social network v1.0.0

flkahf php script

flkahf

Get a license
📦

About flkahf php script

OpenSocial — Full Platform Description
A production-ready, self-hosted social networking script with real-time messaging, voice & video calling, marketplace, and a full admin console.

________________________________________

🎯 What It Is
OpenSocial is a complete, deployable social networking platform built in pure PHP 8 + MySQL. It runs on any shared host with cPanel — no Docker, no Node.js, no external services required. Out of the box it delivers a modern feed, direct messaging, voice/video calls, groups, pages, marketplace, ads, jobs, wallet, reels, and a full admin console with per-user controls.
Live deployment: flkahf.net
________________________________________
✨ Feature Overview
📰 Social Feed
• Hot algorithmic feed with trending hashtags, suggested users, and a reels strip
• Post types: text, image, video, audio, file attachment, reposts, quotes
• Rich text via Quill editor — headlines, lists, links, code blocks, colors
• Inline comments, reactions (👍 ❤️ 😂 😮 😢 😡), shares, bookmarks
• Post visibility controls — public, friends-only, private
• Pinned posts, featured posts, scheduled posts (with cron publishing)
• 4D hover effects, glass-morphism UI, dark mode by default
• Infinite-scroll-ready with grid/list view toggle
• Full mobile responsive down to 320px
💬 Direct Messenger
• Real-time via Server-Sent Events — no polling, no WebSocket server
• Typing indicators, read receipts (✓ / ✓✓), message reactions
• Edit and delete messages with history
• Reply-to threading
• File, image, video, and audio attachments
• Emoji picker with a full Unicode set
• In-conversation search
• Scroll-to-bottom with new-message counter
• Pin / Mute / Archive / Delete conversations
• Presence indicator (online/offline)
• Cross-tab coordination via BroadcastChannel
📞 Voice & Video Calling
• LiveKit support (self-hosted or cloud) as the primary provider
• Jitsi Meet fallback for zero-config setup
• Automatic failover — if LiveKit fails mid-call, falls back to Jitsi without user interaction
• Server-side JWT signing for LiveKit tokens
• Picture-in-picture self-view with mirror mode
• Screen sharing
• Ring timeout, call duration limits, call history
• Missed / declined / ended states written back into the chat stream
• In-iframe call UI, works inside the messenger without a page reload
• Cross-tab aware: a call rings in only one tab
• 3-second incoming call detection via poll + SSE dual path
• STUN / TURN configuration from the admin panel
👥 Groups & Pages
• Public / private / secret groups
• Group invites with expiry and max uses
• Word filters, member bans, moderation roles
• Group analytics — posts, members, bans, chat volume
• Custom group avatars and cover images
• Page system for brands and creators
🛒 Marketplace
• Product listings with images, variants, inventory
• Seller storefronts
• Buyer / seller chat integration
• Order lifecycle: pending → paid → shipped → delivered → completed
• Buyer reviews and ratings
• Sales dashboard for sellers
💼 Jobs Board
• Job postings by employers
• Applications with resume upload
• Provider/seeker profiles
• Application status tracking
💳 Payments & Wallet
• Internal wallet system with balances
• Credit / debit with full transaction ledger
• PaymentRouter architecture supporting multiple gateways
• Manual payment confirmation for bank transfers
• Order funding, refunds, and dispute handling
• Multi-currency support
🎬 Reels / Short Video
• Vertical video feed
• View / like / share counters
• Report moderation queue
• Upload with automatic thumbnail generation
📢 Ads System
• Self-service ad campaign creation
• Ad slots: feed top, feed mid, feed bottom, sidebar
• Impression and click tracking
• Targeting by placement and audience
• Budget and schedule controls
• Funded from the wallet
________________________________________
🛠 Admin Console
Full control panel with a slide-out drawer and 15+ tabs.
Dashboard
Live counters for users, posts, comments, reactions, groups, pages, files, orders, jobs, ads, marketplace revenue, and collected payments.
User Management (advanced)
• Searchable, filterable, paginated user list — filter by role, verification, ban status
• Bulk actions: verify, unverify, ban, unban, tag, delete (multi-select)
• Per-user detail page with:
o Profile editor (avatar, username, display name, email, bio, language)
o Role management (user / moderator / admin)
o Email verification toggle
o Password reset (random or manual)
o Ban with reason and expiry
o Login-as (impersonation) — view the site as any user, with an orange warning banner and a "Stop" button; every action is audited
o 2FA toggle per user
o Login-as permission toggle
o Private admin notes
o Custom tags (VIP, trusted, spammer…)
o Wallet credit / debit
o IP history with geolocation and VPN/proxy/TOR flags
o Active sessions with per-session kill
o Recent activity from the audit log
o Force logout everywhere
o Delete user with content orphaning
• CSV export of the entire user base with all metadata
Content Management
• Posts: create, edit, delete, moderate
• Content blocks (CMS pages) with Quill editor
• Files: browse by category, view previews, delete with disk cleanup
• Groups: full control panel with details, appearance, members, moderation, invites, analytics
Commerce
• Payments: filter by status, mark paid, fail, refund
• Gateways: configure payment providers
• Orders: full order lifecycle management
• Marketplace: products, sellers, disputes
• Ads: campaigns, impressions, clicks
System Settings
• Upload permissions (executables, archives, documents, media)
• Max upload size
• Rich text on/off
• Maintenance mode with custom notice
• Meeting settings (Jitsi)
• Call provider settings (LiveKit / Jitsi / both)
• STUN / TURN servers
• Storage driver (local / S3-compatible)
• Social login providers (Google, Facebook, GitHub, LinkedIn, Apple, TikTok, Discord, Microsoft, X)
• Translations
• Full audit log
Security Tools
• IP log with geolocation, ISP, VPN / proxy / TOR flags
• Login attempts history with country, user agent, failure reason
• Active sessions with the ability to kill any session
• IP blocklist with automatic brute-force banning
• Manual IP blocking with reason and duration
• Trusted proxy configuration for Cloudflare / nginx
• Configurable brute-force thresholds
________________________________________
🔐 Security
• CSRF protection on every POST endpoint
• Prepared statements everywhere — zero SQL injection vectors
• Password hashing with bcrypt and automatic rehash on login
• Session regeneration on login, remember-me tokens with SHA-256 hashes
• Rate limiting — session-based and per-IP
• Brute-force auto-banning after configurable failures
• IP geolocation with VPN / proxy / TOR detection
• HTML escaping on all output (XSS prevention)
• File upload validation with MIME type checking and extension whitelist
• Admin impersonation with an unmissable banner and full audit trail
• Per-user 2FA toggle (ready for TOTP implementation)
• Security headers and HTTPS enforcement
• Trusted proxy awareness — client IP resolution behind Cloudflare, nginx, or any reverse proxy
________________________________________
🏗 Technical Architecture
Layer Tech
Backend PHP 8.0+ (works on 7.4 with minor tweaks)
Database MySQL 5.7+ / MariaDB 10.4+
Web server Apache, nginx, LiteSpeed — anything that runs PHP
Sessions DB-backed with file fallback (no Redis required)
Real-time Server-Sent Events (SSE) — no WebSocket daemon
Calls LiveKit Cloud / self-hosted + Jitsi fallback
Uploads Local disk or any S3-compatible service (AWS, DO Spaces, Wasabi, Backblaze B2, Cloudflare R2, MinIO)
Frontend Vanilla JavaScript, no build step, no npm required
Styling Hand-written CSS with CSS variables, dark mode first
Editor Quill 2 (rich text)
Icons Emoji + inline SVG — no icon fonts
No Composer required. No npm. No build toolchain. Upload and it runs.
________________________________________
📦 What's Included
• Complete source code — PHP, CSS, JavaScript
• SQL schema with self-healing migrations
• Admin console with 15+ tabs
• Full messenger with calls
• LiveKit + Jitsi integration
• Payment gateway framework
• IP tracking and security suite
• Social login for 9 providers
• Reels, marketplace, jobs, ads modules
• Documentation and inline code comments
• Free updates for 12 months
• 6 months of support
________________________________________
🚀 Why OpenSocial
Deploy in 10 minutes
Upload the files, create a MySQL database, run one SQL script. Everything else auto-configures.
Runs on $5/month hosting
No Node.js, no Docker, no Redis, no WebSocket server. Any shared host with PHP 8 and MySQL will run this.
Real voice and video calling
Most "social network scripts" fake it — they embed a Jitsi iframe and call it done. OpenSocial runs a real LiveKit stack with JWT tokens, adaptive streaming, simulcast, and screen sharing, and falls back to Jitsi automatically when LiveKit isn't configured.
Full admin control
Not just a list of users. Per-user detail pages with IP history, sessions, wallet, notes, tags, ban management, impersonation, and bulk actions. You run a platform, not a blog.
Sell-ready from day one
The ads system, wallet, marketplace, and payment router are all wired. You can monetize on day one without writing a line of code.
Modern UI
Glass-morphism, gradient accents, 4D hover effects, neon glow, emoji-rich design language. Looks like a 2026 product, not a 2015 template.
Actively maintained
Built from real production experience. Every edge case (missing tables, absent columns, no LiveKit credentials, blocked IPs) is handled gracefully. The site never crashes to a white screen — every error path returns a user-visible message.
________________________________________
📊 Feature Comparison
Feature OpenSocial Typical competitor
Real-time messenger ✅ SSE ⚠️ Polling only
Voice calls ✅ LiveKit + Jitsi ❌ or ⚠️ iframe only
Video calls ✅ LiveKit + Jitsi ⚠️ iframe only
Screen share ✅ ⚠️ rare
Self-view PiP ✅ ❌
Auto-failover call provider ✅ ❌
Impersonation ("login as") ✅ ⚠️ rare
Per-user 2FA ✅ ⚠️ rare
IP geolocation + VPN detection ✅ ❌
Brute-force auto-ban ✅ ⚠️ rare
Bulk user actions ✅ ❌
Wallet system ✅ ⚠️ rare
S3-compatible storage ✅ ⚠️ rare
Social login (9 providers) ✅ ⚠️ 2-3 usually
Marketplace ✅ ⚠️ sometimes
Jobs board ✅ ❌
Ads system ✅ ⚠️ rare
Reels ✅ ⚠️ rare
CSS framework dependency ❌ None ⚠️ Bootstrap / Tailwind
Build step required ❌ None ⚠️ Usually npm
Node.js required ❌ No ⚠️ Sometimes
________________________________________
🎯 Who It's For
• Entrepreneurs launching a niche social network (fitness, gaming, religion, education, diaspora)
• Agencies delivering community platforms to clients on tight budgets
• Developers who want a mature starting point rather than building auth + feed + messenger from scratch
• Communities migrating off Facebook groups into an owned platform
• Creators building a subscriber-only space with marketplace and paid calls
________________________________________
💡 Roadmap (included free in the next 12 months)
• Web Push notifications
• Full notifications system (bell icon, live updates)
• Creator subscriptions with recurring billing
• Video recording of calls (LiveKit Egress)
• Live streaming
• Polls in posts
• Events with RSVP
• Stories with 24h expiration
• PWA with offline mode
• Full-text search with ranked results
________________________________________
🛡 Support & Licensing
• License: Regular (1 site) and Extended (unlimited sites)
• Support: 6 months included, extendable
• Updates: 12 months of free updates
• Documentation: Installation guide, configuration guide, troubleshooting
• Compatibility: PHP 8.0 – 8.3, MySQL 5.7+, MariaDB 10.4+
• Included extras: SQL migration scripts, sample .htaccess for nginx and Apache
________________________________________
📞 Get Started
Drop the files into public_html, import the SQL, edit config.php with your DB credentials. You're live.
Demo: flkahf.net
Admin demo: demo.flkahf.net/admin.php (credentials provided on request)
________________________________________

Ready to use flkahf php script?

See pricing