{"id":365559,"date":"2026-09-10T05:02:48","date_gmt":"2026-09-10T05:02:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/otp-login-by-waloops\/"},"modified":"2026-09-12T18:08:11","modified_gmt":"2026-09-12T18:08:11","slug":"waloops-otp-login","status":"publish","type":"plugin","link":"https:\/\/ru.wordpress.org\/plugins\/waloops-otp-login\/","author":13605574,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.0","stable_tag":"1.4.0","tested":"7.1","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"WALoops OTP Login","header_author":"WALoops","header_description":"Add \"Login \/ Register with WhatsApp OTP\" to your WordPress login, registration and WooCommerce checkout screens. 100 OTP messages free every month.","assets_banners_color":"259ba8","last_updated":"2026-09-12 18:08:11","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/waloops.com\/wordpress-otp-login","header_author_uri":"https:\/\/waloops.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":93,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"bhagirath25","date":"2026-09-10 05:02:41","revision":3689299},"1.1.0":{"tag":"1.1.0","author":"bhagirath25","date":"2026-09-10 07:07:54","revision":3689432},"1.4.0":{"tag":"1.4.0","author":"bhagirath25","date":"2026-09-12 18:08:11","revision":3692985}},"upgrade_notice":{"1.2.0":"<p>WhatsApp OTP is now the primary login\/register option (password fields move behind a small toggle, configurable in Settings); also fixes wrong country-code defaults and the form showing to already-logged-in visitors.<\/p>","1.1.1":"<p>Fixes the widget not appearing on WooCommerce&#039;s My Account login\/register page.<\/p>","1.1.0":"<p>Adds Contact Form 7 and WPForms phone-verification support.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3689315,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3689315,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3689315,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3689315,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.4.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Settings page \u2014 usage, API key, message style, and where the OTP form shows.","2":"The \"Modern\" front-end OTP form on a login page.","3":"The \"Card\" front-end OTP form style.","4":"Usage dashboard showing your monthly OTP quota."}},"plugin_section":[],"plugin_tags":[602,9210,9217,3160,286],"plugin_category":[38,45],"plugin_contributors":[81060],"plugin_business_model":[],"class_list":["post-365559","plugin","type-plugin","status-publish","hentry","plugin_tags-login","plugin_tags-otp","plugin_tags-two-factor","plugin_tags-whatsapp","plugin_tags-woocommerce","plugin_category-authentication","plugin_category-ecommerce","plugin_contributors-bhagirath25","plugin_committers-bhagirath25"],"banners":{"banner":"https:\/\/ps.w.org\/waloops-otp-login\/assets\/banner-772x250.png?rev=3689315","banner_2x":"https:\/\/ps.w.org\/waloops-otp-login\/assets\/banner-1544x500.png?rev=3689315","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/waloops-otp-login\/assets\/icon-128x128.png?rev=3689315","icon_2x":"https:\/\/ps.w.org\/waloops-otp-login\/assets\/icon-256x256.png?rev=3689315","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>Add WhatsApp OTP login to WordPress in 2 minutes.<\/strong><\/p>\n\n<p>A password-free login and registration option, delivered over WhatsApp \u2014 works alongside your existing login form, on any theme, with or without WooCommerce. No password to remember, no password to reset, no password to leak.<\/p>\n\n<p><strong>Free forever \u2014 100 OTPs\/month<\/strong><\/p>\n\n<p>Get a free API key by creating a WALoops account from the plugin's settings page (no credit card) and start sending real WhatsApp OTPs from WALoops' shared WhatsApp number immediately.<\/p>\n\n<h4>Everything you need, nothing you don't<\/h4>\n\n<ul>\n<li><strong>Adds, never replaces<\/strong> \u2014 sits alongside your normal login and registration forms as an extra option, never in place of them<\/li>\n<li><strong>3 ready-made designs<\/strong> \u2014 Modern, Minimal, and Card form styles, pick one in Settings, no CSS required<\/li>\n<li><strong>Works in minutes<\/strong> \u2014 no Meta Developer account needed on the Free or Introduction (shared-number) plans<\/li>\n<li><strong>Bring your own number<\/strong> \u2014 Introduction and Starter Ecommerce plans let you send from your own WhatsApp Business number<\/li>\n<li><strong>WooCommerce checkout<\/strong> \u2014 offer WhatsApp OTP verification right at checkout on the Starter Ecommerce plan<\/li>\n<li><strong>Shortcode-friendly<\/strong> \u2014 place the form anywhere with <code>[wa_otp_login]<\/code>, or drag it on as a native <strong>Elementor<\/strong> widget or <strong>WPBakery Page Builder<\/strong> element<\/li>\n<li><strong>Spam-proof your other forms<\/strong> \u2014 a \"WhatsApp OTP Verify\" field\/tag for <strong>Contact Form 7<\/strong>, <strong>WPForms<\/strong>, <strong>Gravity Forms<\/strong>, and <strong>Formidable Forms<\/strong> blocks submission until the visitor's number checks out (experimental for Ninja Forms \u2014 test before relying on it)<\/li>\n<li><strong>Goes global<\/strong> \u2014 a country dial-code selector on every phone field, pre-filled from the visitor's browser language and always changeable<\/li>\n<li>Fully translatable (text domain: <code>waloops-otp-login<\/code>)<\/li>\n<\/ul>\n\n<h4>Simple, WordPress-friendly pricing<\/h4>\n\n<p>Start free. Upgrade only when you actually need more volume or your own number.<\/p>\n\n<ul>\n<li><strong>Free \u2014 $0\/month.<\/strong> Everything you need to try WhatsApp OTP login on a live site: 100 OTPs\/month from our shared number, all 3 form styles, login\/register\/shortcode placement.<\/li>\n<li><strong>Introduction \u2014 $5\/month.<\/strong> For sites outgrowing the free quota: 1,000 OTPs\/month, use our shared number or connect your own, switch any time.<\/li>\n<li><strong>Starter Ecommerce \u2014 $9.99\/month.<\/strong> For high-traffic and WooCommerce sites: unlimited OTPs on your own connected WhatsApp Business number, checkout verification, and priority support.<\/li>\n<\/ul>\n\n<h4>How it works<\/h4>\n\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li>Go to <strong>Settings &gt; WhatsApp OTP Login<\/strong> and click <strong>Create a free WALoops account<\/strong> \u2014 you'll land straight on your API key. Paste it into the field on this same settings page.<\/li>\n<li>Pick where the OTP option should appear (login page, registration page, WooCommerce checkout) \u2014 or drop the <code>[wa_otp_login]<\/code> shortcode anywhere.<\/li>\n<li>Done. Visitors can now log in or register with just their WhatsApp number.<\/li>\n<li>To verify a phone number on your own Contact Form 7, WPForms, Gravity Forms, or Formidable Forms form instead: add a <code>[wa_otp_verify your-phone]<\/code> tag in the CF7 form editor, or drag\/add the \"WhatsApp OTP Verify\" field into the other three builders \u2014 no extra setup needed once your API key is saved.<\/li>\n<li>Using Elementor or WPBakery Page Builder? Drag the \"WhatsApp OTP Login\" widget\/element onto any page instead of using the shortcode.<\/li>\n<\/ol>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to WALoops' WhatsApp OTP service (<strong>https:\/\/app.waloops.com\/<\/strong>) to deliver one-time-password messages over WhatsApp. This connection is required for the plugin to work \u2014 there's no way to send a WhatsApp message without it.<\/p>\n\n<p>What is sent, and when:<\/p>\n\n<ul>\n<li><strong>Creating a free WALoops account<\/strong>: clicking \"Create a free WALoops account\" takes you to app.waloops.com to register or log in. Nothing is sent from this plugin at that point \u2014 once you're logged in there, your API key is generated for you to paste back into this settings page.<\/li>\n<li><strong>When a visitor requests a verification code<\/strong> (login, registration, checkout, or a Contact Form 7 \/ WPForms field): their phone number is sent to WALoops so it can send them a WhatsApp message containing the code.<\/li>\n<li><strong>When a visitor submits a code<\/strong>: their phone number and the code they entered are sent to WALoops to be checked.<\/li>\n<li><strong>On the settings page<\/strong>: your account's monthly usage is fetched from WALoops so it can be shown to you. If you choose to connect your own WhatsApp Business number, your Meta access token and phone number ID are also sent to WALoops, to verify and store for your account.<\/li>\n<\/ul>\n\n<p>No data is sent to any other third party. See WALoops' <a href=\"https:\/\/waloops.com\/terms\">Terms of Service<\/a> and <a href=\"https:\/\/waloops.com\/privacy-policy\">Privacy Policy<\/a>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20meta%2Ffacebook%20developer%20account%3F\"><h3>Do I need a Meta\/Facebook Developer account?<\/h3><\/dt>\n<dd><p>No \u2014 not on the Free or Introduction plans, where you can send from WALoops' shared WhatsApp number. Connecting your own number (optional on Introduction, required on Starter Ecommerce) does require your own WhatsApp Business Cloud API app.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20run%20out%20of%20free%20otps%20for%20the%20month%3F\"><h3>What happens when I run out of free OTPs for the month?<\/h3><\/dt>\n<dd><p>Sends are blocked with a clear \"monthly limit reached\" message until the next calendar month starts, or until you upgrade.<\/p><\/dd>\n<dt id=\"does%20this%20replace%20my%20normal%20login%20form%3F\"><h3>Does this replace my normal login form?<\/h3><\/dt>\n<dd><p>No. It's added as an extra option alongside your existing username\/password login and registration forms.<\/p><\/dd>\n<dt id=\"can%20i%20customize%20the%20whatsapp%20message%20text%3F\"><h3>Can I customize the WhatsApp message text?<\/h3><\/dt>\n<dd><p>WhatsApp only allows pre-approved wording for one-time-passcode (Authentication-category) messages \u2014 you can't write fully custom copy. Right now the message is \"{code} is your verification code. For your security, do not share this code.\" More variants (with an expiry line, code-only) will appear as an option once they're approved with Meta.<\/p><\/dd>\n<dt id=\"is%20my%20visitors%27%20data%20safe%3F\"><h3>Is my visitors' data safe?<\/h3><\/dt>\n<dd><p>Phone numbers and OTP codes are transmitted over HTTPS and are used solely to deliver and verify the one-time password. See the \"External services\" section above for exactly what's sent and when.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20international%20phone%20numbers%3F\"><h3>Does this work with international phone numbers?<\/h3><\/dt>\n<dd><p>Yes. Every phone field has a country dial-code selector (pre-filled from the visitor's browser language, always changeable) \u2014 there's no restriction to a specific country, as long as WhatsApp is reachable at that number.<\/p><\/dd>\n<dt id=\"how%20does%20the%20form-builder%20verification%20work%3F\"><h3>How does the form-builder verification work?<\/h3><\/dt>\n<dd><p>Add the <code>[wa_otp_verify your-phone]<\/code> tag (CF7) or the \"WhatsApp OTP Verify\" field (WPForms, Gravity Forms, Formidable Forms) to your form. A visitor enters their WhatsApp number, receives a code, and enters it \u2014 the form can't be submitted until that check passes. No phone number is stored by this plugin for this feature; verification is a signed, short-lived token checked again on submission, the same way a nonce works.<\/p><\/dd>\n<dt id=\"which%20form%20builders%20are%20supported%3F\"><h3>Which form builders are supported?<\/h3><\/dt>\n<dd><p>Contact Form 7, WPForms, Gravity Forms, and Formidable Forms are fully supported. Ninja Forms support is experimental \u2014 please test it on your own site before relying on it. Elementor Pro Forms, Fluent Forms, and SureForms aren't supported yet.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>New: \"Form Builder\" admin page \u2014 the Login form stays fixed to just a Mobile Number (that's all OTP login needs), but the Register form now always collects a Full Name alongside the Mobile Number, plus a tick-box list of optional fields (Email, Company Name, Address, City, Date of Birth) you can turn on. Collected values are saved to the new WordPress account: Full Name sets the account's name\/display name, Email replaces the generated placeholder address, everything else is stored as user meta.<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Fix: the new \"WordPress Login Page\" setting (see 1.3.0) was checked via <code>class_exists( 'WooCommerce' )<\/code> at a point in the load order where it was always false \u2014 WordPress loads plugin files alphabetically by folder name, and \"waloops-otp-login\" sorts before \"woocommerce\", so the check ran before WooCommerce's own file had loaded. This silently fell back to the non-WooCommerce behavior, meaning wp-login.php kept showing WhatsApp OTP as primary even with the new setting off. The check now runs on <code>plugins_loaded<\/code> instead, after every plugin has loaded.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>New: \"Get Free API Key\" is now a real quick-start \u2014 enter your email (pre-filled from your WordPress admin email) and WhatsApp number and get a working API key immediately, without leaving wp-admin or visiting app.waloops.com. This also creates your WALoops account behind the scenes (with a generated password emailed to you) so you can log in later to upgrade your plan \u2014 you're never asked to type a password during setup.<\/li>\n<li>Fix: on WordPress 5.7+ (which wraps the password field's label separately from its input+show\/hide button), the 1.2.0 \"OTP is primary\" redesign only hid the input, leaving the \"Password\" label behind on its own \u2014 looked like a disabled\/broken field. The whole password field now hides together.<\/li>\n<li>Change: on WooCommerce sites, wp-login.php (Login\/Registration) is now a separate \"Show on\" setting from WooCommerce's own My Account login\/register, and defaults off \u2014 wp-login.php is WordPress's backend login, typically used by site staff\/admins, not customers, so it no longer gets the \"OTP is primary\" treatment unless explicitly turned on.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Change: WhatsApp OTP is now shown as the <em>primary<\/em> login\/register option wherever it's enabled, with the site's own username\/password fields tucked behind a small \"Log in with username &amp; password instead\" link (togglable in Settings, or turn it off entirely to make WhatsApp OTP the only way in).<\/li>\n<li>Fix: the country dial-code default was guessed from the browser's UI language (<code>navigator.language<\/code>), which is often wrong (e.g. an English-Canada browser locale showing +1 Canada regardless of where the visitor actually is). Now resolved server-side from a CDN geo header when present, falling back to the WooCommerce store's base country or the site's own locale, with a browser-timezone-based refinement on the front end \u2014 the same method used by WALoops Quick Checkout.<\/li>\n<li>Fix: a visitor who is already logged in now sees a \"You are already logged in as X. Log out?\" notice in place of the form (same idiom wp-login.php itself uses), instead of the widget silently rendering nothing.<\/li>\n<li>Fix: login and register are now the same flow \u2014 a WhatsApp number that verifies successfully but has no linked account gets one created automatically, regardless of which form (login or register) the visitor used. Previously the plain login form dead-ended first-time numbers with \"No account is linked to this WhatsApp number yet. Please register first.\", which made no sense once OTP verification is itself the proof of identity.<\/li>\n<li>New: real design pass on the \"Modern\"\/\"Minimal\"\/\"Card\" styles \u2014 a proper title and description, and buttons that use WordPress's own <code>button<\/code>\/<code>button-primary<\/code> classes so they pick up the active theme's (or wp-admin login screen's) real button color instead of a hardcoded WhatsApp-green.<\/li>\n<li>New: <code>wa_otp_login_show_logged_in_notice<\/code>, <code>wa_otp_login_form_title<\/code>, <code>wa_otp_login_form_description<\/code> filters and <code>wa_otp_login_before_render<\/code>\/<code>wa_otp_login_after_render<\/code> actions \u2014 see HOOKS.md.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Fix: \"Show on Login page\" \/ \"Show on Registration page\" now also appear on WooCommerce's own My Account login\/register tabs (<code>woocommerce_login_form<\/code> \/ <code>woocommerce_register_form<\/code>), not just wp-login.php. Previously, on WooCommerce sites (which almost always use the My Account page instead of wp-login.php), the widget silently never appeared even with the settings enabled.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: phone verification for Contact Form 7 (<code>[wa_otp_verify your-phone]<\/code> form-tag), WPForms, Gravity Forms, and Formidable Forms (\"WhatsApp OTP Verify\" field) \u2014 blocks form submission until the visitor's WhatsApp number is OTP-verified.<\/li>\n<li>New: experimental Ninja Forms support for the same feature.<\/li>\n<li>New: native Elementor widget and WPBakery Page Builder element for the login\/register form.<\/li>\n<li>New: country dial-code selector on every phone field (login, registration, checkout, and the new form fields), defaulting from the visitor's browser language.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: Free\/Introduction\/Starter plans, login\/register\/WooCommerce-checkout integration, three form styles, own-number connection.<\/li>\n<\/ul>","raw_excerpt":"Add WhatsApp OTP login &amp; registration to WordPress in minutes. 100 free OTPs\/month, no credit card required.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/365559","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=365559"}],"author":[{"embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/bhagirath25"}],"wp:attachment":[{"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=365559"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=365559"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=365559"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=365559"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=365559"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ru.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=365559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}