Built by PHP Developers,
for PHP Developers
PHPcube is a native Zend Engine C extension for PHP source code protection and cryptographic licensing. It was built to solve a specific, practical problem: how do you distribute a commercial PHP application to clients who manage their own servers — without handing over your readable source code?
Why PHPcube Exists
The problem is straightforward: PHP is an interpreted language. When you hand a client a ZIP of your application, every line of your business logic — your pricing algorithms, your license checks, your proprietary integrations — goes with it in plain text. Anyone with server access can read it, copy it, or strip out your licensing entirely.
The existing solutions all had the same friction. ionCube and SourceGuardian are mature products, but they were slow to support PHP 8.4 and 8.5. Their encoding tools require uploading source code to a third-party web service — a hard no for many enterprise and agency workflows. Their pricing models charge per server rather than per project. Their licensing systems are opaque and difficult to automate in CI/CD pipelines.
PHPcube was built from scratch to address those gaps directly: a native C Zend extension that encodes locally, supports the latest PHP versions on release day, uses Ed25519 cryptographic licensing that works fully offline, and exposes a REST API so license issuance can be automated from any billing system.
Two tools in one product
The Encoder
A local CLI tool and PHP extension function set that encrypts your PHP files with AES-256-CBC + HMAC-SHA256. Runs on your machine or CI runner. Your source code never leaves your environment. Supports entire directories, selective file lists, or individual files.
The Loader + Licensing System
A native C Zend extension (phpcube.so) that installs on the client's Linux server. It verifies Ed25519-signed licenses, decrypts the PHP payload in RAM, and executes it — zero disk writes, zero network calls, fully offline. Domain lock, IP binding, and expiry dates are enforced cryptographically.
What we believe in
Your source code stays yours
Encoding happens locally. We never see your PHP files. Your intellectual property never touches our servers.
Honest technical claims
We don't use "unbreakable" or "100% secure" language. We describe what the system actually does and what its realistic threat model is.
Same-day PHP version support
When PHP releases a new version, we ship a compatible loader on the same timeline — not months later.
Direct developer support
You talk to the people who built it. No ticket queues, no outsourced support. WhatsApp and email, answered by the team.
Transparent pricing
Per-project pricing, not per-server. Monthly, yearly, or lifetime. No hidden activation fees or per-domain surcharges.
Try before you buy
Free 3-day trial with a working loader and one license quota. No payment required to evaluate the product against your real application.
How it's built
The cryptographic primitives (AES-256-CBC, SHA-256, SHA-512, Ed25519) are implemented as standalone C files with zero external library dependencies — no OpenSSL, no libsodium required on the target server.
Talk to the team
Questions about the product, a specific use case, or whether PHPcube fits your workflow? Reach out directly. We reply to every message.