One loader. Your script.
HWID, not keys.

Create a project, drop people into the database by injector name and HWID. The loader checks the machine — leaked keys don't exist.

How protection works
1

Inject

Buyer runs your generated loader. Nothing is added to the database on first inject.

2

HWID copied

The loader copies the machine HWID to clipboard — they paste it to bind after purchase.

3

API check

Every launch hits our API. Unknown or banned HWID = NO SUB. Script never loads.

4

Script or kick

If the slot is valid, the original script runs. Kick from the panel and they drop on next check.

FAQ

Yes. HookGuard is a modern, high-speed Luarmor alternative built for Roblox developers. It delivers HWID whitelist licensing, cloud Luau obfuscation, anti-dump canary traps, and custom UI loaders without brittle key systems.

Keys get dumped and shared. Access is bound to hardware plus injector name. There is nothing to leak.

No. Unknown HWID is not subscribed. You add clients in the database, or they buy and bind.

You receive 65% of each sale. Funds clear in 2 days, then sit on your available balance and can be withdrawn immediately.

Once every 7 days. After that they bind the new machine like a first-time buyer.

HWID, injector name, subscription and kick status. Unknown or banned machine never receives the script.

Public projects

Scripts from the community — ratings, likes, views.

— ₽

—

Activate HWID

  1. 1Copy the loader and inject it in Roblox.
  2. 2The loader copies your HWID. If you are not in the database it shows NO SUB.
  3. 3Paste that HWID here, press Check, then Bind.

Reviews

No insults or fake ratings. Break it — the review goes.

Only buyers can leave a review. One review per account.

U
—
@—
Plan
Free
Likes
0
Publications
0
Rating
—
Status
Active

Published scripts

Plans

Upgrade only. Pick 1 / 3 / 12 months — longer term = discount.

Free
0 ₽
Forever free
  • 5 loaders / month
  • 15 people slots
  • HWID loader
  • 1 public listing
Pro+
1739 ₽ / mo
  • 30 loaders / month
  • 300 people slots
  • Priority support
  • Dumper shields in loader

Extra slots

Add capacity on top of the plan.

+10
100 ₽
HWID slots
  • 10 extra HWID slots
  • Stacks on your plan
  • Applied instantly
+1
49 ₽
project slots
  • 1 extra project slot
  • Stacks on your plan
  • Applied instantly

Wallet

Sales clear in 2 days, then you can withdraw anytime. Marketplace fee 35%.

0 ₽
Available0 ₽
Clearing0 ₽
Can withdraw0 ₽
Available
0 ₽
Clearing
0 ₽
In
0 ₽
Out
0 ₽

Incoming · 2 days

Sales land here for 2 days, then move to available. Withdraw anytime after that.

Available 0 ₽

Withdrawal history

Income (7 days)

History

Purchases

Refunds

How it works

Account

Register with email. We send a 6-digit code. Guests can browse Explore, but cannot publish, review, buy or open Dashboard.

Project = injector

Create a named project. Slots, HWID database and the generated loader all live inside that project. New projects start private.

Loader

Generate a GUI loader. On inject it copies HWID and asks our API. Unknown HWID is denied. Reset a slot and that PC is gone on the next launch. We never auto-add a machine on first inject.

Selling access

On Publish you add duration plans (7 days, 30 days, lifetime…). Buyers pay from the wallet. You receive 65% — platform fee is 35%. Sale funds clear in 2 days, then you can withdraw. After purchase they inject, Check HWID, then Bind. Access lasts exactly as long as the plan. HWID reset is once per 7 days.

Reviews

Only buyers can leave a star review. One review per account — no spam, no guest ratings. The average shows on Explore cards and on the project page.

Wallet

Sales clear in 2 days, then sit on available balance. Withdraw anytime after that. Marketplace fee 35%. History lists every operation.

Moderation and Static Guard

Public projects are reviewed before source becomes live. Static Guard blocks obvious stealers, Roblox cookie/token exfiltration, mutable loaders and destructive file behavior, then staff performs a manual check.

Community links

Creators may attach a Discord invite. It appears as a dedicated button on the project page. Keep support channels honest; platform safety rules still apply.

Bans and appeals

Trust & Safety can block accounts and the last known IP for fraud, malware or abuse. Banned users see a clear blocked-account overlay and cannot use protected APIs until unbanned.

Mailbox

Security alerts, purchases, sales, reviews, moderator decisions and report receipts are mirrored into the in-app mailbox, so important messages are still visible when SMTP is delayed.

Static Guard: how it works

Every uploaded original script is scanned before it can be published. The engine blocks obfuscators (MoonSec, Luraph, Ironbrew, Prometheus, PSU), encoded byte and base64 blobs, minified dumps, remote loaders (loadstring(game:HttpGet…)), exploit APIs (getrenv, hookfunction, os.execute), cookie/token theft and exfiltration into webhooks and IP loggers. Fake “security” scripts that only paint a watermark are flagged HIGH RISK and require a human decision.

Money flow

Buyers pay from the wallet. You receive 65% of every sale, the platform keeps 35%. Sale funds wait 2 days in “clearing”, then move to available balance. Withdrawals go through the linked payout service; until it is connected, requests stay “processing”, reserve the amount and never consume the daily limit.

Trust & Safety team

Users can apply for moderator from their profile. Only administrators approve applications. Staff works in a separate space: they claim a review, read the card, the Static Guard report and the full source, then approve (the frozen revision goes live) or reject with a concrete reason. Rejected projects are frozen out of Explore until the owner fixes them and resubmits. A ban covers the account and the last known IP; banned users see a clear blocked screen.

Reports and bug reports

Anyone can report a project, comment or user from its page. “Found a bug?” opens a structured form: category, details and optional contact. Every report lands in the staff room and the admin mail, so nothing is lost even if the mail is delayed.

Data and privacy

Accounts are created by e-mail plus a one-time code. Sign-in with Google never sends your Google password — HookGuard asks for a separate local password. Security events (password changes, e-mail changes, sign-ins from a new device) are mirrored into the in-app mail with a shared read status alongside the bell.

Limits at a glance

Flash (free): 5 projects, 15 HWID slots. Pro: 15 projects, 150 slots. Pro+: 30 projects, 300 slots. Buyers can reset an HWID once per 7 days. Extra HWID packs and extra project slots are on Pricing, on top of the plan.

Почта

Письма от HookGuard и других пользователей — с историей.

Выбери письмо слева, чтобы прочитать

Settings

Site, language, currency, notifications.

Appearance

Language

Currency

Choose how RUB wallet values are displayed. Rates update automatically.

Display currencyUSD

Notifications

HOOKGUARD / TRUST & SAFETY

Moderation workspace

Claim a review before working on it. Every approved source becomes an immutable runtime revision.

Team online
0Pending
0Unclaimed
0Assigned to me
0Team members

Moderation queue

Inspect the listing, Static Guard findings and complete Original Script.

Team chat

A shared room for hand-offs and difficult review decisions.

Enter to send · Shift+Enter for a new line

Users

Every registered account.

Inspect

Paste a project link or id. Open the original and the current draft.

Reports

Inbox of reports on users, projects, reviews and bugs.

Bans

Mods send a reasoned request. Admins approve or deny.

Log

Closed reviews, reports and bans — with the original script.

Admin tools

Plan, project capacity and wallet adjustments.

If you write something, they get it with the grant — in HookGuard Mail and on their email.

Roles

Promote admins/moderators or remove moderator rights.

Bans

Ban/unban account and its last IP.

Moderator applications

Only admins can approve new moderators.

Free-Kassa cashier

Invoices are created through the cashier API; one button verifies the settings, the signature and the API key. «Check status» in the merchant cabinet must get HTTP 200 + YES from our webhook.

Do not pick the widget, the pay button or the SCI payment link. Top-ups use the merchant API. The key belongs on Settings → API, not the widget key and not FK Wallet.

Webhook journal

What the cashier sent to /webhooks/freekassa and what we answered. Secrets are never stored.

Withdrawal queue

Manual payouts. Users already paid from the wallet — send the transfer yourself, then mark sent. Reject returns the money.