Amirhossein Hosseinpouramirhp
CV
Active WordPress plugin · Gravity Forms

Gravity Forms OTP Verification

The code is checked before the entry exists.

Add an OTP field to a Gravity Forms form and point it at a mobile or email field. The visitor gets a one-time code, types it in, and only then is the submission saved. A wrong or missing code is a validation error, like any other.

Get it on WordPress.org Source on GitHub

Free, GPL-2.0 or later, published by Pigment Dev, where I am a co-founder and lead developer. Figures from the WordPress.org and GitHub APIs, 30 September 2026.

On WordPress.org2025 to today

What it does

A one-time code for any Gravity Forms form, by SMS or by email, without a separate login system around it.

SMS or email

Each OTP field verifies either a mobile number or an email address. Email codes use an HTML template you can edit, with your own sender name.

Your SMS gateway

Built-in support for WP-SMS and Persian WooCommerce SMS, and a hook for any other provider.

Persian and Arabic digits

Numbers typed as ۰۹۱۲ or ٠٩١٢ are converted before they are checked, because that is how many visitors in Iran type them.

Limits by default

By default three wrong codes lock the number for ten minutes, and a code sent from the form expires after sixty seconds. All three values are settings.

Why before, not after

Before the entry is written, not after. That ordering is the whole plugin.

The usual way to add verification is to save the entry and mark it unverified, then clean up. That leaves fake numbers in the entries table, notifications sent for submissions nobody confirmed, and every add-on that reacts to a new entry reacting to junk.

Gravity Forms already has a moment where a submission can be refused without leaving a trace: validation. The plugin does its checking there, so an unverified submission never becomes an entry at all, and notifications, feeds and payments only ever see verified ones.

How it checks

One filter, gform_validation, and a short-lived code per number in a WordPress transient.

When the form is submitted, the plugin reads the digits of the OTP field and the number or email it is attached to, and validates the format. If no code is stored for that number yet, it sends one and fails validation with "OTP has been sent to you". If a code is stored, it compares them as strings, and on a match deletes the code and the attempt counter.

Codes come from random_int(). Version 3.2.0 fixed a case where a correct code failed because one side was an integer and the other a string, which is why the comparison is explicit about types now.

add_filter('gform_validation', [$this, 'validate_otp_before_submit_gform']);

$stored = get_transient('gravity_otp_verification_' . $phone);
if (!$stored) {
  // send a code, refuse this submission
} elseif ((string) $stored === (string) $typed) {
  // verified: clear the code and the attempts
} else {
  // count the attempt, lock after the limit
}
Condensed from gravity-otp-verification.php, version 3.2.0.

Getting started

Needs Gravity Forms, and for SMS, either an SMS plugin it supports or your own gateway code.

  1. Install

    Plugins, Add New, search for "Gravity Forms OTP Verification", then Install and Activate.

  2. Choose a gateway

    In the plugin's settings pick the SMS gateway, set the email sender if you verify emails, and send yourself a test code.

  3. Add the field

    In the form editor, add an OTP field and attach it to the phone or email field it should verify.

  4. Submit once yourself

    The first submit sends a code, the second checks it. A wrong code is shown as a validation error on the field.

Releases

Eight dated versions on WordPress.org since April 2025, each dated by its download.

VersionReleasedWhat changed
3.2.012 Mar 2026Fixed the WP-SMS and WooCommerce SMS gateways, an Ajax error in debug mode, and the type mismatch in code checks. Errors reported through Query Monitor.
3.1.012 Mar 2026Tagged the same day as 3.2.0.
3.0.13 Sep 2025Patchstack disclosure link for security reports.
3.0.03 Sep 2025Email verification, an HTML email template, WP-SMS as a gateway, Persian translation.
2.7.015 May 2025Persian WooCommerce SMS as a gateway; the log panel fixed.
2.6.030 Apr 2025Gravity Forms panel fix, WordPress compatibility.
2.630 Apr 2025Tag of the same release.
2.5.03 Apr 2025Oldest version on WordPress.org, dated the day the plugin was listed.

The changelog lists 3.0.0 as 4 August 2025; its download on WordPress.org is dated 3 September 2025, the date used here. Notes from the plugin's readme.

branch main 6 active projects ↑ 113 releases open-source/gravity-otp-verification.md Sari --:-- UTC+3:30 its@amirhp.com