a lock bound to your application key and database identity. A missing or forged lock does not expose the installer; the application checks the database and fails closed, and a repair command is included.

Two-factor authentication

A real TOTP implementation. The QR code is generated on your own server, so the secret is never sent to a third party. Required at cashout once a member has enabled it.

Password and account policy

A twelve-character minimum, with optional complexity and breach checks. Banned email domains and offer keywords are both configurable.

Uploads outside the web root

Support attachments and withdrawal documents are written outside the public web root and served only through a permission-checked, rate limited route.

Errors do not leak

Error pages are tested not to leak paths, keys or stack traces, and admin responses are marked non-cacheable so a shared browser cannot read an admin screen out of its cache.

The screen you will live in. Roles and permissions, per-network reporting, a redacted postback log, the page and email editors, and a scheduler screen that prints the exact commands to run.

Three roles, 33 permissions

Administrator, staff and member. Staff accounts get a named permission list, every sensitive screen re-checks it at the point of the write rather than only on load, and admin responses are marked non-cacheable.

Reporting and diagnostics

A dashboard, offer analysis, per-network conversion reporting, a redacted postback log, an error-log viewer, and a member view showing every transaction, withdrawal, login and commission.

Content and communication

A page editor, an announcement marquee, a navbar-button manager, an ad rotator, twelve email templates with editable variables, and a send log. Four shortcodes expand the site name, domain, email and URL wherever content is written.

Scheduler screen

The admin prints the exact scheduled commands to run, with your token filled in, for offer sync, pending-offer settlement, leaderboard payouts, level recomputation and crypto rate refresh.

Rebranding from the admin

Site name, logo, small logo, favicon, loading image, social share image, meta description and keywords, nine social links, and raw code injection into the head and footer. The React app ships pre-built, so there is no build step to run.

Languages and community

A translation table with a language manager and RTL support, so every UI string is editable without a deploy. A public community page and a member chat sit behind admin switches, which makes the site more than a task list. English ships populated.

Scheduled work is done over HTTP, not by a Laravel scheduler. The admin prints the exact commands, each authenticated with a token generated at install time. The endpoint fails closed with a 503 if that token is not set, so a missing token cannot turn it into a public endpoint. Verified in VerifyCronToken and the scheduler screen

Two complete member storefronts, five social sign-ins, and a member lifecycle that handles verification, privacy and self-service deletion. Pick the theme in the admin; it is one setting, not a rebuild.

Two complete member storefronts

A React single-page app and a classic Blade and Livewire theme, both covering the whole member experience. The React theme is the default; switching is one setting.

Email and five social sign-ins

Google, Facebook, Twitter, Discord and Telegram, each behind its own toggle and credentials. All ship disabled with blank keys.

Member lifecycle

Login history with IP and country, email and TOTP verification, a public-profile privacy toggle, and self-service account deletion that anonymises retained financial rows.

A versioned JSON API

The same member experience is available over REST, authenticated by Sanctum — a session for the web client, a bearer token for a native one. One response envelope throughout, so a client never has to guess which shape it got.

Multilingual, with RTL

A translation table and a language manager with right-to-left support. Every UI string is editable without a deploy, and the English set ships populated with 462 keys.

There is no colour picker. Branding covers identity and assets, not palette. Changing colours means editing the theme's CSS. Two smaller limits worth knowing: the web app manifest is not editable from the admin, and the English string “VibeCash” appears literally in the seeded translations, so a full rebrand should include a pass over the language table. Verified against the admin settings allowlist and the schema
The Solution

The earning loop, end to end

Every step below is a real code path, and every one of them writes to the same ledger.

  1. 1 A member registers. Email, or one of five social providers. A captcha is required on registration by default, and a referred member starts on a higher opening balance than one who arrives cold.
  2. 2 You connect offer networks. Each one is a provider record with your credentials and a postback URL you paste into the network's dashboard. Six of them can also sync their catalogue on a schedule.
  3. 3 The member browses offers. Filtered by their country and device, with offers they have already completed removed from their list.
  4. 4 A click is recorded. A tracking row ties the offer, the member and the network together so the return can be matched.
  5. 5 The network posts the conversion back. The parser for that network verifies its signature, the click is matched, and the transaction is written. A repeated transaction ID is refused.
  6. 6 The member is credited. Either immediately, or held as pending if it is over your auto-pay threshold, and settled later by your scheduler.
  7. 7 Other earnings stack on top. Streak bonus, daily challenges, the spin wheel, approved tasks, leaderboard placing, coupons and referral commission, each writing its own ledger row.
  8. 8 The member requests a cashout. Fees are recalculated server-side, the amount leaves the balance at request time, and an admin is notified.
  9. 9 You review and pay. The audit panel shows account age, device fingerprint, earnings velocity and IP geography. You approve, or reject and the balance is returned.
Product Tour

Every screen, as it ships

Captured from the release. Filter by area, then select any image to open it full size.

Names, balances and offer artwork visible in these captures are demo data from a seeded installation. Your installation starts with no members, no offers and no ledger history.

Technical Details

The stack, as shipped

Standard Laravel and MySQL, with a pre-built frontend. Nothing exotic to host.

Laravel 12on PHP 8.2 or newer
MySQL46 tables, one SQL file
React SPA + Bladepre-built, no Node step
Livewireadmin, in both themes
REST APIversioned, Sanctum auth
359 testscovering the ledger and parsers
Six-step installerchecks the server, writes the env
Named rate limiterson every entry point
How It Works

From purchase to your first payout

The operator's path, then the member's.

Install it

Point a vhost at the release, make the storage directory writable, and open the site. A six-step installer checks the server, writes the environment file, imports the schema and creates your administrator account.

Brand it

Site name, logo, favicon, social image, meta tags, social links and theme choice, all from the admin. Then send yourself a test offer to prove the loop works before you invite anyone.

Connect a network

Create a provider record, paste in your credentials, copy the postback URL into that network's dashboard, and let the activation check tell you the connection is verifiable.

Sync or add offers

Turn on catalogue sync for the networks that support it, or add offers by hand. Toggle each one active when you are ready for members to see it.

Open registration

Flip the registration switch, point your mail transport at a real server so verification codes send, and let members in. The captcha is already on.

Run the scheduler

Wire the commands from the admin's scheduler screen into your cron. Offer sync, pending settlement and leaderboard payouts all depend on them running.

Requirements

What your server needs

Checked automatically by the installer, which will not continue until they pass.

Requirement Detail
PHP 8.2.0 or newer
Extensions openssl, pdo, pdo_mysql, mbstring, tokenizer, xml, ctype, json, bcmath, fileinfo, curl, and gd or imagick
Writable paths The project root, the storage directory and the bootstrap cache directory
Database MySQL, reachable with the credentials you enter in the installer
Web server Anything that can serve a Laravel application, with .htaccess support if you use Apache. An IIS configuration file ships with the release.
Cron Required — offer sync, pending settlement, leaderboard payouts and rate refreshes are HTTP jobs you schedule
Outbound HTTPS Required to reach offer networks, captcha providers, OAuth endpoints and the IP-reputation service
Mail A real transport is required to send verification codes and notifications. The installer's default writes mail to a log file instead.
Node.js Not required. The React storefront ships pre-built.

Before you buy, worth knowing

  • You need a server you control, and a cron you actually run.
  • You need your own account with at least one offer network, or the offerwall has nothing to show.
  • You need to decide how you will pay members out, because the software does not do it for you.
  • SSL is expected. Turn on the force-SSL switch once you have a certificate.
  • Configure a real mail transport before you open registration, or verification codes go nowhere.
  • The bundled GeoIP database covers country lookup. If you remove it, the app falls back to a plain HTTP geo service, so replace it before launch.
Documentation

23 pages, shipped in the box

This is the buyer documentation set, written against this release and versioned with it. It is included in the archive you receive.

Getting started

Introduction, installation, requirements, configuration, the full environment reference, deployment, and a troubleshooting guide.

Running the economy

Core features end to end, the rewards mechanics, offerwalls and all 23 postback parsers, and payments and cashout.

Operating it

The admin guide, every settings screen, social login and captcha setup, the member guide, and a verification checklist to run before launch.

Reference

The API reference, customization and branding, legal and data handling, a changelog, and an honest FAQ.

Online documentation. The documentation ships inside the release, so it travels with the code, and the same set is also published at https://vibecash.hansaldev.com/documentation. The bundled copy and the published copy are the same pages. Versioned with the release
Terms

Licence, updates and support

Plain statements, including the parts that are limited.

Licence

You receive the complete source code and the right to run it on a server you control and modify it for your own operation.

The product is sold as a regular licence for a single installation. You cannot resell or redistribute the source as a competing product. The full terms are presented and accepted during installation, so they are recorded on your own instance as well as here.

Updates

You get an upgrade guide and a changelog, and the source is yours to maintain. The release is built from committed source rather than from a vendor's working copy, so the archive you hold matches the documented version.

Future releases are a commercial question for the vendor at the point of purchase. This page does not promise a lifetime update commitment, because none has been contracted.

Support

HansalDev provides support on a commercial basis, and you can raise a request through the contact form before or after purchase.

This page deliberately makes no response-time or 24/7 availability promise. The shipped documentation says the same thing: no support policy, response time, channel or contact has been committed, so none is quoted here.

Contact HansalDev

FAQ

Questions a technical buyer asks

Answered from what the release actually does.

Yes, in full. The Laravel application, the React storefront source, both themes, the admin panel and the schema. The only minified third-party asset is one file in the offer-delivery module.

Point your vhost at the release, make the storage directory writable, and open the site. A six-step installer checks PHP and the twelve required extensions, writes the environment file, imports the schema and creates your administrator account. No command line is needed to complete the install.

PHP 8.2 or newer with twelve specific extensions, MySQL, three writable paths, working outbound HTTPS, and a cron you actually run. Node.js is not required because the frontend ships pre-built.

Create a provider record in the admin and paste in the credentials from your account with that network. The admin then prints the postback URL for that provider, which you copy into the network's own dashboard. The activation check refuses to enable a provider whose verification cannot be performed.

The network posts to a single endpoint that dispatches to the parser for that network. Each parser implements that network's own signature scheme. A conversion is matched to the recorded click, a repeated transaction ID is refused, and every attempt is written to a log with its credentials redacted.

Not by leaving a provider unconfigured. Each provider declares which credential its parser actually reads, and a provider with no verifiable credential is refused at both the save step and the callback, on the credit path and the clawback path. One network has no verification at all and cannot be activated by design.

No, and this page will not imply otherwise. There is no automated payout adapter for any provider. What ships is a payout method editor: you define each method with its own limits, fees, exchange rate and the fields a member supplies, and the software calculates the fee, holds the balance, queues the request and audits your decision.

By you. The software calculates the fee, holds the amount from the balance, queues the request with a risk panel beside the approve control, and records the decision. There is no automated payout adapter for any provider, so paying out is a manual step. The four seeded methods are described as manual payouts and that is accurate.

No, and this page will not claim it does. Referral is single-level: a percentage of the referred member's offer earnings, at one of three tiers that rise with how many members you have referred. There is no second tier of referrers.

An advisory panel, not an automatic block. It reports account age, device fingerprint, 24-hour earnings velocity and whether the member's registration, withdrawal and conversion IPs agree, and summarises them as one label. Approval remains your decision.

Site name, logo, favicon, loading image, social share image, meta tags, social links, and head and footer code injection are all admin settings, and the site name, domain, email and URL expand as shortcodes in your content. Colours are not an admin setting; changing the palette means editing the theme CSS.

No. The React storefront is pre-built and shipped as hashed bundles, so deployment is a file copy. Both the React theme and the classic Blade and Livewire theme are included, and the active one is a single setting.

Yes, 23 pages, versioned with the release: installation, requirements, configuration, environment, deployment, core features, rewards, offerwalls and all 23 parsers, payments, admin, admin settings, social login and captcha, the API reference, customization, the member guide, legal and data handling, troubleshooting, a verification checklist, a changelog and an FAQ.

Four captcha providers including a built-in one that is on for registration by default, throttles on login, registration, two-factor, coupon redemption and per-provider postbacks, and switches for single-account-per-IP, device-fingerprint blocking, country blocking, VPN and proxy detection, and automatic duplicate-account banning. All of the switches ship off, and the reputation-driven ones need an API key you supply.

No, and that is deliberate. The schema ships with an empty user table and the release tooling fails the build if a credential appears in the seed. Your administrator is created during installation, with a twelve-character password minimum. The same is true of the live demo, which is why there are no demo credentials listed above.

You get an upgrade guide and a changelog with the release, and the source is yours to maintain. Future releases are a commercial question for the vendor at the point of purchase. This page does not promise free lifetime updates, because no such commitment has been contracted.

Yes. The site-wide Refund Policy (linked in the footer) covers every product sold here: refund requests can be made within 14 days of the transaction date, with clear rules for what qualifies and what does not. Read it before you buy, and ask through the contact page if anything is unclear.

Support is available on a commercial basis and can be arranged before purchase. No response-time or 24/7 commitment is stated here, because none has been contracted. The shipped documentation takes the same position.

That is set by the offers you connect, the rates those networks pay and the traffic you bring. The product does not quote or guarantee a figure, and this page does not invent one. Your dashboard reports the actual figures for your own traffic.

The licence covers one installation. Running several separate public instances is outside it. If you need a multi-site arrangement, raise it with HansalDev before you buy.

The store listing carries version 3.2.1, which is the version the documentation set is written against.
Pricing

One price, for the source code

A single Regular licence. No per-member fees and no revenue share to us.

Prerequisites

What you bring

None of this is held back from you deliberately — it is not yours to resell, and some of it can only be issued to you personally.

Not included in the price

  • Offer-network accounts. All 23 provider records ship disabled with blank credentials. You need your own accounts, and eligibility to receive offers from them.
  • Payout provider accounts, and an adapter for them. The four payout methods are manual templates. There is no automated payout integration to configure.
  • Social sign-in credentials. Five providers are wired and all five ship disabled with blank client IDs and secrets.
  • Captcha and IP-quality keys. The built-in arithmetic captcha works with no key. The three commercial captchas and the IP-reputation provider need your own accounts.
  • A hosted instance. You receive the application, not a running server. SSL and a real mail transport are yours to set up.
  • A colour or theme editor. Branding covers identity and assets. Palette changes mean editing CSS.
  • Custom development. The code is yours to extend; the package does not include bespoke feature work.
  • Any revenue, ranking or earnings promise. What members earn depends on the offers you connect, the networks' rates and the traffic you bring.
Open the live demo

No default administrator credentials and no demo content ship with the release. The schema has an empty user table, an empty offer catalogue and an empty ledger; your administrator is created during installation with a twelve-character password minimum, and a release test asserts that no credential value is present in the seed.

No recurring fee

You pay once for the source. There is no per-member charge, no revenue share to us, and no subscription to renew.

One installation

The licence covers one site you operate. Running several public instances is outside it, and that question is easier settled before you buy.

Yours to maintain

The source is yours to host, modify and maintain. Future releases are a commercial question with the vendor.

Also From HansalDev
Popular Save $49.00

Offerwall & App Monetization Platform

Preads

Monetise your website or app with offerwall and content-locker integrations, postback tracking and monthly payout invoices.

  • Version 2.4.0
  • Offerwall
  • Monetization
  • Publisher

Run your own rewards site

Get the source code, install it, connect a network you already have an account with, and start earning from your own traffic.

VibeCash — $85 one-time Regular licence · full source · 23 offer networks Demo Buy now
Copied