Description
Arabic dashboard, multiple independently configured forms, Elementor shortcode
[codlino_form id=”123″], RTL layout and responsive styling. Each form orders a published simple or variable WooCommerce product, with an
optional quantity selector. Orders use WooCommerce CRUD APIs,
COD, on-hold status, stock handling and the standard receipt page; HPOS declared.
Start a new form with no fixed fields and create up to 30 fields: text, textarea,
email, phone, number or select. Use a small required checkbox under each field. Choose optional
price display and colors for the box, fields, field borders, button and button text.
Fields are visible in WooCommerce order details. Optional role mapping populates
customer name, city, phone, address and email. Legacy fixed fields migrate to
editable/deletable fields without changing existing form IDs.
Three ready-made styles (Classic, Express, Premium) apply their palette and layout
without replacing fields. Select Arabic/Latin fonts, button text size, vertical
padding, width, gap above the button and optional gentle shake animation.
Remote selected fonts load from Google Fonts; Janna must be loaded by your site.
Reduced-motion preferences disable animation. Optional Moroccan mobile format
validation accepts 06/07 and 212/+212/00212 international formats on the server.
Optional phone/IP duplicate blocking lasts 24 hours after an accepted order,
with editable messages. Optional HTTPS JSON webhooks run asynchronously with
up to three attempts. Webhook failure never cancels an accepted WooCommerce order.
Powered by Taha Belmezrar.
Operational details
- One product per form; optional quantity (1–100 maximum, subject to stock).
- Variable products support up to 200 variations. Configure attributes, prices,
stock and variation images in WooCommerce. Choose buttons, colors, images or
select lists per attribute in Codlino. Prices displayed are per unit. - No coupons, shipping-zone pricing or upsells.
- Assign a field role to map it to customer details; unmapped fields are metadata.
Email role populates billing email; WooCommerce handles notifications. One field
per role is allowed. Publishing requires at least one field. The builder uses JavaScript. - Store country is used. No state/postcode mapping; verify tax rules for this model.
- Delivery line costs zero. On-hold orders are unpaid.
- Site font is the default. Janna is local; Cairo, Tajawal, Noto Sans Arabic, Inter,
Poppins and Open Sans use Google Fonts only when selected (internet required). - Duplicate protection counts accepted Codlino submissions where protection was
enabled, across protected forms on this site. Historical orders and orders from
other checkout flows are not scanned. Cancellation does not remove the 24h block. - Phone protection makes phone required. It normalizes common country-code formats;
Moroccan validation is a separate optional switch; it checks syntax, not ownership
or whether a number is allocated/active. A mapped phone is required for either switch. - IP means public network address: several customers may share one IP. REMOTE_ADDR
is used; trusted proxies require the codlino_client_ip filter configured by an admin. - Generic webhooks require direct HTTPS JSON endpoints returning 2xx without redirects.
Google Sheets mode includes an Arabic setup guide, generated Apps Script receiver,
copy button and admin-only test. It follows only Google content redirects via GET
and verifies a matching JSON write acknowledgment. Each form uses a private token.
Tests add a dummy Sheet row, never a WooCommerce order. WP-Cron runs real delivery/retries. - A guard table is created on upgrade. Expired blocks stop blocking by timestamp,
even before daily cleanup. WP-Cron also retires temporary request records. - Request retry protection lasts 48 hours. AJAX refreshes nonce/request IDs for
cached pages. Without JavaScript, exclude form pages from full-page caching. - Deactivation/removal preserves forms, orders and configuration.
External services and privacy
Codlino does not phone home to its author and has no analytics or licensing
connection. A merchant can use the form and create orders with all external
integrations disabled. The default font uses the site’s own styles.
Google Fonts (optional)
Selecting Cairo, Tajawal, Noto Sans Arabic, Inter, Poppins or Open Sans loads a
stylesheet from fonts.googleapis.com and font files from fonts.gstatic.com.
Requests happen in the admin preview and visitors’ browsers where that font is
used. Google receives the browser IP address and normal HTTP request information.
Choose the site font or locally supplied Janna to avoid these Google requests.
Service: https://fonts.google.com/
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy
Google Apps Script and Google Sheets (optional)
The merchant configures and deploys the bundled receiver using their own Google
account and spreadsheet. Enabling the integration sends accepted order data
from the WordPress server to the configured script.google.com/macros/s/…/exec
endpoint. Data includes order/form/event identifiers, customer name, phone,
city, country, products, selected attributes, quantity, totals, currency, status
and configured form fields. A private per-form receiver token authenticates the
POST. Google may serve its response at script.googleusercontent.com/macros/echo;
Codlino reads it by GET without forwarding the POST body or token. Google also
receives the server IP address and normal HTTP request information. Clicking
Test sends synthetic sample data and creates a test row, with no WooCommerce
order. Real delivery and retries run through WP-Cron.
Service: https://developers.google.com/apps-script
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy
Merchant-configured generic webhooks (optional)
Enabling a webhook sends the same order payload, without the Sheets token, to
the merchant’s own HTTPS endpoint. Clicking Test sends synthetic sample data.
The endpoint provider’s terms/privacy policy apply; merchants must review them
and disclose relevant processing to shoppers before enabling their integration.
Local storage
Orders and customer details are stored in WooCommerce. Form settings, webhook
endpoints and receiver tokens are stored in the WordPress database. Order
metadata keeps submitted form fields, selected attributes and delivery state;
enabled Sheets delivery stores its endpoint and token with the order for retries.
Duplicate phone/IP guards use salted HMAC identifiers with 24-hour expiry;
request records expire after 48 hours. Orders retain the WooCommerce customer
IP and submitted details subject to the merchant’s WooCommerce retention policy.
Deactivation/removal preserves settings, forms and orders. Merchants manage
WooCommerce customer-data retention and any external spreadsheet/webhook copies.
Extension points
codlino_validate_submission($error, $fields, $form_id)
codlino_order_created($order, $form_id)
codlino_client_ip($ip)
Order metadata retains _codflow_form_id, _codflow_full_name, _codflow_request_id,
_codflow_fields and optional webhook delivery metadata for upgrade compatibility.
Screenshots


Installation
- Activate WooCommerce 8.2+ and enable Cash on delivery.
- Upload codlino-cod-order-forms-0.6.1.zip. When upgrading from CODFlow, deactivate CODFlow first, then install and activate Codlino.
- Create a published simple or variable product. Include delivery in its price; for physical products leave COD shipping-method restrictions empty.
- Open Codlino, create/edit a form, choose its product and save as published.
- Embed its shortcode in Elementor or a WordPress Shortcode block.
- Verify orders and enabled integrations on staging before live traffic.
FAQ
-
Do I need a license key or an account?
-
No. All features included in this plugin work without a paid license key or an
author account. Google integrations require the merchant’s own Google account. -
Is Elementor required?
-
No. Use [codlino_form id=”123″] in a WordPress Shortcode block or an Elementor
Shortcode widget. WooCommerce is required; Elementor is optional. -
Does disabling the webhook stop WooCommerce orders?
-
No. Orders are saved directly in WooCommerce. External delivery is optional.
-
No. Optional Google Fonts and merchant-configured integrations are described
under External services and privacy.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Codlino – COD Order Forms for WooCommerce” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Codlino – COD Order Forms for WooCommerce” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
0.6.1
Refined admin and storefront styling with consistent emerald, ivory and ink
palettes, responsive spacing, clear focus states and coordinated presets.
Existing merchant color settings remain preserved.
0.6.0
Rename to Codlino – COD Order Forms for WooCommerce with text domain
codlino-cod-order-forms. Add allowlisted, typed request sanitizers and explicit
permission/nonce checks at admin save endpoints. Replace manual core admin
header/footer loading with redirects and per-user admin validation notices.
Retain persisted identifiers and legacy shortcode/cron compatibility.
0.5.6
Constrain the admin menu icon to 20px on every WordPress admin screen.
0.5.5
Selected Codlino icon in the admin menu, dashboard header and information section.
Soft section backgrounds and clearer navigation colors.
0.5.4
Admin dashboard refresh: emerald brand header, distinct section accents, clearer
inputs, cards, focus states and responsive navigation. Frontend styling unchanged.
0.5.3
Set the enqueued Google font resource version and place the documented Apps Script
response-host analyzer exception at the validated host literal. No delivery or
security behavior changes.
0.5.2
Plugin Check fixes: translator comments, prefixed template variables, safe field
attributes, WordPress font enqueue/late printing, sanitized server input and
prepared SQL identifiers. Document narrowly scoped analyzer exceptions for
nonce-verified delegation, read-only navigation and atomic uncached guard queries.
Google Sheets acknowledgment handling is unchanged and documented as service
communication. Tested up to reflects the merchant-reported WordPress 7.1 site.
0.5.1
Publication preparation: document optional external services and local storage,
clarify account requirements, and correct the 0.4.1 changelog version.
0.5.0
Save in place and advance through setup sections. Empty forms save as drafts with
an Arabic popup. WooCommerce variations with colors/images/sizes and optional
quantity. Server-authoritative variation prices, eligibility and stock.
Selected attributes and quantity are included in webhook/Sheets data.
0.4.1
Light dashboard refresh: white surfaces, quiet green accent, numbered sections,
clearer text and controls, mobile navigation and refined frontend presentation.
0.4.0
Built-in Google Sheets setup guide and Apps Script generator, private per-form
receiver token, verified Google response handling and admin webhook test.
0.3.0
Fields from scratch, per-field required checkbox and customer role mapping.
Three templates, font selection, button size/gap/motion and Moroccan phone validation.
0.2.0
Arabic dashboard and branding, custom field builder, configurable colors,
optional HTTPS webhook, optional 24-hour phone/IP duplicate blocking.
0.1.1
RTL layout, hidden required markers, optional fields and price visibility.
0.1.0
Initial MVP.