Happy Coders OTP Login for WooCommerce

Àpèjúwe

Happy Coders OTP Login is a simple, secure, and customizable OTP login plugin for WordPress and WooCommerce sites. It enables users to log in using their mobile number via one-time password (OTP) verification, using the MSG91 SMS API, and also supports email-based OTP login.

The plugin supports full-screen and popup login forms, integrates smoothly with WooCommerce, and improves user experience by replacing traditional email/password logins with secure phone-based authentication.

Now, you can fully customize your transactional SMS messages using dynamic variables like ##customer_name##, ##order_id##, and more, directly from the plugin settings.

Watch our quick video tutorial to see how easy it is to set up!

MSG91 Integration

This plugin uses the MSG91 SMS and WhatsApp gateway (https://msg91.com) to send and verify OTPs, and also to send order-related notifications. You must have a valid MSG91 account and approved SMS/WhatsApp templates. You can sign up here

Visit MSG91Ìtumọ̀ Yorùbá: ’s Terms of Service and Privacy Policy for more details about how they handle data

Data Handling and Privacy

  • Only the phone number is sent to MSG91 for OTP and transactional SMS/WhatsApp delivery.
  • No personal or sensitive user data is stored or tracked by this plugin.
  • Plugin does not collect analytics or track users without consent.
  • All configurable from the plugin settings page.

🔥 Features:
Ìtumọ̀ Yorùbá: – Full-screen or popup OTP login form
Ìtumọ̀ Yorùbá: – WooCommerce login compatibility
Ìtumọ̀ Yorùbá: – OTP verification via MSG91 (SMS & WhatsApp)
Ìtumọ̀ Yorùbá: – Email OTP login option
Ìtumọ̀ Yorùbá: – WhatsApp Send OTP support
Ìtumọ̀ Yorùbá: – Automatic SMS/WhatsApp alerts for:
Ìtumọ̀ Yorùbá: – New user registration
Ìtumọ̀ Yorùbá: – Order placed
Ìtumọ̀ Yorùbá: – Order shipped
Ìtumọ̀ Yorùbá: – Order completed
Ìtumọ̀ Yorùbá: – Cart cronjob (abandoned cart reminders)
Ìtumọ̀ Yorùbá: – Customizable resend timer
Ìtumọ̀ Yorùbá: – Country code and flag selection
Ìtumọ̀ Yorùbá: – Shortcodes for embedding login anywhere
Ìtumọ̀ Yorùbá: – Admin panel for MSG91 and plugin settings
Ìtumọ̀ Yorùbá: – Customizable transactional SMS templates with dynamic variables (e.g., ##customer_name##, ##order_id##).
Ìtumọ̀ Yorùbá: – Dynamic OTP length (4 or 6 digits).

🎯 Shortcodes:
Ìtumọ̀ Yorùbá: – [msg91_otp_form] – Display full-screen OTP login form anywhere (pages, posts, widgets).

🔧 Admin Settings:
Ìtumọ̀ Yorùbá: – MSG91 Auth Key, Sender ID, Template IDs
Ìtumọ̀ Yorùbá: – Enable/disable WhatsApp OTP option
Ìtumọ̀ Yorùbá: – Country code options
Ìtumọ̀ Yorùbá: – OTP resend timer settings
Ìtumọ̀ Yorùbá: – Button/text color customization
Ìtumọ̀ Yorùbá: – Post-login redirect URL
Ìtumọ̀ Yorùbá: – OTP send limit per user/day
Ìtumọ̀ Yorùbá: – Enable/disable specific SMS/WhatsApp features (registration, order, cart)
Ìtumọ̀ Yorùbá: – Customizable SMS message templates with dynamic variables.

Configuration

  1. Get an MSG91 Account: This plugin requires an MSG91 account. If you donÌtumọ̀ Yorùbá: ’t have one, you can sign up here.
  2. Enter Credentials: In the plugin settings, enter your MSG91 Auth Key, Sender ID, and DLT-approved Template IDs.
  3. Display the Form: Use the shortcode [msg91_otp_form] on any page or add the CSS class otp-popup-trigger to a button/link to show the login form.

Support

We are committed to helping you succeed. To get you the fastest and most accurate help, please direct your query to the correct team.

For Plugin Issues & Configuration (Happy Coders Support)

If you need help with installing the plugin, configuring its settings in WordPress, encounter a bug, or have a feature request for the plugin itself, please use our official support channel.
Primary Support Channel: WordPress.org Support Forum

For MSG91 Service & Delivery Issues (MSG91 Support)

If your question is about the MSG91 service itself—such as your account, API key, billing, Sender ID approval, DLT templates, or SMS/WhatsApp delivery reports—you must contact the MSG91 support team directly. They are the experts on their platform and can assist you with all service-related inquiries.
Contact MSG91 Support: Visit the MSG91 Contact Page

Àwọn àwòrán ìbòjú

Ìgbéwọlẹ̀

  1. Upload the plugin to the /wp-content/plugins/happy-coders-otp-login directory.
  2. Activate it from the ‘Plugins’ menu in WordPress.
  3. Go to MSG91 OTP & SMS in the admin menu to configure the settings.
  4. Enter your MSG91 credentials and setup options.
  5. Add shortcodes to posts/pages/widgets for login.

FAQ

Do I need an MSG91 account?

Yes, this plugin is a connector for the MSG91 service. You must have an active MSG91 account. Sign up for MSG91 here.

How do I display the login form?

You have two easy options:
1. Shortcode: Place [msg91_otp_form] on any page, post, or text widget.
2. Popup/Modal: Add the CSS class otp-popup-trigger to any button or link. Example: <a href="#" class="otp-popup-trigger">Login here</a>.

Is this compatible with WooCommerce?

Yes, it works with WooCommerce login and sends order status notifications via SMS/WhatsApp.

Can I disable certain SMS notifications?

Yes. In the “Transactional SMS Settings” tab, each notification type (new order, shipped, etc.) can be individually enabled or disabled with a simple toggle.

How does Email OTP work?

Users must first register using Mobile OTP. On the first login after registration, they must verify their email address with an Email OTP. After this one-time email verification, they can use Email OTP for future logins.

Àwọn àgbéyẹ̀wò

Ẹrẹ́nà 28, 2026
I am extremely impressed with this plugin! It’s not only highly functional and user-friendly, but the support team behind it is also incredibly responsive and helpful. Their dedication made my experience seamless and stress-free. I highly recommend this plugin to everyone—truly a game-changer. Thank you for creating such an amazing tool!
Ọwẹ́wẹ̀ 24, 2025
thank you team happy coders pvt. ltd. Ìtumọ̀ Yorùbá: – very highly recommended great OTP signup plugins Ìtumọ̀ Yorùbá: – highly suitable for MSG91 gateway and customer support also very great Ìtumọ̀ Yorùbá: – again appreciate you team happy coders. from UAE Ìtumọ̀ Yorùbá: – BAHRAIN and Kerala, India Team BEOEB
Ògún 31, 2025
Very useful OTP plugin. By default it works for login and registration, but I customized it for WooCommerce order delivery confirmation and it works smoothly. The developer’s communication and support are amazing. Highly recommended!
Ògún 29, 2025
I installed the Happy Coders OTP plugin on my WooCommerce store, and itÌtumọ̀ Yorùbá: ’s been working perfectly right from the start. The installation process was quick, and the configuration was simple even for someone without a technical background. OTPs are sent instantly, and the verification process feels seamless for customers. It adds a strong layer of security during checkout, which is exactly what I needed. I also reached out to support with a minor question, and they responded quickly and helpfully. Very satisfied with this plugin – reliable, efficient, and well-developed. Highly recommended!
Ka gbogbo àwọn àgbéyẹ̀wò 7

Àwọn Olùkópa & Olùgbéejáde

“Happy Coders OTP Login for WooCommerce” jẹ́ ètò ìṣàmúlò orísun ṣíṣí sílẹ̀. Àwọn ènìyàn wọ̀nyí ti ṣe ìkópa sí plugin yìí.

Àwọn Olùkópa

Túmọ̀ “Happy Coders OTP Login for WooCommerce” sí èdè rẹ.

Ṣe o nífẹ̀ẹ́ sí ìdàgbàsókè?

Ṣàwárí koodu, ṣàyẹ̀wò ibi ìpamọ́ SVN, tàbí ṣe àgbékalẹ̀ sí àkọsílẹ̀ ìdàgbàsókè nípasẹ̀ RSS.

Àkọsílẹ̀ àwọn àyípadà

2.8

  • Security: Fixed a critical authentication bypass vulnerability (CVSS 9.8) reported by the WPScan security team (discovered by moonge). The auto-login handler was incorrectly exposed as a public unauthenticated AJAX endpoint, allowing any visitor with the publicly available nonce to log in as any existing user — including administrators — without OTP verification. The handler is no longer registered as an AJAX endpoint; login is now performed exclusively within the OTP verification handler after server-side confirmation.
  • Security: WhatsApp OTP flow no longer creates a WordPress user account at OTP send time. Account creation is now deferred until after the OTP is successfully verified, preventing phantom account creation for unverified numbers.
  • Security: WhatsApp OTPs are now stored as short-lived transients (10-minute expiry) and are deleted immediately upon successful verification to prevent replay attacks.
  • Security: Resolved a logical flaw in the SMS OTP verification path where the fallback code path could bypass the user-existence check.
  • Fix: Send OTP button no longer changes to “Sending…” state when the mobile number field is empty. Validation now runs before the button state changes, so the form correctly shows the error message without disabling the button.
  • Fix: WhatsApp option no longer appears in the Resend OTP section when WhatsApp OTP is disabled in settings. The resend buttons now correctly reflect the admin configuration.
  • Security: OTP rate-limit counter now initializes to 0 before the database check, preventing a bypass when the rate-limit table is unavailable.
  • Security: MSG91 API key and parameters are now properly URL-encoded in the OTP send request, preventing potential injection via special characters in credentials.
  • Security: Verification cookies (msg91_verified_mobile, msg91_verified_user_id) are now set with HttpOnly, Secure, and SameSite=Strict flags to prevent JavaScript access and cross-site transmission.
  • Security: Duplicate AJAX hook registration for hcotp_send_otp_ajax removed — previously caused each OTP send to be processed twice, including double rate-limit counting and double API calls.
  • Security: WhatsApp OTPs are now stored as bcrypt hashes (via wp_hash_password) in both transients and user meta, preventing plaintext OTP exposure if the database is compromised.
  • Security: Email account enumeration prevented — sending OTP to an unregistered email now returns a generic success response instead of a distinct error message.
  • Security: Settings migration function now requires manage_options capability, preventing lower-privilege admin users from triggering the migration.
  • Security: Checkout login notice now uses wc_get_page_permalink() for the account URL instead of a hardcoded path, and output is properly escaped.
  • Security: Transactional SMS message templates now saved with sanitize_textarea_field instead of wp_kses_post, preventing HTML tags from being stored and sent inside SMS messages.
  • Security: Admin asset versions changed from time() to HCOTP_VERSION, enabling proper browser caching.
  • Fix: Server error messages in the OTP form are now rendered with .text() instead of .html() to prevent potential XSS from untrusted response content.
  • Fix: Removed console.log statements that were exposing the nonce and plugin configuration in the browser developer console.

2.7

  • Fix: Updated blocked numbers table queries to use the active WordPress database prefix instead of hardcoded wp_hcotp_blocked_numbers.

2.6

  • Tweak: Added default Email OTP subject/body in settings when fields are empty.

2.5

  • Feature: Added customizable HTML email templates for Email OTP messages.
  • Feature: Added header/footer image support and preview for Email OTP templates.
  • Tweak: Improved Email OTP settings UI and template controls.

2.4

  • Feature: Added Email OTP login option.
  • Tweak: Updated plugin version to 2.4.

2.3

  • Feature: Added ‘otp_length’ parameter to the MSG91 API call for dynamic OTP length.
  • Tweak: Updated plugin version to 2.3.

2.2

  • Feature: Added setting to configure OTP length dynamically (4 or 6 digits).
  • Tweak: Updated plugin version to 2.2.
  • Fix: Minor bug fixes and improvements.

2.1

  • Feature: Introduced customizable transactional SMS message templates with dynamic variable support (e.g., ##customer_name##, ##order_id##).
  • Tweak: Enhanced settings page to allow direct input of SMS message templates using descriptive variables.
  • Fix: Ensured backward compatibility for existing SMS notes by repurposing the field for message templates.

2.0

  • Fix: Corrected an issue where SMS settings were not being saved properly.
  • Feature: Added a migration function to move old settings to a new format.

1.9

  • Fix: General bug fixes and performance improvements.

1.8

  • Fix: General bug fixes and performance improvements.

1.7

  • Feature: Added support for sending OTPs via WhatsApp.
  • Tweak: Improved UI and clarity on the settings pages.
  • Fix: General bug fixes and performance improvements.

1.6

  • Fix: Minor bug fixes and overall improvements for better performance and stability.

1.5

  • Feature: Added automated SMS notifications for New User Registration, Order Placed, Order Shipped, Order Completed, and Abandoned Cart.
  • Tweak: Enhanced admin settings UI for managing new transactional SMS features.
  • Fix: Minor bug fixes and improvements.

1.0.0

  • Initial release with OTP login features (full-screen and popup) and core MSG91 integration.