Select one or more tags, then press “Search Plugins”

Find Plugin with any / all of the selected criteria
Search Plugin

Cindova Phone OTP & SMS For Gravity Forms Wordpress Plugin - Rating, Reviews, Demo & Download

Cindova Phone OTP & SMS For Gravity Forms Wordpress Plugin - Rating, Reviews, Demo & Download
No ratings yet
Free
Follow for free plugins, new theme releases and theme news

Plugin Description

Confirm that visitors own the phone number they enter, and send SMS or Slack notifications when a form is submitted.

Requires Gravity Forms 2.5 or later (tested with Gravity Forms 3.1). Gravity Forms is a separate commercial plugin that is not available on WordPress.org and is not included with this plugin. You must install and license it yourself.

This plugin is not affiliated with, endorsed by, or sponsored by Rocketgenius (Gravity Forms), Google, or Firebase.

Features

  • Phone OTP verification with Firebase Authentication. The visitor receives an SMS code, and your server verifies the resulting Firebase ID token during form validation, so the check cannot be bypassed from the browser.
  • SMS notifications after submission through MSG91 (Flow API v5 or the legacy API) or Twilio, with {{field_X}} placeholders and Gravity Forms merge tags in the message.
  • Optional Firebase App Check (off by default) to help stop SMS abuse.
  • Slack notifications to a public or private channel.
  • Built on the Gravity Forms Add-On Framework: settings live under Forms > Settings (Phone OTP, SMS & Slack) and per form under the form’s Settings tab, like other Gravity Forms add-ons.
  • Notification feeds: add as many SMS and Slack notifications per form as you need, each with its own message and its own conditional logic.
  • Send a test SMS or Slack message from the feed screen, using the values you have typed (no need to save first).
  • Entry notes record each notification, and failures are logged to the entry and to the Gravity Forms logs.
  • Works with AJAX and multi-page forms, and with several OTP forms on one page.
  • Translation ready.

External services

This plugin connects to the third-party services below. Each one is used only after you configure it under Forms > Settings and in your forms (you need your own account with that service). Nothing is sent to the plugin author.

Google Firebase Authentication

  • Service: https://firebase.google.com/products/auth
  • What it is used for: sending the one-time SMS code to the visitor and confirming it.
  • When and what data is sent: only on forms where you set a Phone field and OTP field, and only after the visitor clicks “Send code”. The Firebase SDK is bundled with the plugin and served from your own site; it does not contact Google until that click. It then sends the phone number to Google (identitytoolkit.googleapis.com and securetoken.googleapis.com, plus your Firebase project’s auth domain, e.g. your-project.firebaseapp.com). When the visitor clicks “Verify code”, the code they typed is sent to check it. Google sends the SMS and creates a phone-number user in your Firebase project.
  • Terms of service: https://firebase.google.com/terms
  • Privacy policy: https://policies.google.com/privacy

Google reCAPTCHA

  • Service: https://www.google.com/recaptcha/about/
  • What it is used for: Firebase Authentication requires an invisible reCAPTCHA check to prevent abuse of SMS sending.
  • When and what data is sent: loaded in the visitor’s browser by Firebase when they click “Send code”. Google receives the browser and interaction data it uses for reCAPTCHA.
  • Terms of service: https://policies.google.com/terms
  • Privacy policy: https://policies.google.com/privacy

Google public key endpoint (Firebase token verification)

  • Service: https://firebase.google.com/docs/auth/admin/verify-id-tokens
  • What it is used for: your server downloads Google’s public certificates from https://www.googleapis.com/robot/v1/metadata/x509/securetoken@system.gserviceaccount.com to check that a submitted verification token is genuine.
  • When and what data is sent: when an OTP-enabled form is submitted and the cached certificates have expired. No personal data is sent; it is a plain download.
  • Terms of service: https://policies.google.com/terms
  • Privacy policy: https://policies.google.com/privacy

Google reCAPTCHA v3 / Enterprise for Firebase App Check (optional)

  • Service: https://firebase.google.com/docs/app-check
  • What it is used for: proving to Firebase that OTP requests come from your genuine website, to help prevent SMS abuse.
  • When and what data is sent: only if you enter an App Check site key on the settings page. The App Check script is bundled and loaded in the visitor’s browser when they click “Send code”; it then loads Google reCAPTCHA and sends the browser and interaction data Google uses for reCAPTCHA, and App Check tokens, to Google. Nothing is sent if the site key is blank.
  • Terms of service: https://policies.google.com/terms
  • Privacy policy: https://policies.google.com/privacy

MSG91

  • Service: https://msg91.com/
  • What it is used for: sending SMS notifications.
  • When and what data is sent: only if MSG91 is the selected SMS provider and a form has an SMS notification feed. Your server sends your MSG91 auth key, the recipient phone number and the Flow template ID with its variable values (Flow API v5), or your auth key, sender ID, the recipient phone number and the message text (legacy API), including any submitted field values you placed in them, to control.msg91.com after the form is submitted, or when you click “Send test” on a feed screen.
  • Terms of service: https://msg91.com/terms-of-use
  • Privacy policy: https://msg91.com/privacy-policy

Twilio

  • Service: https://www.twilio.com/
  • What it is used for: sending SMS notifications.
  • When and what data is sent: only if Twilio is the selected SMS provider and a form has an SMS notification feed. Your server sends your Twilio account SID and auth token, your Twilio number, the recipient phone number and the message text (including any submitted field values you placed in it) to api.twilio.com after the form is submitted, or when you click “Send test” on a feed screen.
  • Terms of service: https://www.twilio.com/en-us/legal/tos
  • Privacy policy: https://www.twilio.com/en-us/legal/privacy

Slack

  • Service: https://slack.com/
  • What it is used for: posting a notification to a Slack channel.
  • When and what data is sent: when you save a new bot token (or ask for a refresh), your server asks slack.com for the list of channels. For each Slack notification feed, your server sends the configured message (including any submitted field values you placed in it) to the chosen channel after the form is submitted, or when you click “Send test” on the feed screen.
  • Terms of service: https://slack.com/terms-of-service
  • Privacy policy: https://slack.com/trust/privacy/privacy-policy

Third-party libraries

This plugin bundles the Firebase JS SDK 12.19.0 compat builds (app, auth and app-check) (assets/vendor/firebase/), licensed under Apache-2.0 (protobuf portions BSD-3-Clause); the license text is included in that folder. The files are the official minified builds. The human-readable source is at https://github.com/firebase/firebase-js-sdk (tag firebase@12.19.0) and on npm at https://www.npmjs.com/package/firebase .

Screenshots

No screenshots provided


Reviews & Comments