Why Payora
What makes it better
than the alternatives
- 01
UAE-specific payroll
UAE-specific payroll
- 02
Bilingual payslips
Bilingual payslips
- 03
Multi-tenant with organization isolation
Multi-tenant with organization isolation
- 04
Workflow automation
Workflow automation
- 05
Employee self-service portal
Employee self-service portal
Organizations & Users
- Sign-up wizard with organization setup
- Multi-organization membership per user
- Role-based permissions grid (view/create/edit/delete/approve/pay)
- User invitations with secure tokens (SHA-256 hashed)
- Audit log of every change (ActivityLog table)
Payroll Settings
- Pay schedule (work week
- actual or fixed working days
- pay date rules)
- GPSSA old and new schemes with applicable components
- 27 UAE salary components (bilingual)
- Salary templates
- Email and PDF templates (customizable per language)
- Employer bank accounts (IBAN encrypted with Data Protection API)
Employees
- 5-step add-employee wizard
- Bilingual names (English and Arabic)
- GCC national vs expatriate classification
- Salary structure with components
- IBAN validation (ISO mod-97)
- MOL person ID
- Documents with expiry tracking
- Probation and exit workflows
- CSV/XLSX import (EmployeeImport)
Pay Runs
- Regular
- one-time and off-cycle runs
- Loss of pay
- pro-rata
- overtime
- GPSSA calculation
- Approval workflow (Draft → Approved → Paid)
- Comments and adjustments per employee
- PayRunService.Calculation with PayrollCalculator
Payslips & WPS
- Bilingual payslip PDF (PayslipPdfRenderer with QuestPDF)
- Arabic page right-to-left
- Amount in words in both languages (AmountInWords)
- Payslip emails (OrganizationMailer)
- WPS SIF salary file generation (WpsSifFile)
Adjustments
- Salary revisions with automatic arrears (RevisionService)
- Revision letters (PDF)
- Leave salary (LeaveSalaryService)
- Loans with instalments (LoanService
- LoanTypeService)
- Giving (donation) campaigns (GivingService)
Final Settlement
- Gratuity per UAE labour law (FinalSettlementCalculator
- Gratuity)
- Leave encashment
- Notice pay
- Loan reconciliation
- Final settlement PDF
Employee Portal
- Separate authentication (PortalAuth scheme
- Portal cookie)
- View payslips
- Download documents
- Update profile (PortalService)
- No admin access
Reports
- 27 reports (employee
- payroll
- finance)
- ReportBuilder with EmployeeReports
- PayrollReports
- FinanceReports
- Scheduled report delivery (ReportScheduleService)
- Export to XLSX/CSV (ReportExporter)
- Report periods (ReportPeriod)
Workflow Automation
- Triggers on employee lifecycle events (hire
- probation end
- exit)
- Scheduled workflows (WorkflowProcessor)
- Actions: email alerts
- in-app notifications
- field updates
- WorkflowService
- WorkflowEvents
- Background job runner (BackgroundJobs hosted service)
Documents
- Employee and organization documents (DocumentService)
- Expiry tracking (ExpiryReminderService)
- Private file storage (LocalPrivateFileStorage)
- Upload validation (size
- extension
- file signature)
- Permission-checked downloads
Customization
- Custom fields (CustomFieldService
- 4 data types)
- Validation rules (RecordRuleService)
- Record locking rules
- Email template customization (EmailTemplateService)
- PDF template customization (PdfTemplateService)
| Language | Version | Framework | Used for | Share of code |
|---|---|---|---|---|
| C# | — | — | Web, API, admin | 55.3% |
| C# (Razor) | — | — | Web pages | 23.5% |
| SQL | — | — | Database | 11.5% |
| CSS | — | — | Styling | 3.9% |
| JavaScript | — | — | Front-end | 3% |
| HTML | — | — | Front-end | 2.4% |
| PowerShell | — | — | Scripts | 0.3% |
- Primary language
- C# 13 (.NET 10)
- Framework
- ASP.NET Core MVC 10
- Database
- SQL Server 2019+
- Authentication
- Cookie authentication (CookieAuthenticationDefaults), BCrypt password hashing, separate portal cookie (PortalAuth)
- Licence
- Single-site
- Screens
- 85
- Database tables
- 104
- Supported languages
- English, Arabic (full RTL)
- Browser support
- Modern browsers (Chrome, Firefox, Safari, Edge)
| Minimum | Recommended | |
|---|---|---|
| CPU | 2 vCPU | 4 vCPU |
| RAM | 4 GB RAM | 8 GB RAM |
| OS | .NET 10 Runtime (ASP.NET Core), SQL Server 2019+ (Express, Developer, Standard, Enterprise, Azure SQL), Windows Server 2019 | .NET 10 Runtime (ASP.NET Core), SQL Server 2019+ (Express, Developer, Standard, Enterprise, Azure SQL), Windows Server 2019 |
| Est. monthly hosting | $25 | $25 |
```bash cp .env.example .env # Edit .env: set MSSQL_SA_PASSWORD (8+ chars, upper/lower/digit/symbol, no semicolon) docker compose up -d # App at http://localhost:8080, database at localhost:1433 ```
```bash # Install .NET 10 Runtime wget https://dot.net/v1/dotnet-install.sh chmod +x dotnet-install.sh ./dotnet-install.sh --channel 10.0 --runtime aspnetcore # Install SQL Server 2019 (or use Azure SQL) curl https://packages.microsoft.com/keys/microsoft.asc | sudo tee /etc/apt/trusted.gpg.d/microsoft.asc sudo add-apt-repository "$(wget -qO- https://packages.microsoft.com/config/ubuntu/22.04/mssql-server-2019.list)" sudo apt-get update sudo apt-get install -y mssql-server sudo /opt/mssql/bin/mssql-conf setup # Publish and run dotnet publish src/Royex.Payroll.Web -c Release -o /var/www/payora cd /var/www/payora export ConnectionStrings__PayrollDb="Server=localhost;Database=RoyexPayroll;User Id=sa;Password=YOUR_PASSWORD;TrustServerCertificate=True" export Email__Smtp__Password="YOUR_SMTP_PASSWORD" dotnet Royex.Payroll.Web.dll # App at http://localhost:5000, configure Nginx reverse proxy for HTTPS ```
```bash # Create resources az group create --name payora-rg --location eastus az sql server create --name payora-sql --resource-group payora-rg --location eastus --admin-user sqladmin --admin-password YOUR_PASSWORD az sql db create --resource-group payora-rg --server payora-sql --name RoyexPayroll --service-objective S0 az appservice plan create --name payora-plan --resource-group payora-rg --sku B1 --is-linux az webapp create --resource-group payora-rg --plan payora-plan --name payora-app --runtime "DOTNETCORE:10.0" # Deploy dotnet publish src/Royex.Payroll.Web -c Release -o ./publish cd publish zip -r ../app.zip . cd .. az webapp deployment source config-zip --resource-group payora-rg --name payora-app --src app.zip # Set connection string in Azure Portal > Configuration > Connection strings # Name: PayrollDb, Value: Server=payora-sql.database.windows.net;Database=RoyexPayroll;User Id=sqladmin;Password=YOUR_PASSWORD ```
```bash # Prerequisites: .NET 10 SDK, SQL Server LocalDB or Docker SQL Server dotnet restore dotnet build # Start SQL Server in Docker (if not using LocalDB) docker run -e "ACCEPT_EULA=Y" -e "SA_PASSWORD=DevPass123!" -p 1433:1433 -d mcr.microsoft.com/mssql/server:2019-latest # Update appsettings.Development.json or set environment variable export ConnectionStrings__PayrollDb="Server=localhost;Database=RoyexPayroll;User Id=sa;Password=DevPass123!;TrustServerCertificate=True" # Run dotnet run --project src/Royex.Payroll.Web --launch-profile https # App at https://localhost:7210 ```
Quality report
Manually reviewedHow to read the quality report
What this is. Every project on Vibe96 goes through an automated audit of its source code before a reviewer in Dubai checks it by hand. The score is out of 100; 75 is the minimum to be listed, and any single failing check blocks a listing regardless of the score.
- Security
- No real credentials in the code, every data-changing route protected, admin areas role-gated, no SQL built from user input.
- Code structure
- A developer can navigate and extend it: clear module boundaries, no giant files, little copy-paste.
- Docs & completeness
- The setup guide, example config, schema and required files the builder committed to are actually in the archive.
- Dependency health
- Packages pinned, no known critical vulnerabilities, no abandoned libraries in production paths.
- Build & deploy
- A clean machine can restore, build and start it by following the shipped instructions.
Warnings are problems that didn't block the listing; they stay visible here until a later version clears them. The audit reads the code — it does not run it — so always try the live demo before you buy. Lines of code are counted from the same audited archive.
What to know before you buy
4 non-blocking findings shown publicly: no real secrets found; weak defaults in example files need environment variable enforcement; strong authentication and permission checks; minor gaps in employee portal ownership validation; raw ado.net with parameterized queries; schema solid; missing indexes on some foreign keys; clean architecture with minor duplication and some oversized service files. The seller has been notified; fixes ship in the next version.
Versions & updates
No updates yet. New versions appear here with a changelog.
Buyers receive updates free for 1 year.
What you get
- </>Full source codeThe complete audited source, delivered as a download from your account. No obfuscation.
- ▤DocumentationSetup guide, architecture notes, CLAUDE.md and AGENTS.md.
- ↻One year of updatesEvery new version the builder publishes, free for 12 months.
- ♧30 days of supportInstallation and defect support through Vibe96 tickets.