Flick Pro
Ship faster with production-ready services. Stop building auth, email, uploads, and database abstractions from scratch.
Get Flick Pro — $99 per year · every project you build
What's Included
Ten services you never have to build or babysit:
| Service | What You Get |
|---|---|
| Auth | Sessions, remember-me, password hashing, timing-safe verification |
| Checkout | Polar and Stripe hosted checkout plus webhook confirmation |
| SMTP, SES, SendGrid, Mailgun, Postmark + templates | |
| OTP | One-time codes for passwordless login, email verification, and two-factor |
| SQL | MySQL, PostgreSQL, SQLite + query builder + mass assignment protection |
| Throttle | Per-client rate limiting for logins, OTP sends, and form submissions |
| Upload | Image processing, WebP conversion, S3, DigitalOcean Spaces |
| Validation | Client-side rules synced with server-side validation |
| reCAPTCHA | Google reCAPTCHA v3 with score thresholds and action verification |
| Turnstile | Cloudflare's privacy-focused bot protection |
While you subscribe
New services and updates are included for as long as your subscription is active.
Quick Example
A complete contact form with email sending in under 20 lines:
<?php require 'vendor/autoload.php'; $form = new Flick\Flick([ 'services' => [ 'mail' => [ 'fromAddress' => 'noreply@example.com', 'mailer' => [ 'transport' => 'sendgrid', 'key' => 'your-sendgrid-api-key' ] ] ] ]); $form->create('Name, Email, Message|textarea'); if ($form->submitted()) { $request = $form->request('Name[required], Email[required, email], Message[required]'); if ($form->ok()) { $form->mail->sendFormData('admin@example.com', 'Contact Form', $request); $form->successMessage('Message sent!'); } }
Tip
Check ok() after request(), not before. Nothing has been validated until
request() runs, so submitted() && ok() is always true on a submission and would
mail out invalid data.
Installation
Already purchased? Here's how to get started.
1. Add the Repository
Add the private repository to your project's composer.json:
{ "repositories": [ { "type": "vcs", "url": "https://github.com/flickphp/pro" } ] }
2. Install the Package
composer require flickphp/pro
The repository is private, so the first time you run this Composer needs a way in. By default it goes through GitHub's API, so it stops and walks you through creating a personal access token with the repo scope. It saves that token in its own auth.json and won't ask again — once per machine.
It has to be the GitHub account you connected in your Polar customer portal after buying. That's the account with access.
Using an SSH key instead
If the machine already has an SSH key on your GitHub account, you can skip tokens entirely by telling Composer to install this one package from source:
{ "config": { "preferred-install": { "flickphp/pro": "source" } } }
That clones over SSH and never prompts. Scope it to flickphp/pro so everything else keeps installing from dist, which is faster.
Warning
On a server or in CI there's nobody to paste a token, and Composer won't fall back to SSH on its own — you'll get a flat 404 Not Found on the zipball URL that never mentions authentication. It's a missing token, not a missing package.
Put the token in place first with composer config --global github-oauth.github.com YOUR_TOKEN or the COMPOSER_AUTH environment variable, or use the preferred-install block above with a deploy key. You can also commit your vendor directory and skip the question entirely — the license allows it, and it's how you keep your copy after a subscription ends.
That's the whole setup. There's no key to paste and no config file to create — if composer require worked, you're done.
License
Use it on every project you build, including client work. If a client wants to keep Pro after you walk away, they buy their own.
Every version released while your subscription is active is yours to keep. If you cancel, you stop getting new versions — you don't stop using the ones you already have, and nothing you've shipped needs touching. Your subscription pays for what comes next: new services, and keeping the whole thing working as PHP moves.
One thing worth planning for: access to the private repository ends with the subscription, and that's where composer installs from. Commit your vendor directory to your own private repo, or keep an archive of the release, so a later deploy can still find it.
Ready to go? Get Flick Pro.