{"id":371046,"date":"2026-09-29T12:30:44","date_gmt":"2026-09-29T12:30:44","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/candorlight-connector-for-odoo\/"},"modified":"2026-09-29T11:16:37","modified_gmt":"2026-09-29T11:16:37","slug":"candorlight-connector-for-odoo","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/candorlight-connector-for-odoo\/","author":23568621,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.8.0","stable_tag":"0.8.0","tested":"7.1.2","requires":"6.4","requires_php":"8.1","requires_plugins":null,"header_name":"CandorLight Connector for Odoo","header_author":"CandorLight LLC","header_description":"Sends WordPress contact form submissions to Odoo as tagged contacts (res.partner) using the Odoo External JSON-2 API.","assets_banners_color":"","last_updated":"2026-09-29 11:16:37","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/candorlight.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":59,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.8.0":{"tag":"0.8.0","author":"candorlight","date":"2026-09-29 11:16:37","revision":3718879},"1.0.0":{"tag":"1.0.0","author":"candorlight","date":"2026-09-29 11:44:17","revision":3718934}},"upgrade_notice":{"0.8.0":"<p>CRM lead creation has been removed in favour of a contact tag. Set a Tag ID on\nthe settings screen after upgrading.<\/p>","0.7.0":"<p>First public release. If you ran an internal build, note that logging now\ndefaults to off and that &quot;Update the existing contact&quot; no longer overwrites the\ncontact&#039;s Notes or name.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.8.0","1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[358,2736,1150,12827,19380],"plugin_category":[58],"plugin_contributors":[283404],"plugin_business_model":[],"class_list":["post-371046","plugin","type-plugin","status-publish","hentry","plugin_tags-contact-form","plugin_tags-contacts","plugin_tags-crm","plugin_tags-erp","plugin_tags-odoo","plugin_category-user-management","plugin_contributors-candorlight","plugin_committers-candorlight"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/candorlight-connector-for-odoo.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>When someone fills in a contact form on your site, this plugin writes them into\nyour Odoo database as a contact (<code>res.partner<\/code>) and tags it with the Odoo\ncontact tag you choose, so web enquiries are easy to find and filter.<\/p>\n\n<p>It talks to Odoo over the <strong>External JSON-2 API<\/strong> (<code>POST \/json\/2\/{model}\/{method}<\/code>\nwith bearer-token authentication). It deliberately avoids the legacy XML-RPC and\n    \/jsonrpc endpoints, which Odoo has deprecated.<\/p>\n\n<h4>What it does<\/h4>\n\n<ul>\n<li><strong>Field mapping you control.<\/strong> Point any Odoo contact field \u2014 name, email,\nphone, mobile, company, website, job position, street, city, ZIP, notes \u2014 at\nwhichever field id your form sends. Nothing is hard-coded.<\/li>\n<li><strong>Contact tag.<\/strong> Enter the ID of an Odoo contact tag and every contact the\nplugin creates or updates gets that tag. Tags already on a contact are kept.<\/li>\n<li><strong>Duplicate handling.<\/strong> Matches on email, case-insensitively. Choose whether a\nrepeat submission updates the existing contact, is left alone, or always\ncreates a new record.<\/li>\n<li><strong>Non-destructive updates.<\/strong> When it updates an existing contact it appends to\nthe Notes field rather than overwriting it, and never rewrites the contact's\nname. Your sales team's notes survive.<\/li>\n<li><strong>A built-in form.<\/strong> The <code>[odoo_contact_form]<\/code> shortcode gives you a plain,\nnonce- and honeypot-protected contact form, so you can prove the whole chain works\nwithout installing a form plugin first.<\/li>\n<li><strong>Divi Contact Form support.<\/strong> Detected automatically when Divi or the Divi\nBuilder is active.<\/li>\n<li><strong>Diagnostics.<\/strong> A read-only \"Test connection\" check (which also confirms the\ntag ID exists) and a \"Create a test contact\" button, so you find out about a bad API key on the settings screen\nrather than from a visitor's lost enquiry.<\/li>\n<li><strong>Safe by design.<\/strong> A sync failure is logged and swallowed \u2014 it never turns\ninto a broken-looking page for the person who filled in your form.<\/li>\n<\/ul>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>An Odoo server running version 19 or newer, reachable over HTTPS.<\/li>\n<li>An Odoo API key for a user with create\/write access to <code>res.partner<\/code> and read\naccess to contact tags (<code>res.partner.category<\/code>).<\/li>\n<li>PHP 8.1 or newer, WordPress 6.4 or newer.<\/li>\n<\/ul>\n\n<h4>Extending it<\/h4>\n\n<p>Form integrations are pluggable. Implement <code>OdooConnector\\Forms\\FormIntegration<\/code>\nand add it through the <code>odoo_connector_form_integrations<\/code> filter to support\nWPForms, Gravity Forms, Contact Form 7 or anything else.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin sends data to <strong>the Odoo server that you configure on its settings\nscreen<\/strong>. No data is sent anywhere else, and the plugin contacts no service\nbelonging to CandorLight LLC or to any third party.<\/p>\n\n<p><strong>What is sent, and when.<\/strong> Each time a visitor submits a connected form, the\nplugin makes an HTTPS request to your Odoo server containing the form values you\nhave mapped. In a default setup that is the visitor's name, email address, phone\nnumber, company name, company website and message, plus a provenance line naming\nthe form, your site's URL and the submission time, and the contact tag ID you\nconfigured. Requests are also made\nwhen you press \"Test connection\" (a read-only count of contacts and a lookup of\nthe configured tag) or \"Create a\ntest contact\" on the settings screen.<\/p>\n\n<p><strong>Where it goes.<\/strong> To the URL you enter as the Odoo URL \u2014 normally your own\nself-hosted Odoo instance or your Odoo Online subscription. This plugin's\nauthors do not operate, host or have access to that server.<\/p>\n\n<p><strong>Whose terms apply.<\/strong> If you use Odoo Online or another hosted Odoo service,\nthat provider's terms and privacy policy govern the data once it arrives:\nOdoo S.A.'s terms are at https:\/\/www.odoo.com\/terms and their privacy policy at\nhttps:\/\/www.odoo.com\/privacy . If you self-host, the data stays on your own\ninfrastructure.<\/p>\n\n<p>Because the plugin transmits personal data your visitors have submitted, make\nsure your own privacy policy says so, and that you have a lawful basis for\nsending it to your CRM.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/<\/code> or install it through\n<strong>Plugins \u2192 Add New<\/strong>, then activate it.<\/li>\n<li>In Odoo, create an API key: click your avatar \u2192 <strong>My Profile<\/strong> (or\n<strong>My Preferences<\/strong>) \u2192 <strong>Account Security<\/strong> \u2192 <strong>New API Key<\/strong>. Odoo requires a\nduration and currently caps keys at three months, so note the expiry date.<\/li>\n<li>In WordPress, go to <strong>Settings \u2192 Connector for Odoo<\/strong>. Enter your\nOdoo server root URL (no trailing slash, no <code>\/web<\/code> or <code>\/odoo<\/code> path), the\ndatabase name, and the API key. Save.<\/li>\n<li>Press <strong>Test connection<\/strong>. A green result means the URL, the database and the\nkey are all good.<\/li>\n<li>Under <strong>Contacts<\/strong>, enter the ID of the Odoo contact tag to apply. In\nOdoo go to <strong>Contacts \u2192 Configuration \u2192 Tags<\/strong>, open the tag and read the\nnumber at the end of the URL. Leave it empty for no tag.<\/li>\n<li>Under <strong>Field mapping<\/strong>, check that each Odoo field points at the field id\nyour form actually sends. Divi lowercases its field ids and strips spaces, so\na field labelled \"Company name\" arrives as <code>companyname<\/code>.<\/li>\n<li>Submit your form once and confirm the contact appears in Odoo.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"which%20versions%20of%20odoo%20are%20supported%3F\"><h3>Which versions of Odoo are supported?<\/h3><\/dt>\n<dd><p>Odoo 19 and newer. The plugin uses the External JSON-2 API, which older releases\ndo not provide. It does not fall back to XML-RPC.<\/p><\/dd>\n<dt id=\"where%20do%20i%20find%20my%20database%20name%3F\"><h3>Where do I find my database name?<\/h3><\/dt>\n<dd><p>It is the Odoo database name, not your WordPress database. If you are unsure,\nrun <code>odoo.info<\/code> in your browser's developer console while viewing any Odoo page.<\/p><\/dd>\n<dt id=\"do%20i%20need%20the%20crm%20module%20in%20odoo%3F\"><h3>Do I need the CRM module in Odoo?<\/h3><\/dt>\n<dd><p>No. Contacts and contact tags are part of every Odoo install.<\/p><\/dd>\n<dt id=\"how%20do%20i%20stop%20sending%20submissions%20to%20odoo%3F\"><h3>How do I stop sending submissions to Odoo?<\/h3><\/dt>\n<dd><p>Deactivate the plugin. Your settings are kept until you delete it.<\/p><\/dd>\n<dt id=\"my%20api%20key%20stopped%20working%20after%20a%20few%20months.\"><h3>My API key stopped working after a few months.<\/h3><\/dt>\n<dd><p>Odoo caps API key lifetimes (currently at three months). Generate a new key and\npaste it into the settings screen. The stored key is never shown back to you \u2014\nthe field displays dots \u2014 so leaving the dots untouched keeps the existing key.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20contact%20form%207%20%2F%20wpforms%20%2F%20gravity%20forms%3F\"><h3>Does it work with Contact Form 7 \/ WPForms \/ Gravity Forms?<\/h3><\/dt>\n<dd><p>Not out of the box. Divi's contact form and the bundled <code>[odoo_contact_form]<\/code>\nshortcode are supported today. Other forms can be added through the\n    odoo_connector_form_integrations filter without modifying the plugin.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20store%20submissions%20in%20wordpress%3F\"><h3>Does the plugin store submissions in WordPress?<\/h3><\/dt>\n<dd><p>No. Submissions are passed straight through to Odoo and are not written to your\nWordPress database. If logging is switched on, request details are written to\nyour PHP error log with API keys and tokens redacted \u2014 that log is the only\nlocal copy, and logging is off by default.<\/p><\/dd>\n<dt id=\"a%20submission%20did%20not%20reach%20odoo.%20how%20do%20i%20debug%20it%3F\"><h3>A submission did not reach Odoo. How do I debug it?<\/h3><\/dt>\n<dd><p>Turn on <strong>Logging<\/strong> in the settings screen and make sure <code>WP_DEBUG_LOG<\/code> is\nenabled in <code>wp-config.php<\/code>. Every request, response code and error is written to\nthe log, prefixed <code>[odoo-connector]<\/code>. Failed payloads are logged in full so a\nlost enquiry can be re-entered by hand.<\/p><\/dd>\n<dt id=\"my%20divi%20form%20submits%20but%20nothing%20happens.\"><h3>My Divi form submits but nothing happens.<\/h3><\/dt>\n<dd><p>Turn on <strong>Logging<\/strong> and submit the form once. If no <code>et_pb_contact_form_submit\nfired<\/code> line appears in the log, your Divi version does not fire the action this\nplugin listens to.<\/p><\/dd>\n<dt id=\"is%20this%20an%20official%20odoo%20product%3F\"><h3>Is this an official Odoo product?<\/h3><\/dt>\n<dd><p>No. It is an independent integration by CandorLight LLC, not affiliated with,\nendorsed by or sponsored by Odoo S.A. \"Odoo\" is a trademark of Odoo S.A.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.8.0<\/h4>\n\n<ul>\n<li>New: \"Tag ID\" setting. Every contact created or updated is linked to that Odoo\ncontact tag; existing tags are kept. \"Test connection\" checks the tag exists.<\/li>\n<li>Removed: CRM lead \/ opportunity creation and its settings.<\/li>\n<li>Removed: the \"Send submissions\" switch; deactivate the plugin to stop\nsyncing.<\/li>\n<li>Security: the built-in form verifies its nonce before reading any other posted\nvalue, and every field is sanitized and validated for its type (email, phone,\nURL, text length).<\/li>\n<li>Security: removed the Divi hook probe, which inspected $_POST on every\nrequest. The Divi integration no longer reads request data at all; it only\nreceives values from Divi's own nonce-checked submit action and sanitizes them.<\/li>\n<\/ul>\n\n<h4>0.7.0<\/h4>\n\n<ul>\n<li>First public release.<\/li>\n<li>Settings screen with connection details, field mapping, duplicate handling and\nCRM lead options.<\/li>\n<li>Odoo External JSON-2 API client covering arbitrary model calls, plus helpers\nfor finding, creating and updating contacts and creating CRM leads.<\/li>\n<li>Divi Contact Form integration, plus the <code>[odoo_contact_form]<\/code> shortcode with\nhoneypot spam protection and post\/redirect\/get handling.<\/li>\n<li>Duplicate handling on email with update \/ skip \/ always-create modes.<\/li>\n<li>Updates now append to an existing contact's Notes instead of overwriting them,\nand no longer rewrite the contact's name.<\/li>\n<li>Optional CRM lead or opportunity creation with a templated subject.<\/li>\n<li>\"Test connection\" and \"Create a test contact\" diagnostics.<\/li>\n<li>Opt-in logging with credentials redacted; logging now defaults to off.<\/li>\n<li>The Divi hook probe is now opt-in and scoped to genuine contact-form requests.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial internal scaffold: settings screen, JSON-2 client, connection test.\nVersions 0.2.0 through 0.6.0 were internal development builds and were never\nreleased publicly.<\/li>\n<\/ul>","raw_excerpt":"Send contact form submissions to your Odoo database as tagged contacts. Uses the modern External JSON-2 API.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/371046","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=371046"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/candorlight"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=371046"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=371046"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=371046"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=371046"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=371046"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=371046"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}