PluginProbe
Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification / 5.8.1
Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification v5.8.1
5.9.0 5.8.0 5.8.1 5.7.0 5.6.2 5.6.3 5.6.1 5.6.0 5.5.0 5.4.0 5.3.2 5.3.1 5.1.6 5.1.5 trunk 2.1.5 2.11 2.12 2.13 2.15 3.0.0 3.0.1 3.0.2 3.0.3 3.0.5 All 42 releases
← All changes | readme.txt +86 -19 5.6.3 → 5.8.1 View file →
@@ -1,12 +1,12 @@
1 1 === Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification ===
2 2 Contributors: forge12
3 3 Donate link: https://www.paypal.com/donate?hosted_button_id=MGZTVZH3L5L2G
4 -Tags: contact form 7, double opt-in, gdpr, email verification
4 +Tags: contact form 7, double opt-in, gdpr, email verification, newsletter
5 5 Requires at least: 6.0
6 -Tested up to: 7.0
6 +Tested up to: 7.1
7 7 Requires PHP: 7.4
8 -Stable tag: 5.6.3
8 +Stable tag: 5.8.1
9 9 License: GPLv3
10 10 License URI: http://www.gnu.org/licenses/gpl-3.0.html
11 11
12 12 **Protect your Contact Form 7 forms with GDPR-compliant Double Opt-In.**
@@ -25,8 +25,9 @@
25 25
26 26 * Only **valid, verified email addresses** reach your inbox.
27 27 * **GDPR / DSGVO requirements** are met with proper consent tracking, IP logging, and data retention.
28 28 * Your database stays **clean and reliable** -- no fake or mistyped addresses.
29 +* The form mail **arrives after the confirmation** -- every action that runs after the click is recorded, and temporary failures are retried automatically.
29 30
30 31 Out-of-the-box support for **Contact Form 7**. Additional form systems — Avada, Elementor, Gravity Forms, WPForms — are available as separate addon plugins.
31 32
32 33 = How It Works =
@@ -38,17 +39,18 @@
38 39 5. The confirmed opt-in is logged in the admin dashboard with timestamps and IP addresses for full GDPR compliance.
39 40
40 41 = Quick Start =
41 42
43 +After activation, a setup wizard asks for the sender, the forms that should ask for confirmation, the confirmation email and the page visitors see after the click. Everything is prefilled; it takes about three minutes and can be skipped.
44 +
42 45 [Read the Quick Guide](https://www.forge12.com/blog/so-verwendest-du-das-double-opt-in-fuer-contact-form-7/)
43 46
44 47 = Free Features =
45 48
46 -* **Block-Based Email Templates** -- build your confirmation email from heading, text, button, spacer, divider and placeholder blocks
47 49 * **Double Opt-In for Contact Form 7** -- per-form activation with full CF7 integration
48 50 * **Centralized Form Settings** -- manage all form integrations from a single admin panel
49 -* **Email Template Presets** -- start from a pre-built template (one saved template on the free version)
50 -* **Send Test Email** -- preview your confirmation emails before going live
51 +* **Built-In Email Designs** -- write the confirmation email per form and pick one of three ready-made HTML layouts, or send it plain
52 +* **Resend Confirmation** -- resend the confirmation email to a single recipient from the opt-in detail view
51 53 * **Custom Confirmation Pages** -- redirect users to a specific page after confirmation
52 54 * **Dynamic Conditions** -- enable opt-in based on user input (e.g. only when a checkbox is checked)
53 55 * **Delete Confirmation Modal** -- safety dialog before deleting an opt-in record to prevent accidental deletion
54 56 * **GDPR Consent Export** -- export individual consent records as JSON or CSV directly from the opt-in detail view
@@ -63,13 +65,13 @@
63 65 * **Category System** -- organize opt-ins into categories for better management
64 66 * **Pagination & Search** -- search and filter opt-in records in the admin dashboard
65 67 * **Admin Tooltips** -- contextual help tooltips throughout the admin interface
66 68 * **WordPress Multisite** -- network-wide activation creates tables on all sites automatically
67 -* **Developer Hooks** -- 44 action hooks, 72 filters, and 11 typed events for full extensibility
69 +* **Developer Hooks** -- 48 action hooks, 82 filters, and 13 typed events for full extensibility
68 70
69 71 = Pro Features =
70 72
71 -Unlock the full potential of Double Opt-In with the [Pro version](https://www.forge12.com):
73 +Unlock the full potential of Double Opt-In with the [Pro version](https://www.forge12.com/shop/contact-form-7-double-opt-in?from=readme&utm_source=double-opt-in&utm_medium=plugin&utm_campaign=readme):
72 74
73 75 **Additional Form Integrations:**
74 76
75 77 * **Double Opt-In for Elementor Forms** -- seamless integration with Elementor's form widget
@@ -85,10 +87,9 @@
85 87 **Email & Communication:**
86 88
87 89 * **Double Opt-Out System** -- unique opt-out links per submission with confirmation emails
88 90 * **Opt-In Reminder System** -- automatic reminders for unconfirmed opt-ins via cron
89 -* **Visual Email Editor** -- drag & drop editor with live preview and mobile preview, plus unlimited saved templates
90 -* **Resend Confirmation** -- resend the confirmation email to a single recipient from the admin dashboard
91 +* **Visual Email Editor** -- drag & drop block editor with live preview and mobile preview, template presets, unlimited saved templates and test emails
91 92 * **Conditional Email Templates** -- dynamic content blocks based on form data
92 93 * **Multi-Column Layouts** -- 2-column, 3-column, and sidebar layouts in the email editor
93 94 * **Image & Social Blocks** -- add images and social media icons to your emails
94 95
@@ -143,8 +144,20 @@
143 144 = Is this plugin GDPR / DSGVO compliant? =
144 145
145 146 Yes. The plugin tracks all data required for GDPR compliance: consent text, registration and confirmation timestamps, IP addresses, and form data. It integrates with WordPress Privacy Tools for personal data export and erasure requests. You can configure automatic data retention and anonymization policies.
146 147
148 += Is double opt-in mandatory? =
149 +
150 +For newsletters and other advertising emails in Germany, practically yes: the sender has to prove consent, and without the confirmation click that proof rarely holds up. No law names the procedure, but courts and data protection authorities expect it. This is general information, not legal advice. [More on the legal situation](https://www.forge12.com/de/blog/double-opt-in-wordpress-pflicht-rechtslage)
151 +
152 += Do I need double opt-in for a contact form? =
153 +
154 +A plain contact request does not need a consent checkbox or double opt-in. It becomes necessary as soon as the form also signs people up for a newsletter or other advertising. You can switch double opt-in on per form, or only when a checkbox is ticked (see "Conditions" below).
155 +
156 += What about Switzerland and Austria? =
157 +
158 +Advertising emails need prior consent there as well, and the sender has to be able to prove it. Double opt-in is the common way to do that, even where the law does not name it.
159 +
147 160 = Which form plugins are supported? =
148 161
149 162 The free Core plugin supports **Contact Form 7** out of the box. Support for **Avada Forms**, **Elementor Pro Forms**, **WPForms**, and **Gravity Forms** is available through separate paid addon plugins (install alongside Core).
150 163
@@ -153,9 +166,9 @@
153 166 If you configured Double Opt-In on an Avada form before Core 5.0, a one-time notice appears in your WordPress admin with a **"Claim free Avada grandfather license"** button. One click installs the paid Avada addon with a permanent free license bound to your site. Your existing setup continues working with zero configuration changes. The free claim window is open until October 2026.
154 167
155 168 = Can I customize the confirmation email? =
156 169
157 -Yes. The plugin includes a visual drag & drop email editor with block-based design. You can choose from pre-built template presets or create your own. Placeholders like `[doubleoptinlink]`, `[doubleoptin_form_date]`, and form field values are replaced automatically.
170 +Yes. In the free version you write subject and text of the confirmation email in each form's settings and choose one of three built-in designs or plain text. Placeholders like `[doubleoptinlink]`, `[doubleoptin_form_date]`, and form field values are replaced automatically. The Pro version adds a visual drag & drop editor with template presets, reusable templates and test emails.
158 171
159 172 = What happens if the user does not confirm? =
160 173
161 174 Unconfirmed opt-ins are stored in the database and can be cleaned up automatically. You can configure the retention period for unconfirmed entries in the settings (e.g. delete after 30 days). In the Pro version, you can also send automatic reminder emails.
@@ -163,8 +176,18 @@
163 176 = Can I redirect the user to a specific page after confirmation? =
164 177
165 178 Yes. In the per-form settings, you can select a **Confirmation Page**. The user will be redirected there after clicking the confirmation link.
166 179
180 += How do I show the right message on the confirmation and error pages? =
181 +
182 +Put these shortcodes on the page:
183 +
184 +* `[doi_confirmation_status]` says whether the link just confirmed the address, was already used, has expired or is invalid. Each text can be replaced, for example `[doi_confirmation_status confirmed="Welcome aboard!"]`.
185 +* `[doi_field name="your-name"]` shows a value from the form, only right after the confirmation.
186 +* `[doi_error_message]` on the error page explains why a sign-up was refused (too many attempts, address already signed up, and so on).
187 +
188 +A page without `[doi_confirmation_status]` still shows a short notice when the link has expired or is invalid.
189 +
167 190 = Does the plugin work with CAPTCHA plugins? =
168 191
169 192 Yes. The plugin automatically disables CAPTCHA validation (Google reCAPTCHA, hCaptcha, CF7 Captcha by Forge12) when re-sending the original form mail after confirmation. This prevents false spam detections during the confirmation step. CAPTCHA is re-enabled immediately after the mail has been sent.
170 193
@@ -193,9 +216,9 @@
193 216 The free version requires at least one supported form plugin. However, developers can register custom form integrations using the `f12_cf7_doubleoptin_register_integrations` action hook. See the developer documentation for details.
194 217
195 218 = Where can I find the developer documentation? =
196 219
197 -A hook, filter, and event reference with code examples ships at `docs/hooks-and-events.md` inside the plugin directory. It documents 27 of the 44 action hooks, 22 of the 72 filters, and all 11 typed events — the ones extensions actually reach for. The rest are discoverable in the source; if you need one documented, ask and we will add it.
220 +A hook, filter, and event reference with code examples ships at `docs/hooks-and-events.md` inside the plugin directory. It documents 29 of the 48 action hooks, 24 of the 82 filters, and all 13 typed events — the ones extensions actually reach for. The rest are discoverable in the source; if you need one documented, ask and we will add it.
198 221
199 222 = How do I report a bug or request a feature? =
200 223
201 224 Please visit [forge12.com](https://www.forge12.com) or contact us via the WordPress support forum.
@@ -201,15 +224,16 @@
201 224 Please visit [forge12.com](https://www.forge12.com) or contact us via the WordPress support forum.
202 225
203 226 == Screenshots ==
204 227
205 -1. **Opt-In Dashboard** -- Overview of all opt-in records with status, email, form, date, and actions.
206 -2. **Form Settings** -- Per-form configuration with sender, subject, recipient field, confirmation page, and conditions.
207 -3. **Email Template Editor** -- Visual drag & drop editor with blocks, live preview, and mobile preview.
208 -4. **Template Presets** -- Choose from pre-built email template designs.
209 -5. **Single Opt-In View** -- Detailed view of an opt-in record with form data, timestamps, and IP addresses.
210 -6. **Global Settings** -- Configure data retention, token expiry, telemetry, and opt-out settings.
211 -7. **Category Management** -- Organize opt-in records into categories.
228 +1. **Dashboard** -- Total, confirmed and pending opt-ins at a glance, with the latest submissions.
229 +2. **Opt-In list** -- Every record with form, status and date; search and filter by status, follow-up actions and mail delivery.
230 +3. **Opt-in detail** -- Timestamps and IP addresses of request and confirmation, the consent text, and whether the form mail ran after the click.
231 +4. **Forms** -- All Contact Form 7 forms with Double Opt-In switched on or off per form.
232 +5. **Form settings** -- Consent text, acceptance field, category, sender, subject and confirmation page for one form.
233 +6. **Setup wizard** -- Sender, forms, confirmation email and the page after the click, in four steps.
234 +7. **Settings** -- Data retention, privacy policy page, token expiry and rate limits.
235 +8. **What the visitor sees** -- After submitting: where the confirmation mail comes from and what to do if it does not arrive.
212 236
213 237 == Privacy & Telemetry ==
214 238
215 239 **As of version 5.1.7 the plugin no longer transmits any telemetry.** The daily
@@ -239,8 +263,17 @@
239 263 licensed under the SIL Open Font License 1.1 (see licenses/inter-OFL-1.1.txt).
240 264
241 265 == Upgrade Notice ==
242 266
267 += 5.8.1 =
268 +Fixes German admin texts. No functional changes.
269 +
270 += 5.8.0 =
271 +Shows whether each confirmation email reached your mail server and tells Contact Form 7 visitors to confirm their address. Pro users: update the email editor and opt-out add-ons too.
272 +
273 += 5.7.0 =
274 +Adds a setup wizard for new installations. Existing forms and settings are not changed.
275 +
243 276 = 5.6.3 =
244 277 Ships the hook and Addon API reference the readme refers to. No functional changes.
245 278
246 279 = 5.6.2 =
@@ -335,8 +368,42 @@
335 368 = 3.1.0 =
336 369 Adds optional anonymous telemetry (opt-out). No breaking changes.
337 370
338 371 == Changelog ==
372 +
373 += 5.8.1 =
374 +* Fix: on sites in formal German (Sie), a sentence on the user creation page was shown in English, and the role appeared as its internal key ("subscriber") instead of its name.
375 +* Fix: German admin texts used the English names "Conditional Templates", "User Creation" and "Unique Email"; they now use the German terms throughout.
376 +* Fix: the breadcrumb on add-on settings pages read "Page".
377 +
378 += 5.8.0 =
379 +
380 +**Know whether the confirmation email went out**
381 +
382 +* New: every opt-in records whether its confirmation email was handed to your mail server or failed, and why. Shown in the opt-in list (with a filter), on the detail page and in Site Health; included in the WordPress privacy export and eraser.
383 +* New: after a Contact Form 7 submission, visitors read "please confirm your address" with the sender and subject to look for, instead of "Thank you for your message". When the email could not be sent, they are told so.
384 +* New: Site Health checks SPF and DMARC of the sender domain, the two most common reasons confirmation emails land in spam.
385 +* New: a dashboard hint when many recent opt-ins stay unconfirmed.
386 +* New: shortcodes [doi_confirmation_status], [doi_error_message] and [doi_field] for the confirmation and error pages, and a readable message when a link is broken or expired.
387 +* New: a hidden honeypot field and a minimum fill time keep simple bots away from Contact Form 7 double opt-in forms.
388 +* New: the forms page suggests add-ons only for form plugins that are installed on the site.
389 +* New: after ten confirmations, a one-time request for a review, only on the plugin's own pages.
390 +* Changed: the free plugin no longer contains locked Pro features. Email template management and the opt-out page generator now live in their add-ons. If you use them, update the email editor add-on to 1.1.0 and the opt-out add-on to 1.5.0; Site Health reminds you.
391 +* Changed: a renewed consent after an opt-out no longer overwrites the original confirmation; it gets its own entry in the audit log.
392 +* Fix: the Activate button on the Add-ons page and links in REST responses were broken ("&" in the URL).
393 +* Fix: Avada forms without a notification were reported as a failed follow-up action.
394 +* Fix: several admin texts stayed English on translated sites; the breadcrumb read "Page" on detail pages; a waiting button now shows a countdown.
395 +* Developers: Core API 4.6.0 with the filters f12_doi_submit_notice_data and f12_doi_mail_headers, the events f12_doi_optin_opted_out and f12_doi_optin_reopted_in, follow-up adapters for add-ons and a shared resend service.
396 +
397 += 5.7.0 =
398 +
399 +**A setup wizard gets new sites to the first working confirmation email**
400 +
401 +* New: after installing the plugin, a short wizard sets up the sender, the Contact Form 7 forms that should ask for confirmation, the confirmation email and the page visitors see after clicking the link. Everything is prefilled; it takes about three minutes and can be skipped at any time. A test email to yourself shows the result before visitors see it.
402 +* New: the sender name and address from the wizard are used for every form you switch on later. Confirmation emails without a sender name no longer arrive as "WordPress".
403 +* New: if you also use Elementor Pro, WPForms, Gravity Forms or Avada Forms, the wizard tells you which add-on protects those forms.
404 +* Improved: forms that already use Double Opt-In are left exactly as they are. Existing sites do not see the wizard unless you start it under Settings.
405 +* Fix: this description listed the visual email editor, saved templates and test emails as free features. They are part of the email editor add-on; the free plugin offers three built-in email designs. Resending a confirmation email from the opt-in details is free.
339 406
340 407 = 5.6.3 =
341 408
342 409 * Fix: the developer reference this readme points to — `docs/hooks-and-events.md` and `docs/addon-api.md` — was never actually included in the plugin. Both files now ship.