PluginProbe
Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification / 5.7.0
Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification v5.7.0
5.9.0 5.8.0 5.8.1 5.7.0 5.6.2 5.6.3 5.6.1 5.6.0 5.5.0 5.4.0 5.3.2 5.3.1 5.1.6 5.1.5 trunk 2.1.5 2.11 2.12 2.13 2.15 3.0.0 3.0.1 3.0.2 3.0.3 3.0.5 All 42 releases
← All changes | readme.txt +76 -18 5.5.0 → 5.7.0 View file →
@@ -1,12 +1,12 @@
1 1 === Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification ===
2 2 Contributors: forge12
3 3 Donate link: https://www.paypal.com/donate?hosted_button_id=MGZTVZH3L5L2G
4 -Tags: contact form 7, double opt-in, gdpr, email verification
4 +Tags: contact form 7, double opt-in, gdpr, email verification, newsletter
5 5 Requires at least: 6.0
6 6 Tested up to: 7.0
7 7 Requires PHP: 7.4
8 -Stable tag: 5.5.0
8 +Stable tag: 5.7.0
9 9 License: GPLv3
10 10 License URI: http://www.gnu.org/licenses/gpl-3.0.html
11 11
12 12 **Protect your Contact Form 7 forms with GDPR-compliant Double Opt-In.**
@@ -42,13 +42,12 @@
42 42 [Read the Quick Guide](https://www.forge12.com/blog/so-verwendest-du-das-double-opt-in-fuer-contact-form-7/)
43 43
44 44 = Free Features =
45 45
46 -* **Block-Based Email Templates** -- build your confirmation email from heading, text, button, spacer, divider and placeholder blocks
47 46 * **Double Opt-In for Contact Form 7** -- per-form activation with full CF7 integration
48 47 * **Centralized Form Settings** -- manage all form integrations from a single admin panel
49 -* **Email Template Presets** -- start from a pre-built template (one saved template on the free version)
50 -* **Send Test Email** -- preview your confirmation emails before going live
48 +* **Built-In Email Designs** -- write the confirmation email per form and pick one of three ready-made HTML layouts, or send it plain
49 +* **Resend Confirmation** -- resend the confirmation email to a single recipient from the opt-in detail view
51 50 * **Custom Confirmation Pages** -- redirect users to a specific page after confirmation
52 51 * **Dynamic Conditions** -- enable opt-in based on user input (e.g. only when a checkbox is checked)
53 52 * **Delete Confirmation Modal** -- safety dialog before deleting an opt-in record to prevent accidental deletion
54 53 * **GDPR Consent Export** -- export individual consent records as JSON or CSV directly from the opt-in detail view
@@ -63,13 +62,13 @@
63 62 * **Category System** -- organize opt-ins into categories for better management
64 63 * **Pagination & Search** -- search and filter opt-in records in the admin dashboard
65 64 * **Admin Tooltips** -- contextual help tooltips throughout the admin interface
66 65 * **WordPress Multisite** -- network-wide activation creates tables on all sites automatically
67 -* **Developer Hooks** -- 43 action hooks, 71 filters, and 11 typed events for full extensibility
66 +* **Developer Hooks** -- 44 action hooks, 74 filters, and 11 typed events for full extensibility
68 67
69 68 = Pro Features =
70 69
71 -Unlock the full potential of Double Opt-In with the [Pro version](https://www.forge12.com):
70 +Unlock the full potential of Double Opt-In with the [Pro version](https://www.forge12.com/shop/contact-form-7-double-opt-in?from=readme&utm_source=double-opt-in&utm_medium=plugin&utm_campaign=readme):
72 71
73 72 **Additional Form Integrations:**
74 73
75 74 * **Double Opt-In for Elementor Forms** -- seamless integration with Elementor's form widget
@@ -85,10 +84,9 @@
85 84 **Email & Communication:**
86 85
87 86 * **Double Opt-Out System** -- unique opt-out links per submission with confirmation emails
88 87 * **Opt-In Reminder System** -- automatic reminders for unconfirmed opt-ins via cron
89 -* **Visual Email Editor** -- drag & drop editor with live preview and mobile preview, plus unlimited saved templates
90 -* **Resend Confirmation** -- resend the confirmation email to a single recipient from the admin dashboard
88 +* **Visual Email Editor** -- drag & drop block editor with live preview and mobile preview, template presets, unlimited saved templates and test emails
91 89 * **Conditional Email Templates** -- dynamic content blocks based on form data
92 90 * **Multi-Column Layouts** -- 2-column, 3-column, and sidebar layouts in the email editor
93 91 * **Image & Social Blocks** -- add images and social media icons to your emails
94 92
@@ -153,9 +151,9 @@
153 151 If you configured Double Opt-In on an Avada form before Core 5.0, a one-time notice appears in your WordPress admin with a **"Claim free Avada grandfather license"** button. One click installs the paid Avada addon with a permanent free license bound to your site. Your existing setup continues working with zero configuration changes. The free claim window is open until October 2026.
154 152
155 153 = Can I customize the confirmation email? =
156 154
157 -Yes. The plugin includes a visual drag & drop email editor with block-based design. You can choose from pre-built template presets or create your own. Placeholders like `[doubleoptinlink]`, `[doubleoptin_form_date]`, and form field values are replaced automatically.
155 +Yes. In the free version you write subject and text of the confirmation email in each form's settings and choose one of three built-in designs or plain text. Placeholders like `[doubleoptinlink]`, `[doubleoptin_form_date]`, and form field values are replaced automatically. The Pro version adds a visual drag & drop editor with template presets, reusable templates and test emails.
158 156
159 157 = What happens if the user does not confirm? =
160 158
161 159 Unconfirmed opt-ins are stored in the database and can be cleaned up automatically. You can configure the retention period for unconfirmed entries in the settings (e.g. delete after 30 days). In the Pro version, you can also send automatic reminder emails.
@@ -193,9 +191,9 @@
193 191 The free version requires at least one supported form plugin. However, developers can register custom form integrations using the `f12_cf7_doubleoptin_register_integrations` action hook. See the developer documentation for details.
194 192
195 193 = Where can I find the developer documentation? =
196 194
197 -A hook, filter, and event reference with code examples ships at `docs/hooks-and-events.md` inside the plugin directory. It documents 26 of the 43 action hooks, 20 of the 71 filters, and all 11 typed events — the ones extensions actually reach for. The rest are discoverable in the source; if you need one documented, ask and we will add it.
195 +A hook, filter, and event reference with code examples ships at `docs/hooks-and-events.md` inside the plugin directory. It documents 27 of the 44 action hooks, 22 of the 74 filters, and all 11 typed events — the ones extensions actually reach for. The rest are discoverable in the source; if you need one documented, ask and we will add it.
198 196
199 197 = How do I report a bug or request a feature? =
200 198
201 199 Please visit [forge12.com](https://www.forge12.com) or contact us via the WordPress support forum.
@@ -201,15 +199,16 @@
201 199 Please visit [forge12.com](https://www.forge12.com) or contact us via the WordPress support forum.
202 200
203 201 == Screenshots ==
204 202
205 -1. **Opt-In Dashboard** -- Overview of all opt-in records with status, email, form, date, and actions.
206 -2. **Form Settings** -- Per-form configuration with sender, subject, recipient field, confirmation page, and conditions.
207 -3. **Email Template Editor** -- Visual drag & drop editor with blocks, live preview, and mobile preview.
208 -4. **Template Presets** -- Choose from pre-built email template designs.
209 -5. **Single Opt-In View** -- Detailed view of an opt-in record with form data, timestamps, and IP addresses.
210 -6. **Global Settings** -- Configure data retention, token expiry, telemetry, and opt-out settings.
211 -7. **Category Management** -- Organize opt-in records into categories.
203 +1. **Dashboard** -- Total, confirmed and pending opt-ins at a glance, with the latest submissions.
204 +2. **Opt-In list** -- Every record with form, status and date; search and filter by status, follow-up actions and mail delivery.
205 +3. **Opt-in detail** -- Timestamps and IP addresses of request and confirmation, the consent text, and whether the form mail ran after the click.
206 +4. **Forms** -- All Contact Form 7 forms with Double Opt-In switched on or off per form.
207 +5. **Form settings** -- Consent text, acceptance field, category, sender, subject and confirmation page for one form.
208 +6. **Setup wizard** -- Sender, forms, confirmation email and the page after the click, in four steps.
209 +7. **Settings** -- Data retention, privacy policy page, token expiry and rate limits.
210 +8. **What the visitor sees** -- After submitting: where the confirmation mail comes from and what to do if it does not arrive.
212 211
213 212 == Privacy & Telemetry ==
214 213
215 214 **As of version 5.1.7 the plugin no longer transmits any telemetry.** The daily
@@ -239,8 +238,23 @@
239 238 licensed under the SIL Open Font License 1.1 (see licenses/inter-OFL-1.1.txt).
240 239
241 240 == Upgrade Notice ==
242 241
242 += 5.7.0 =
243 +Adds a setup wizard for new installations. Existing forms and settings are not changed.
244 +
245 += 5.6.3 =
246 +Ships the hook and Addon API reference the readme refers to. No functional changes.
247 +
248 += 5.6.2 =
249 +Visitors who forget the consent checkbox now see why their sign-up was not accepted, instead of a success message. No settings or data change.
250 +
251 += 5.6.1 =
252 +Fixes a blank or partly loaded Double Opt-In admin on sites with Avada and other themes or plugins that use the Underscore/Lodash library. No settings or data change.
253 +
254 += 5.6.0 =
255 +Security release — update recommended. Also records every action that runs after the confirmation click, retries temporary failures automatically and shows the result on each opt-in. Adds one database table, created automatically on update. If you use the Elementor, Avada, WPForms or Gravity Forms add-ons, update them after this release.
256 +
243 257 = 5.5.0 =
244 258 Recommended if you ever ran a Double Opt-In Pro older than 4.0. Such a plugin, left installed next to the current modules, made WordPress fail with a critical error that also locked you out of the admin. This release keeps the site reachable in that situation and adds two Site Health checks that name the problem and repair it in one click. Nothing is deleted from your server, and no schema changes.
245 259
246 260 = 5.4.0 =
@@ -323,8 +337,52 @@
323 337 = 3.1.0 =
324 338 Adds optional anonymous telemetry (opt-out). No breaking changes.
325 339
326 340 == Changelog ==
341 +
342 += 5.7.0 =
343 +
344 +**A setup wizard gets new sites to the first working confirmation email**
345 +
346 +* New: after installing the plugin, a short wizard sets up the sender, the Contact Form 7 forms that should ask for confirmation, the confirmation email and the page visitors see after clicking the link. Everything is prefilled; it takes about three minutes and can be skipped at any time. A test email to yourself shows the result before visitors see it.
347 +* New: the sender name and address from the wizard are used for every form you switch on later. Confirmation emails without a sender name no longer arrive as "WordPress".
348 +* New: if you also use Elementor Pro, WPForms, Gravity Forms or Avada Forms, the wizard tells you which add-on protects those forms.
349 +* Improved: forms that already use Double Opt-In are left exactly as they are. Existing sites do not see the wizard unless you start it under Settings.
350 +* Fix: this description listed the visual email editor, saved templates and test emails as free features. They are part of the email editor add-on; the free plugin offers three built-in email designs. Resending a confirmation email from the opt-in details is free.
351 +
352 += 5.6.3 =
353 +
354 +* Fix: the developer reference this readme points to — `docs/hooks-and-events.md` and `docs/addon-api.md` — was never actually included in the plugin. Both files now ship.
355 +* Improved: the notice for major updates on the Plugins screen no longer starts with an emoji; it already sits in a warning box.
356 +
357 += 5.6.2 =
358 +
359 +**A refused consent no longer looks like a successful sign-up**
360 +
361 +* Fix: when a visitor left the consent checkbox unticked, Contact Form 7 still showed "Thank you for your message. It has been sent." and emptied the form. The actual reason appeared only in a small notice that disappeared after ten seconds — so the visitor believed they were subscribed and waited for a confirmation mail that never came. The form now stops with "You must agree to the consent statement to continue." and keeps everything the visitor typed; they only have to tick the box.
362 +* Fix: the same on Elementor, WPForms and Gravity Forms forms — the consent checkbox is now marked the way a missed required field is, and the form stays on the page with the visitor's input. This needs the Elementor add-on 1.2.1, the WPForms add-on 1.1.1 and the Gravity Forms add-on 1.1.1. With older add-ons the success message is at least hidden and the notice stays until the visitor closes it.
363 +* Developer: new `AbstractFormIntegration::refusedConsentBeforeSubmit()` for integrations whose submit hook runs after the form plugin has accepted the submission (Core API 4.5.0, additive).
364 +* Note: this applies to the consent checkbox only. Other refusals (rate limits, blocked domains, …) keep their current behaviour and can be shown in the form with the filter `f12_cf7_doubleoptin_show_validation_error`, which now also receives the error and the form ID.
365 +
366 += 5.6.1 =
367 +
368 +**The admin no longer stays blank next to Avada and similar plugins**
369 +
370 +* Fix: on some sites the Double Opt-In admin stayed blank or loaded only partly after 5.6.0, depending on the browser, with "clearTimeout is not a function" in the browser console. The admin script accidentally registered an internal helper under the global name `_`, which WordPress and many themes and plugins (Avada among them) use for the Underscore/Lodash library. Whichever loaded last won. The admin script now keeps all of its names to itself, and it no longer replaces WordPress' own `_` either.
371 +
372 += 5.6.0 =
373 +
374 +**What happens after the confirmation click is now recorded, retried and visible**
375 +
376 +* Security: a crafted request could switch off the double opt-in for a single submission, so the form's follow-up actions ran without a confirmed address. This is closed for all form systems. Update recommended.
377 +* New: every action that runs after a subscriber confirms — the form's notification mail, the stored entry, and for Elementor each "Actions After Submit" step — is now recorded individually with its outcome. The opt-in detail page shows them in a new "Follow-up actions" panel.
378 +* New: an action that fails for a temporary reason (mail server unreachable, timeout) is retried automatically after 1, 5 and 30 minutes. Actions that already succeeded are never run again, so a retry does not send a second mail or write a second entry. An action whose outcome is unclear (the connection broke after the request was sent) is not retried automatically; the panel says so and asks before you retry it by hand.
379 +* New: a "Retry failed actions" button on the opt-in detail page, and a "Follow-ups need attention" filter in the opt-in list. A manual retry starts a fresh set of automatic attempts.
380 +* New: a Site Health check when follow-up actions keep failing, and entries in the audit log for every attempt.
381 +* Fix: on Elementor forms the actions after the confirmation could be cut short by a CAPTCHA or honeypot field that was checked a second time, long after the visitor had passed it.
382 +* Fix: a second click on the confirmation link no longer runs the follow-up actions again.
383 +* Fix: with debug logging switched on, the log files could be downloaded from the uploads folder. The folder is now protected and the files carry names that cannot be guessed; existing log files are renamed on the next request.
384 +* Developer: new filter `f12_doi_follow_up_backoff` and adapter interface for form integrations; Core API 4.4.0 (additive, no breaking change).
327 385
328 386 = 5.5.0 =
329 387
330 388 **An old Pro plugin no longer takes the site down with it**