{"id":370130,"date":"2026-09-22T23:27:47","date_gmt":"2026-09-22T23:27:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/optinbridge-crm-consent-contact-manager\/"},"modified":"2026-09-22T23:27:11","modified_gmt":"2026-09-22T23:27:11","slug":"optinbridge-crm","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/optinbridge-crm\/","author":15460149,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.5.6","stable_tag":"1.5.6","tested":"7.1.2","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"OptinBridge CRM \u2013 Consent & Contact Manager","header_author":"Justo Crivelaro","header_description":"Consent-first contact CRM for WordPress, with auditable opt-ins, segmentation, privacy tools and CSV workflows for WhatsApp communications.","assets_banners_color":"cfd5e6","last_updated":"2026-09-22 23:27:11","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":45,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.5.6":{"tag":"1.5.6","author":"justocrivelaro","date":"2026-09-22 23:27:11","revision":3708240}},"upgrade_notice":{"1.5.6":"<p>Uses WordPress identifier placeholders for atomic rate-limit queries and documents intentional cache bypasses.<\/p>","1.5.5":"<p>Security and WordPress.org review hardening: prefixed public identifiers, readable JavaScript sources, and atomic public rate limiting.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3708289,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3708289,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.5.6"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[20011,1150,463,396,3160],"plugin_category":[54,58],"plugin_contributors":[282164],"plugin_business_model":[],"class_list":["post-370130","plugin","type-plugin","status-publish","hentry","plugin_tags-consent","plugin_tags-crm","plugin_tags-opt-in","plugin_tags-privacy","plugin_tags-whatsapp","plugin_category-security-and-spam-protection","plugin_category-user-management","plugin_contributors-justocrivelaro","plugin_committers-justocrivelaro"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/optinbridge-crm\/assets\/icon-256x256.png?rev=3708289","icon_2x":"https:\/\/ps.w.org\/optinbridge-crm\/assets\/icon-256x256.png?rev=3708289","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>OptinBridge CRM \u2013 Consent &amp; Contact Manager helps WordPress site owners collect voluntary registrations, organize contacts and keep an auditable history of consent for communications intended for WhatsApp.<\/p>\n\n<p>The Community edition does not scrape groups, discover private phone numbers or send messages automatically. It focuses on consent capture, contact governance, segmentation, export\/import and privacy workflows.<\/p>\n\n<h4>Highlights<\/h4>\n\n<ul>\n<li>Public opt-in form with explicit unchecked consent checkbox.<\/li>\n<li>Public unsubscribe form.<\/li>\n<li>Consent Passport: auditable timeline of consent creation, renewal, revocation, blocking and related events.<\/li>\n<li>Duplicate prevention using normalized phone numbers.<\/li>\n<li>Administrative blocking that cannot be bypassed by a new public signup.<\/li>\n<li>Safe unblock flow: blocked \u2192 pending \u2192 new explicit opt-in \u2192 authorized.<\/li>\n<li>Groups, tags and saved campaign segments.<\/li>\n<li>Campaign audience preview and filtered CSV export.<\/li>\n<li>CSV import with preview, legal-origin confirmation and duplicate handling.<\/li>\n<li>Dashboard, logs and environment diagnostics.<\/li>\n<li>WordPress personal-data exporter and eraser integration.<\/li>\n<li>Individual anonymization and deletion tools.<\/li>\n<li>Gutenberg block and shortcodes.<\/li>\n<li>Authenticated REST API for authorized administrators.<\/li>\n<li>No mandatory external libraries or services.<\/li>\n<li>No built-in telemetry.<\/li>\n<\/ul>\n\n<h4>What this plugin does NOT do<\/h4>\n\n<ul>\n<li>It does not access WhatsApp groups.<\/li>\n<li>It does not scrape or extract group participants.<\/li>\n<li>It does not discover private phone numbers.<\/li>\n<li>It does not collect contacts silently.<\/li>\n<li>It does not use unofficial WhatsApp Web automation.<\/li>\n<li>It does not send messages automatically in the Community edition.<\/li>\n<li>It does not guarantee legal compliance by itself.<\/li>\n<\/ul>\n\n<p>The site operator remains responsible for choosing an appropriate legal basis, wording notices, defining retention, handling data-subject requests and using exported data appropriately.<\/p>\n\n<h3>Shortcodes<\/h3>\n\n<pre><code>[optinbridge_consent_form]\n<\/code><\/pre>\n\n<p>Displays the public registration form.<\/p>\n\n<pre><code>[optinbridge_consent_form group=\"group-slug\"]\n<\/code><\/pre>\n\n<p>Displays the registration form tied to one active group.<\/p>\n\n<pre><code>[optinbridge_unsubscribe_form]\n<\/code><\/pre>\n\n<p>Displays the public unsubscribe form.<\/p>\n\n<pre><code>[optinbridge_support_form]\n<\/code><\/pre>\n\n<p>Displays the native public support\/feedback form. Configure the destination e-mail in <strong>OptinBridge CRM &gt; Configura\u00e7\u00f5es<\/strong>.<\/p>\n\n<h3>Blocks<\/h3>\n\n<p>The plugin registers a dynamic Gutenberg consent-form block. Existing shortcode integrations remain supported for backward compatibility.<\/p>\n\n<h3>Consent Passport<\/h3>\n\n<p>Each contact can keep an auditable event history, including events such as:<\/p>\n\n<ul>\n<li>consent_created<\/li>\n<li>consent_renewed<\/li>\n<li>consent_revoked<\/li>\n<li>contact_blocked<\/li>\n<li>blocked_signup_attempt<\/li>\n<li>contact_unblocked<\/li>\n<li>contact_anonymized<\/li>\n<\/ul>\n\n<p>Internal event codes remain stable for integrations while the WordPress admin displays friendly labels.<\/p>\n\n<h3>Contact statuses<\/h3>\n\n<ul>\n<li><code>authorized<\/code> \u2014 has an active recorded opt-in.<\/li>\n<li><code>cancelled<\/code> \u2014 the contact revoked\/cancelled communications.<\/li>\n<li><code>blocked<\/code> \u2014 administratively blocked and cannot reactivate through the public form.<\/li>\n<li><code>pending<\/code> \u2014 not currently authorized; may become authorized after a new explicit public opt-in.<\/li>\n<\/ul>\n\n<p>Cancelled and blocked contacts must not be treated as authorized recipients.<\/p>\n\n<h3>Groups, Tags and Campaigns<\/h3>\n\n<p>Groups represent a primary campaign\/source. Tags provide additional segmentation. Campaigns are saved audience definitions based on status, group and tag.<\/p>\n\n<p>Campaigns do not send messages. They can preview the current audience, open filtered contacts and export a protected CSV for an authorized administrator.<\/p>\n\n<h3>CSV Import<\/h3>\n\n<p>Preferred columns:<\/p>\n\n<pre><code>nome;telefone;email;grupo;consentimento\n<\/code><\/pre>\n\n<p>Example:<\/p>\n\n<pre><code>Maria Silva;51999999999;maria@example.com;promocoes;sim\n<\/code><\/pre>\n\n<p>Comma-separated files are also detected when possible.<\/p>\n\n<p>The importer:<\/p>\n\n<ul>\n<li>rejects rows without affirmative consent;<\/li>\n<li>validates and normalizes phone numbers;<\/li>\n<li>avoids duplicates;<\/li>\n<li>can create a missing group;<\/li>\n<li>shows a preview before import;<\/li>\n<li>requires an administrative legal-origin confirmation;<\/li>\n<li>reports imported, updated and rejected rows;<\/li>\n<li>does not send any message after import;<\/li>\n<li>does not reactivate administratively blocked contacts.<\/li>\n<\/ul>\n\n<h3>CSV Export<\/h3>\n\n<p>Exports require an authorized WordPress user and a valid nonce. Spreadsheet-formula prefixes are neutralized to reduce CSV Injection risk.<\/p>\n\n<p>Campaign audience export includes only the contacts matching that campaign's saved filters at export time.<\/p>\n\n<h3>REST API<\/h3>\n\n<p>Administrative read endpoints are available under <code>\/wp-json\/optinbridge-crm\/v1\/<\/code> for backward compatibility.<\/p>\n\n<p>Current routes include:<\/p>\n\n<ul>\n<li><code>GET \/contacts<\/code><\/li>\n<li><code>GET \/groups<\/code><\/li>\n<li><code>GET \/contacts\/{id}\/consent-events<\/code><\/li>\n<\/ul>\n\n<p>These routes may expose personal data and therefore require an authenticated WordPress user with the configured CRM management capability.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Depending on configuration and use, the plugin may store:<\/p>\n\n<ul>\n<li>name;<\/li>\n<li>phone number;<\/li>\n<li>optional email;<\/li>\n<li>group and tags;<\/li>\n<li>consent text and version;<\/li>\n<li>consent date\/time;<\/li>\n<li>consent IP address;<\/li>\n<li>source URL;<\/li>\n<li>status;<\/li>\n<li>audit events.<\/li>\n<\/ul>\n\n<p>The plugin integrates with WordPress' personal-data exporter and eraser when an email address is available. Contacts without email can be handled from the CRM administration screens.<\/p>\n\n<p>The plugin also supplies suggested privacy-policy text through WordPress' privacy-policy helper.<\/p>\n\n<p>IP capture uses <code>REMOTE_ADDR<\/code>. The plugin does not trust <code>HTTP_X_FORWARDED_FOR<\/code> by default because that header can be spoofed when proxy trust is not explicitly configured.<\/p>\n\n<p>No plugin-owned telemetry is enabled, and the Community edition makes no mandatory external HTTP requests.<\/p>\n\n<h3>Retention<\/h3>\n\n<p>The retention-days setting is a governance reference. Version 1.5.5 does not automatically delete records solely because that period has elapsed. Administrators should apply a retention policy appropriate to their context.<\/p>\n\n<h3>Uninstall<\/h3>\n\n<p>Data is preserved by default.<\/p>\n\n<p>If the administrator explicitly enables <strong>delete data on uninstall<\/strong>, uninstall.php removes the plugin tables and stored options. Public WordPress pages created by the setup wizard are not deleted automatically.<\/p>\n\n<h3>Security<\/h3>\n\n<p>The plugin uses WordPress security primitives including capabilities, nonces, sanitization, escaping, prepared queries, ID validation, CSRF protection, honeypot protection, IP rate limiting and CSV Injection mitigation.<\/p>\n\n<p>Please see <code>SECURITY.md<\/code> in the package for responsible disclosure guidance.<\/p>\n\n<h3>Developer Hooks<\/h3>\n\n<p>Actions include:<\/p>\n\n<ul>\n<li><code>optinbridge_contact_created<\/code><\/li>\n<li><code>optinbridge_contact_updated<\/code><\/li>\n<li><code>optinbridge_consent_event_recorded<\/code><\/li>\n<\/ul>\n\n<p>Filters include:<\/p>\n\n<ul>\n<li><code>optinbridge_consent_text<\/code><\/li>\n<li><code>optinbridge_consent_version<\/code><\/li>\n<li><code>optinbridge_integration_providers<\/code><\/li>\n<\/ul>\n\n<p>Version 1.5.5 uses the OptinBridge-prefixed PHP API, options and database tables. A one-time migration preserves data created by earlier development builds. The public API, REST namespace and shortcodes use the OptinBridge-specific prefix to avoid naming collisions.<\/p>\n\n<h3>External services<\/h3>\n\n<p>The Community edition does not require or call an external service to provide its core features. It contains no real WhatsApp API tokens and no fabricated API endpoints.<\/p>\n\n<p>Future messaging integrations should be distributed separately and use official provider APIs and terms.<\/p>\n\n<h3>Trademark notice<\/h3>\n\n<p>WhatsApp is a trademark of Meta Platforms, Inc. OptinBridge CRM \u2013 Consent &amp; Contact Manager is an independent project and is not affiliated with, endorsed by or sponsored by Meta Platforms, Inc. or WhatsApp.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload and activate the plugin.<\/li>\n<li>Open <strong>OptinBridge CRM &gt; Primeiros passos<\/strong>.<\/li>\n<li>Confirm the organization name, consent text and consent version.<\/li>\n<li>Add the privacy-policy URL.<\/li>\n<li>Select or create the public registration and unsubscribe pages.<\/li>\n<li>Review the readiness indicator and diagnostics.<\/li>\n<li>Create groups\/tags as needed.<\/li>\n<li>Run a test registration and unsubscribe before using the CRM with real contacts.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20extract%20members%20from%20whatsapp%20groups%3F\"><h3>Does it extract members from WhatsApp groups?<\/h3><\/dt>\n<dd><p>No. The plugin does not access groups or collect their participants.<\/p><\/dd>\n<dt id=\"does%20it%20automatically%20send%20whatsapp%20messages%3F\"><h3>Does it automatically send WhatsApp messages?<\/h3><\/dt>\n<dd><p>No. The Community edition does not send messages automatically.<\/p><\/dd>\n<dt id=\"can%20a%20blocked%20number%20sign%20up%20again%3F\"><h3>Can a blocked number sign up again?<\/h3><\/dt>\n<dd><p>Not while it remains blocked. A public attempt is rejected and can be audited. An administrator may unblock the record to <code>pending<\/code>; a fresh explicit opt-in is then required before the contact becomes <code>authorized<\/code> again.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20guarantee%20lgpd%2Fgdpr%20compliance%3F\"><h3>Does the plugin guarantee LGPD\/GDPR compliance?<\/h3><\/dt>\n<dd><p>No. It provides technical tools for consent records, privacy workflows and data minimization, but legal compliance depends on the site's policies, purposes, legal bases, notices and actual use of the data.<\/p><\/dd>\n<dt id=\"does%20it%20send%20my%20crm%20data%20to%20the%20plugin%20author%3F\"><h3>Does it send my CRM data to the plugin author?<\/h3><\/dt>\n<dd><p>No. There is no plugin-owned telemetry or mandatory external data transmission in the Community edition.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.5.6<\/h4>\n\n<ul>\n<li>Reworked atomic rate-limit SQL to use WordPress <code>%i<\/code> identifier placeholders and <code>%s<\/code> value placeholders.<\/li>\n<li>Documented intentional direct, uncached database access required for concurrency-safe throttling.<\/li>\n<li>Removed dynamic SQL interpolation from the rate-limit read\/write queries.<\/li>\n<\/ul>\n\n<h4>1.5.5<\/h4>\n\n<ul>\n<li>Replaced generic public shortcodes with <code>[optinbridge_consent_form]<\/code> and <code>[optinbridge_unsubscribe_form]<\/code>.<\/li>\n<li>Changed the REST namespace to <code>\/wp-json\/optinbridge-crm\/v1\/<\/code> to avoid naming collisions.<\/li>\n<li>Replaced transient get-then-set throttles with atomic counters backed by a plugin-owned database table.<\/li>\n<li>Added the rate-limit table to activation\/upgrade and explicit full-uninstall cleanup.<\/li>\n<li>Expanded the custom admin and public JavaScript into human-readable source files included in the plugin package.<\/li>\n<li>Re-audited state-changing administrative handlers for capability and nonce verification.<\/li>\n<\/ul>\n\n<h4>1.5.3<\/h4>\n\n<ul>\n<li>Added public release version\/ZIP settings and live counter to the admin settings page.<\/li>\n<\/ul>\n\n<h4>1.5.2<\/h4>\n\n<ul>\n<li>Added native public support\/feedback form shortcode: <code>[optinbridge_support_form]<\/code>.<\/li>\n<li>Added nonce, honeypot and per-IP rate limiting for support submissions.<\/li>\n<li>Added configurable support destination e-mail and hourly limit.<\/li>\n<li>Added optional attachment support (JPG, PNG, WebP, PDF, TXT; max 2 MB).<\/li>\n<li>Support submissions use <code>wp_mail()<\/code> and are not stored as tickets in the database.<\/li>\n<li>Audit logs record only request type\/version outcome, not submitted message or e-mail.<\/li>\n<li>Added explicit privacy consent and privacy-policy link.<\/li>\n<\/ul>\n\n<h4>1.5.1<\/h4>\n\n<ul>\n<li>Public distribution release candidate based on the approved 1.5.0 stable baseline.<\/li>\n<li>Revalidated package metadata and WordPress.org-facing documentation.<\/li>\n<li>Confirmed GPLv2-or-later declaration, privacy disclosures, uninstall behavior, and no mandatory telemetry\/external services.<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Hardened public unsubscribe against phone-number enumeration.<\/li>\n<li>Added honeypot and per-IP\/phone throttling to unsubscribe.<\/li>\n<li>Fixed public post-submit\/source URL normalization for Elementor template previews.<\/li>\n<li>Unified Settings capability with the configured CRM management capability.<\/li>\n<\/ul>","raw_excerpt":"Consent-first CRM for WordPress with auditable opt-ins, segmentation, privacy tools and CSV workflows for WhatsApp communications.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/370130","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=370130"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/justocrivelaro"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=370130"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=370130"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=370130"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=370130"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=370130"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=370130"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}