Costatech COD Checkout Verification for WooCommerce

Description

Fake Cash on Delivery orders drive up Return-to-Origin (RTO) rates and shipping losses. This plugin helps by requiring OTP verification at checkout for Cash on Delivery and other offline payment methods. It adds a one-time-password (OTP) check for offline payment methods — Cash on Delivery, Direct Bank Transfer, and Cheque Payment — so a customer must verify a 6-digit code sent to their email and/or phone before an order can be placed.

This directly targets the biggest source of fake and time-wasting COD orders: customers who checkout on impulse with a phone number or address they never intend to honor. By requiring real-time verification of the OTP recipient, you filter out fake orders, reduce RTO/failed-delivery costs, and only ship to customers who’ve actually confirmed their order. Customers paying by card or another online method never see this step.

Key features

  • Works with both the classic (shortcode) checkout and the WooCommerce Blocks checkout
  • Verification required only for the offline payment methods you choose (COD, Bank Transfer, Cheque — configurable individually)
  • Delivery by email, SMS, or both
  • Configurable OTP length, expiry time, maximum attempts, and resend cooldown
  • Live countdown timer and resend button on the checkout page
  • Verified orders go straight to “Processing” — no separate post-order verification step
  • Server-side enforcement: WooCommerce itself refuses to place the order until the code is verified, for both checkout types

SMS delivery via Twilio

SMS delivery is entirely optional. If you enable it and configure your Twilio Account SID, Auth Token, and phone number in the plugin settings, the customer’s phone number and their OTP code are sent to Twilio’s API (api.twilio.com) in order to deliver the SMS. No data is sent to Twilio unless you explicitly enable and configure SMS delivery. Email delivery works completely standalone, with no third-party service involved.

See Twilio’s Terms of Service and Privacy Policy if you choose to use this feature.

Requires WooCommerce

This plugin extends WooCommerce checkout and requires WooCommerce to be installed and active.

Screenshots

Installation

  1. Upload the plugin files to /wp-content/plugins/costatech-cod-checkout-verification-woocommerce, or install the plugin through the WordPress plugins screen directly.
  2. Activate the plugin through the ‘Plugins’ screen in WordPress.
  3. Make sure WooCommerce is installed and active.
  4. Go to WooCommerce COD OTP Settings to configure OTP length, expiry, delivery method, and which payment methods require verification.
  5. If you want SMS delivery, enter your Twilio Account SID, Auth Token, and phone number under the same settings page.

FAQ

Does this work without SMS/Twilio?

Yes. Set the delivery method to “Email Only” and no third-party service is used at all.

Does this work with the WooCommerce Blocks checkout?

Yes. It works with both the classic (shortcode) checkout and the block-based checkout introduced in newer WooCommerce versions, using WooCommerce’s official checkout extensibility APIs.

Which payment methods can require OTP verification?

Cash on Delivery, Direct Bank Transfer (BACS), and Cheque Payment — WooCommerce’s built-in offline gateways. You can enable verification for any combination of the three. Online payment methods (cards, PayPal, etc.) are never affected.

What happens if the customer doesn’t verify the code?

WooCommerce will not allow the order to be placed until a valid, unexpired code has been verified — this is enforced on the server, not just hidden in the browser.

Is customer data sent anywhere besides my own site?

Only if you enable SMS delivery, in which case the phone number and OTP code are sent to Twilio to deliver the text message. Email delivery uses your site’s own wp_mail() and involves no external service.

Will this actually reduce RTO (Return to Origin) and fake COD orders?

Yes — this is the core purpose of the plugin. Requiring a customer to verify a live OTP sent to their own phone or email before an order is accepted filters out fake orders, prank orders, and mistyped contact details, which are the leading causes of failed COD deliveries and RTO losses.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Costatech COD Checkout Verification for WooCommerce” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.4.3

  • Fixed the auto-cancel cron repeatedly re-cancelling and re-emailing the same order every run instead of handling it once.

1.4.2

  • Registered the missing 5-minute cron schedule so unverified orders are actually auto-cancelled.
  • Removed an inline script from the classic checkout markup.
  • Renamed the plugin.

See changelog.txt for the full version history.