Gravity Forms OTP Verification
The code is checked before the entry exists.
Add an OTP field to a Gravity Forms form and point it at a mobile or email field. The visitor gets a one-time code, types it in, and only then is the submission saved. A wrong or missing code is a validation error, like any other.
Free, GPL-2.0 or later, published by Pigment Dev, where I am a co-founder and lead developer. Figures from the WordPress.org and GitHub APIs, 30 September 2026.
What it does
A one-time code for any Gravity Forms form, by SMS or by email, without a separate login system around it.
SMS or email
Each OTP field verifies either a mobile number or an email address. Email codes use an HTML template you can edit, with your own sender name.
Your SMS gateway
Built-in support for WP-SMS and Persian WooCommerce SMS, and a hook for any other provider.
Persian and Arabic digits
Numbers typed as ۰۹۱۲ or ٠٩١٢ are converted before they are checked, because that is how many visitors in Iran type them.
Limits by default
By default three wrong codes lock the number for ten minutes, and a code sent from the form expires after sixty seconds. All three values are settings.
Why before, not after
Before the entry is written, not after. That ordering is the whole plugin.
The usual way to add verification is to save the entry and mark it unverified, then clean up. That leaves fake numbers in the entries table, notifications sent for submissions nobody confirmed, and every add-on that reacts to a new entry reacting to junk.
Gravity Forms already has a moment where a submission can be refused without leaving a trace: validation. The plugin does its checking there, so an unverified submission never becomes an entry at all, and notifications, feeds and payments only ever see verified ones.
How it checks
One filter, gform_validation, and a short-lived code per number in a WordPress transient.
When the form is submitted, the plugin reads the digits of the OTP field and the number or email it is attached to, and validates the format. If no code is stored for that number yet, it sends one and fails validation with "OTP has been sent to you". If a code is stored, it compares them as strings, and on a match deletes the code and the attempt counter.
Codes come from random_int(). Version 3.2.0 fixed a case where a correct code failed because one side was an integer and the other a string, which is why the comparison is explicit about types now.
add_filter('gform_validation', [$this, 'validate_otp_before_submit_gform']); $stored = get_transient('gravity_otp_verification_' . $phone); if (!$stored) { // send a code, refuse this submission } elseif ((string) $stored === (string) $typed) { // verified: clear the code and the attempts } else { // count the attempt, lock after the limit }
Getting started
Needs Gravity Forms, and for SMS, either an SMS plugin it supports or your own gateway code.
Install
Plugins, Add New, search for "Gravity Forms OTP Verification", then Install and Activate.
Choose a gateway
In the plugin's settings pick the SMS gateway, set the email sender if you verify emails, and send yourself a test code.
Add the field
In the form editor, add an OTP field and attach it to the phone or email field it should verify.
Submit once yourself
The first submit sends a code, the second checks it. A wrong code is shown as a validation error on the field.
Releases
Eight dated versions on WordPress.org since April 2025, each dated by its download.
| Version | Released | What changed |
|---|---|---|
| 3.2.0 | 12 Mar 2026 | Fixed the WP-SMS and WooCommerce SMS gateways, an Ajax error in debug mode, and the type mismatch in code checks. Errors reported through Query Monitor. |
| 3.1.0 | 12 Mar 2026 | Tagged the same day as 3.2.0. |
| 3.0.1 | 3 Sep 2025 | Patchstack disclosure link for security reports. |
| 3.0.0 | 3 Sep 2025 | Email verification, an HTML email template, WP-SMS as a gateway, Persian translation. |
| 2.7.0 | 15 May 2025 | Persian WooCommerce SMS as a gateway; the log panel fixed. |
| 2.6.0 | 30 Apr 2025 | Gravity Forms panel fix, WordPress compatibility. |
| 2.6 | 30 Apr 2025 | Tag of the same release. |
| 2.5.0 | 3 Apr 2025 | Oldest version on WordPress.org, dated the day the plugin was listed. |
The changelog lists 3.0.0 as 4 August 2025; its download on WordPress.org is dated 3 September 2025, the date used here. Notes from the plugin's readme.
// open-source/
More open source
The other projects with a page of their own. The rest, 56 in all, are in the explorer, each with its status and where the numbers come from.
- Receipt Uploader for WooCommerce1,000+ installs, rated 5.0 from 14
- upload-url-to-serverOne PHP file, 32 releases since 2020
- Justify It and Lorem SazAdobe XD plugins, 11,015 downloads, archived
- CF7 DatabaseContact Form 7 submissions, kept and exported
- Gravity Forms OTP VerificationA one-time code before the entry is saved
- Block External RequestWordPress's outbound calls, under control
- Slipnet for macOSA Mac client for a DNS-tunnelling VPN
- BDM, BlackSwan Download ManagerSegmented downloads on the Mac, with browser extensions
- Firefox add-onsFive published, 4.6 average rating