| 开发者 | rayasoren |
|---|---|
| 更新时间 | 2026年9月30日 11:11 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
myotp_verified_phone.[myotp_verify]: the same widget on any page. Fires a myotp:verified event on document with the number in event.detail.phone.manage_options.myotp_pv_site_hourly_cap filter). The site-wide count uses a fixed one-hour window that starts at the first send, so up to twice the ceiling can go out across a window boundary. It exists to bound what an attacker with many addresses and many numbers can make the site spend. A code that was not billed (provider answered 409 or a server error) is not counted against it.myotp_pv_express_wallet_gateways filter (gateway id => list of request fields that mark a wallet order) and myotp_pv_express_wallet_types.
External service
This plugin sends the phone number a visitor enters to the MyOTP.App API at https://api.myotp.app to deliver a one-time code and to check the code the visitor types. No other data is sent. MyOTP.App privacy policy: https://myotp.app/privacy-policy/. Terms: https://myotp.app/term-condition/.
Data stored on your site
myotp_pv_sid (random id, one day) so a guest's verification can be tied to their browser.myotp_pv_kv_ prefix, not autoloaded): rate-limit counters (a row lives for one window after the last send it counted: 10 minutes, site-wide 1 hour), the pending number with its code reference and attempt count (kept for the configured code validity, at most 4 hours), a 15-minute per-visitor cooldown row after five wrong codes, and the verified number (30 minutes). Expired rows are removed on the next read of that row and by a daily WP-Cron sweep (myotp_pv_sweep). WP-Cron runs on page visits, so on a quiet site the sweep can run later than scheduled._myotp_verified_phone on each verified WooCommerce order. With "Ask for the code after payment", a held order also carries _myotp_pv_awaiting (the wallet type) and _myotp_pv_restore_status (the status to restore) until it is verified, and the store keeps that order's pending code, attempt count and send counter for the code validity.myotp_verified_phone on each account registered through the verified form.myotp-phone-verification folder to /wp-content/plugins/, or upload the zip from Plugins > Add New > Upload Plugin.Country code first, digits only, no plus sign. 14155550123, not +1 (415) 555-0123. The plugin strips spaces, dashes and the plus sign before sending.
Yes, from 1.1.0. The Send code button appears under the phone field and the order is refused until that number is verified, same as the classic [woocommerce_checkout] page. For a returning shopper whose saved address is shown as a card with an Edit link, the Send code button sits right under that card and sends to the saved phone number. If the saved address has no phone number, pressing Send code (or a refused Place order) opens the address form at the phone field. Keep the phone field visible in the checkout block; with it hidden there is nothing to verify.
Yes. Wallet buttons skip the checkout form, so pick what happens to those orders under "Apple Pay / Google Pay and other express wallet orders" in Settings > MyOTP: allow them without a code (the default), hold them until the shopper verifies the order's phone after paying, or block them. The plugin recognises wallet orders from WooPayments and WooCommerce Stripe Payment Gateway; any other request goes through the normal code check.
Not with another payment method. A wallet order is recognised only when the chosen payment method is one of the wallet gateways (WooPayments or WooCommerce Stripe Payment Gateway) and the request carries that gateway's wallet marker. The same marker sent with cash on delivery, bank transfer or any other gateway is ignored and the code is required. The plain limit: those markers come from the shopper's browser. Someone who edits the request by hand can send a wallet marker while paying with an ordinary card through WooPayments or Stripe, and the order is then treated as a wallet order (placed without a code, or held until verified, depending on the setting). They still had to pay through that gateway, with the gateway's own fraud checks. If you need every order verified with no exception, choose "Ask for the code after payment" or "Block".
A number that is not there cannot be verified. While verification is on (and, with "Only for guests", for guests), the plugin shows WooCommerce's checkout phone field as required on both the block and the classic checkout, even when WooCommerce's own setting says optional. Your WooCommerce setting is not changed; Settings > MyOTP says when it is being overridden.
Yes. Tick "Only for guests" under WooCommerce checkout in Settings > MyOTP.
Listen for the event:
document.addEventListener('myotp:verified', function (e) { console.log(e.detail.phone); });
The plugin reads REMOTE_ADDR only, because forwarding headers can be forged by the client. Behind a proxy that address may be the proxy itself, so every visitor shares one per-IP bucket and the site-wide hourly ceiling is the real backstop. If your host guarantees a trusted header, return the real address from the myotp_pv_client_ip filter.
Shoppers only ever see a short message asking them to try again or contact the shop; the verification service's own error text is not shown to them. The detail goes to WooCommerce > Status > Logs (source myotp-phone-verification) and to a notice in the WordPress admin for a day, with phone numbers removed. A common cause is the Brand setting: it must be 3 to 16 letters or digits, with no spaces.
Yes. A test send is a real send.
In the myotp_pv_options option, on the server only. It is shown masked on the settings page and removed on uninstall.
[myotp_verify] shortcode, settings page with test send.