| @@ -2,11 +2,11 @@ | ||
| 2 | 2 | Contributors: forge12 |
| 3 | 3 | Donate link: https://www.paypal.com/donate?hosted_button_id=MGZTVZH3L5L2G |
| 4 | 4 | Tags: contact form 7, double opt-in, gdpr, email verification, newsletter |
| 5 | 5 | Requires at least: 6.0 |
| 6 | -Tested up to: 7.1 | |
| 6 | +Tested up to: 7.0 | |
| 7 | 7 | Requires PHP: 7.4 |
| 8 | -Stable tag: 5.9.0 | |
| 8 | +Stable tag: 5.7.0 | |
| 9 | 9 | License: GPLv3 |
| 10 | 10 | License URI: http://www.gnu.org/licenses/gpl-3.0.html |
| 11 | 11 | |
| 12 | 12 | **Protect your Contact Form 7 forms with GDPR-compliant Double Opt-In.** |
| @@ -25,9 +25,8 @@ | ||
| 25 | 25 | |
| 26 | 26 | * Only **valid, verified email addresses** reach your inbox. |
| 27 | 27 | * **GDPR / DSGVO requirements** are met with proper consent tracking, IP logging, and data retention. |
| 28 | 28 | * Your database stays **clean and reliable** -- no fake or mistyped addresses. |
| 29 | -* The form mail **arrives after the confirmation** -- every action that runs after the click is recorded, and temporary failures are retried automatically. | |
| 30 | 29 | |
| 31 | 30 | Out-of-the-box support for **Contact Form 7**. Additional form systems — Avada, Elementor, Gravity Forms, WPForms — are available as separate addon plugins. |
| 32 | 31 | |
| 33 | 32 | = How It Works = |
| @@ -39,10 +38,8 @@ | ||
| 39 | 38 | 5. The confirmed opt-in is logged in the admin dashboard with timestamps and IP addresses for full GDPR compliance. |
| 40 | 39 | |
| 41 | 40 | = Quick Start = |
| 42 | 41 | |
| 43 | -After activation, a setup wizard asks for the sender, the forms that should ask for confirmation, the confirmation email and the page visitors see after the click. Everything is prefilled; it takes about three minutes and can be skipped. | |
| 44 | - | |
| 45 | 42 | [Read the Quick Guide](https://www.forge12.com/blog/so-verwendest-du-das-double-opt-in-fuer-contact-form-7/) |
| 46 | 43 | |
| 47 | 44 | = Free Features = |
| 48 | 45 | |
| @@ -65,9 +62,9 @@ | ||
| 65 | 62 | * **Category System** -- organize opt-ins into categories for better management |
| 66 | 63 | * **Pagination & Search** -- search and filter opt-in records in the admin dashboard |
| 67 | 64 | * **Admin Tooltips** -- contextual help tooltips throughout the admin interface |
| 68 | 65 | * **WordPress Multisite** -- network-wide activation creates tables on all sites automatically |
| 69 | -* **Developer Hooks** -- 48 action hooks, 83 filters, and 13 typed events for full extensibility | |
| 66 | +* **Developer Hooks** -- 44 action hooks, 74 filters, and 11 typed events for full extensibility | |
| 70 | 67 | |
| 71 | 68 | = Pro Features = |
| 72 | 69 | |
| 73 | 70 | Unlock the full potential of Double Opt-In with the [Pro version](https://www.forge12.com/shop/contact-form-7-double-opt-in?from=readme&utm_source=double-opt-in&utm_medium=plugin&utm_campaign=readme): |
| @@ -144,20 +141,8 @@ | ||
| 144 | 141 | = Is this plugin GDPR / DSGVO compliant? = |
| 145 | 142 | |
| 146 | 143 | Yes. The plugin tracks all data required for GDPR compliance: consent text, registration and confirmation timestamps, IP addresses, and form data. It integrates with WordPress Privacy Tools for personal data export and erasure requests. You can configure automatic data retention and anonymization policies. |
| 147 | 144 | |
| 148 | -= Is double opt-in mandatory? = | |
| 149 | - | |
| 150 | -For newsletters and other advertising emails in Germany, practically yes: the sender has to prove consent, and without the confirmation click that proof rarely holds up. No law names the procedure, but courts and data protection authorities expect it. This is general information, not legal advice. [More on the legal situation](https://www.forge12.com/de/blog/double-opt-in-wordpress-pflicht-rechtslage) | |
| 151 | - | |
| 152 | -= Do I need double opt-in for a contact form? = | |
| 153 | - | |
| 154 | -A plain contact request does not need a consent checkbox or double opt-in. It becomes necessary as soon as the form also signs people up for a newsletter or other advertising. You can switch double opt-in on per form, or only when a checkbox is ticked (see "Conditions" below). | |
| 155 | - | |
| 156 | -= What about Switzerland and Austria? = | |
| 157 | - | |
| 158 | -Advertising emails need prior consent there as well, and the sender has to be able to prove it. Double opt-in is the common way to do that, even where the law does not name it. | |
| 159 | - | |
| 160 | 145 | = Which form plugins are supported? = |
| 161 | 146 | |
| 162 | 147 | The free Core plugin supports **Contact Form 7** out of the box. Support for **Avada Forms**, **Elementor Pro Forms**, **WPForms**, and **Gravity Forms** is available through separate paid addon plugins (install alongside Core). |
| 163 | 148 | |
| @@ -176,19 +161,8 @@ | ||
| 176 | 161 | = Can I redirect the user to a specific page after confirmation? = |
| 177 | 162 | |
| 178 | 163 | Yes. In the per-form settings, you can select a **Confirmation Page**. The user will be redirected there after clicking the confirmation link. |
| 179 | 164 | |
| 180 | -= How do I show the right message on the confirmation and error pages? = | |
| 181 | - | |
| 182 | -Put these shortcodes on the page: | |
| 183 | - | |
| 184 | -* `[doi_confirmation_status]` says whether the link just confirmed the address, was already used, has expired or is invalid. Each text can be replaced, for example `[doi_confirmation_status confirmed="Welcome aboard!"]`. | |
| 185 | -* `[doi_field name="your-name"]` shows a value from the form, only right after the confirmation. | |
| 186 | -* `[doi_if status="confirmed"]…[/doi_if]` shows its content only for the listed outcomes (`confirmed`, `already_confirmed`, `expired`, `not_found`, or `none` for a visit without a link), so one page can carry a different text and different buttons for each case. | |
| 187 | -* `[doi_error_message]` on the error page explains why a sign-up was refused (too many attempts, address already signed up, and so on). | |
| 188 | - | |
| 189 | -A page without `[doi_confirmation_status]` still shows a short notice when the link has expired or is invalid. | |
| 190 | - | |
| 191 | 165 | = Does the plugin work with CAPTCHA plugins? = |
| 192 | 166 | |
| 193 | 167 | Yes. The plugin automatically disables CAPTCHA validation (Google reCAPTCHA, hCaptcha, CF7 Captcha by Forge12) when re-sending the original form mail after confirmation. This prevents false spam detections during the confirmation step. CAPTCHA is re-enabled immediately after the mail has been sent. |
| 194 | 168 | |
| @@ -217,9 +191,9 @@ | ||
| 217 | 191 | The free version requires at least one supported form plugin. However, developers can register custom form integrations using the `f12_cf7_doubleoptin_register_integrations` action hook. See the developer documentation for details. |
| 218 | 192 | |
| 219 | 193 | = Where can I find the developer documentation? = |
| 220 | 194 | |
| 221 | -A hook, filter, and event reference with code examples ships at `docs/hooks-and-events.md` inside the plugin directory. It documents 29 of the 48 action hooks, 25 of the 83 filters, and all 13 typed events — the ones extensions actually reach for. The rest are discoverable in the source; if you need one documented, ask and we will add it. | |
| 195 | +A hook, filter, and event reference with code examples ships at `docs/hooks-and-events.md` inside the plugin directory. It documents 27 of the 44 action hooks, 22 of the 74 filters, and all 11 typed events — the ones extensions actually reach for. The rest are discoverable in the source; if you need one documented, ask and we will add it. | |
| 222 | 196 | |
| 223 | 197 | = How do I report a bug or request a feature? = |
| 224 | 198 | |
| 225 | 199 | Please visit [forge12.com](https://www.forge12.com) or contact us via the WordPress support forum. |
| @@ -264,17 +238,8 @@ | ||
| 264 | 238 | licensed under the SIL Open Font License 1.1 (see licenses/inter-OFL-1.1.txt). |
| 265 | 239 | |
| 266 | 240 | == Upgrade Notice == |
| 267 | 241 | |
| 268 | -= 5.9.0 = | |
| 269 | -Withdrawn opt-ins show as "Revoked", the setup wizard covers every form plugin, and the confirmation page can show content per outcome. Pro users: update the add-ons too. | |
| 270 | - | |
| 271 | -= 5.8.1 = | |
| 272 | -Fixes German admin texts. No functional changes. | |
| 273 | - | |
| 274 | -= 5.8.0 = | |
| 275 | -Shows whether each confirmation email reached your mail server and tells Contact Form 7 visitors to confirm their address. Pro users: update the email editor and opt-out add-ons too. | |
| 276 | - | |
| 277 | 242 | = 5.7.0 = |
| 278 | 243 | Adds a setup wizard for new installations. Existing forms and settings are not changed. |
| 279 | 244 | |
| 280 | 245 | = 5.6.3 = |
| @@ -372,46 +337,8 @@ | ||
| 372 | 337 | = 3.1.0 = |
| 373 | 338 | Adds optional anonymous telemetry (opt-out). No breaking changes. |
| 374 | 339 | |
| 375 | 340 | == Changelog == |
| 376 | - | |
| 377 | -= 5.9.0 = | |
| 378 | - | |
| 379 | -**Withdrawals, every form plugin in the setup wizard, a confirmation page per outcome** | |
| 380 | - | |
| 381 | -* New: opt-ins withdrawn through the opt-out show as "Revoked" (filter in the list, detail page, its own dashboard card) instead of "Pending"; the original confirmation stays visible. | |
| 382 | -* New: the setup wizard offers the forms of every installed form plugin (WPForms, Elementor Pro, Gravity Forms and Avada with their add-ons), not only Contact Form 7, and finds the email field by its label. | |
| 383 | -* New: [doi_if status="confirmed"]…[/doi_if] shows its content only for the given outcome of the confirmation link, so one page can greet, explain an expired link and offer the form again. | |
| 384 | -* New: the form settings warn when the stored consent text differs from the text next to the checkbox in the form (Contact Form 7), and take that text over in one click. Developers: FieldTextProviderInterface and the filter f12_doi_form_field_texts. | |
| 385 | -* Fix: an add-on installed or activated on the Add-ons page works without reloading the page. | |
| 386 | -* Fix: the audit log showed event types as internal keys and some messages in English; its rate-limit filter found nothing. | |
| 387 | -* Fix: the WordPress personal data export described the mail status as "sent" instead of in words. | |
| 388 | -* Fix: the opt-in list showed category numbers instead of names; the forms page said "1 forms". | |
| 389 | -* Fix: the credit request, the deactivation survey and the feedback links were not translated; the French translation had no plural rules. | |
| 390 | - | |
| 391 | -= 5.8.1 = | |
| 392 | -* Fix: on sites in formal German (Sie), a sentence on the user creation page was shown in English, and the role appeared as its internal key ("subscriber") instead of its name. | |
| 393 | -* Fix: German admin texts used the English names "Conditional Templates", "User Creation" and "Unique Email"; they now use the German terms throughout. | |
| 394 | -* Fix: the breadcrumb on add-on settings pages read "Page". | |
| 395 | - | |
| 396 | -= 5.8.0 = | |
| 397 | - | |
| 398 | -**Know whether the confirmation email went out** | |
| 399 | - | |
| 400 | -* New: every opt-in records whether its confirmation email was handed to your mail server or failed, and why. Shown in the opt-in list (with a filter), on the detail page and in Site Health; included in the WordPress privacy export and eraser. | |
| 401 | -* New: after a Contact Form 7 submission, visitors read "please confirm your address" with the sender and subject to look for, instead of "Thank you for your message". When the email could not be sent, they are told so. | |
| 402 | -* New: Site Health checks SPF and DMARC of the sender domain, the two most common reasons confirmation emails land in spam. | |
| 403 | -* New: a dashboard hint when many recent opt-ins stay unconfirmed. | |
| 404 | -* New: shortcodes [doi_confirmation_status], [doi_error_message] and [doi_field] for the confirmation and error pages, and a readable message when a link is broken or expired. | |
| 405 | -* New: a hidden honeypot field and a minimum fill time keep simple bots away from Contact Form 7 double opt-in forms. | |
| 406 | -* New: the forms page suggests add-ons only for form plugins that are installed on the site. | |
| 407 | -* New: after ten confirmations, a one-time request for a review, only on the plugin's own pages. | |
| 408 | -* Changed: the free plugin no longer contains locked Pro features. Email template management and the opt-out page generator now live in their add-ons. If you use them, update the email editor add-on to 1.1.0 and the opt-out add-on to 1.5.0; Site Health reminds you. | |
| 409 | -* Changed: a renewed consent after an opt-out no longer overwrites the original confirmation; it gets its own entry in the audit log. | |
| 410 | -* Fix: the Activate button on the Add-ons page and links in REST responses were broken ("&" in the URL). | |
| 411 | -* Fix: Avada forms without a notification were reported as a failed follow-up action. | |
| 412 | -* Fix: several admin texts stayed English on translated sites; the breadcrumb read "Page" on detail pages; a waiting button now shows a countdown. | |
| 413 | -* Developers: Core API 4.6.0 with the filters f12_doi_submit_notice_data and f12_doi_mail_headers, the events f12_doi_optin_opted_out and f12_doi_optin_reopted_in, follow-up adapters for add-ons and a shared resend service. | |
| 414 | 341 | |
| 415 | 342 | = 5.7.0 = |
| 416 | 343 | |
| 417 | 344 | **A setup wizard gets new sites to the first working confirmation email** |