{"id":375468,"date":"2026-10-03T10:45:48","date_gmt":"2026-10-03T10:45:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/cod-otp-verification-fake-order-prevention-for-woocommerce\/"},"modified":"2026-10-03T10:45:17","modified_gmt":"2026-10-03T10:45:17","slug":"costatech-cod-checkout-verification-woocommerce","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/costatech-cod-checkout-verification-woocommerce\/","author":23564294,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.3","stable_tag":"1.4.3","tested":"7.1.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Costatech COD Checkout Verification for WooCommerce","header_author":"Nitesh Bavishiya","header_description":"Stop fake Cash on Delivery (COD) orders and reduce RTO losses with mandatory SMS\/Email OTP verification for WooCommerce checkout. Also supports Bank Transfer and Cheque.","assets_banners_color":"3d7ce3","last_updated":"2026-10-03 10:45:17","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":59,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.4.3":{"tag":"1.4.3","author":"costatech","date":"2026-10-03 10:45:17","revision":3726121}},"upgrade_notice":{"1.4.3":"<p>Fixes the auto-cancel cron re-cancelling and re-emailing the same order on every run.<\/p>","1.4.1":"<p>Recommended update: adds server-side rate limiting on the OTP request endpoint and fixes a silent failure when SMS is selected without a phone number.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3726121,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3726121,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3726136,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3726136,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.4.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3726121,"resolution":"1","location":"assets","locale":"","width":1600,"height":1000},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3726121,"resolution":"2","location":"assets","locale":"","width":1600,"height":1000},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3726121,"resolution":"3","location":"assets","locale":"","width":1600,"height":1000},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3726121,"resolution":"4","location":"assets","locale":"","width":1600,"height":1000},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3726121,"resolution":"5","location":"assets","locale":"","width":1600,"height":1000},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3726121,"resolution":"6","location":"assets","locale":"","width":1600,"height":1000},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3726121,"resolution":"7","location":"assets","locale":"","width":1600,"height":1000}},"screenshots":{"1":"Verification box on checkout after the code is sent, with countdown timer and resend option.","2":"Customer verified successfully and ready to place the order.","3":"Verification code email received by the customer.","4":"Checkout blocked when the customer has not verified their identity.","5":"General settings: OTP length, expiry time, maximum attempts, and resend cooldown.","6":"Choose which offline payment methods require OTP, and the delivery method (email, SMS, or both).","7":"Twilio SMS configuration and automatic cancellation of unverified orders."}},"plugin_section":[],"plugin_tags":[23683,31179,261981,236038,237935],"plugin_category":[],"plugin_contributors":[280991],"plugin_business_model":[],"class_list":["post-375468","plugin","type-plugin","status-publish","hentry","plugin_tags-anti-fraud","plugin_tags-cash-on-delivery","plugin_tags-cod-verification","plugin_tags-fake-orders","plugin_tags-otp-verification","plugin_contributors-costatech","plugin_committers-costatech"],"banners":{"banner":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/banner-772x250.png?rev=3726136","banner_2x":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/banner-1544x500.png?rev=3726136","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/icon-128x128.png?rev=3726121","icon_2x":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/icon-256x256.png?rev=3726121","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/screenshot-1.png?rev=3726121","caption":"Verification box on checkout after the code is sent, with countdown timer and resend option."},{"src":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/screenshot-2.png?rev=3726121","caption":"Customer verified successfully and ready to place the order."},{"src":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/screenshot-3.png?rev=3726121","caption":"Verification code email received by the customer."},{"src":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/screenshot-4.png?rev=3726121","caption":"Checkout blocked when the customer has not verified their identity."},{"src":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/screenshot-5.png?rev=3726121","caption":"General settings: OTP length, expiry time, maximum attempts, and resend cooldown."},{"src":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/screenshot-6.png?rev=3726121","caption":"Choose which offline payment methods require OTP, and the delivery method (email, SMS, or both)."},{"src":"https:\/\/ps.w.org\/costatech-cod-checkout-verification-woocommerce\/assets\/screenshot-7.png?rev=3726121","caption":"Twilio SMS configuration and automatic cancellation of unverified orders."}],"raw_content":"<!--section=description-->\n<p>Fake Cash on Delivery orders drive up Return-to-Origin (RTO) rates and shipping losses. This plugin helps by requiring OTP verification at checkout for Cash on Delivery and other offline payment methods. It adds a one-time-password (OTP) check for offline payment methods \u2014 Cash on Delivery, Direct Bank Transfer, and Cheque Payment \u2014 so a customer must verify a 6-digit code sent to their email and\/or phone before an order can be placed.<\/p>\n\n<p>This directly targets the biggest source of fake and time-wasting COD orders: customers who checkout on impulse with a phone number or address they never intend to honor. By requiring real-time verification of the OTP recipient, you filter out fake orders, reduce RTO\/failed-delivery costs, and only ship to customers who've actually confirmed their order. Customers paying by card or another online method never see this step.<\/p>\n\n<p><strong>Key features<\/strong><\/p>\n\n<ul>\n<li>Works with both the classic (shortcode) checkout and the WooCommerce Blocks checkout<\/li>\n<li>Verification required only for the offline payment methods you choose (COD, Bank Transfer, Cheque \u2014 configurable individually)<\/li>\n<li>Delivery by email, SMS, or both<\/li>\n<li>Configurable OTP length, expiry time, maximum attempts, and resend cooldown<\/li>\n<li>Live countdown timer and resend button on the checkout page<\/li>\n<li>Verified orders go straight to \"Processing\" \u2014 no separate post-order verification step<\/li>\n<li>Server-side enforcement: WooCommerce itself refuses to place the order until the code is verified, for both checkout types<\/li>\n<\/ul>\n\n<p><strong>SMS delivery via Twilio<\/strong><\/p>\n\n<p>SMS delivery is entirely optional. If you enable it and configure your Twilio Account SID, Auth Token, and phone number in the plugin settings, the customer's phone number and their OTP code are sent to Twilio's API (api.twilio.com) in order to deliver the SMS. No data is sent to Twilio unless you explicitly enable and configure SMS delivery. Email delivery works completely standalone, with no third-party service involved.<\/p>\n\n<p>See Twilio's <a href=\"https:\/\/www.twilio.com\/legal\/tos\">Terms of Service<\/a> and <a href=\"https:\/\/www.twilio.com\/legal\/privacy\">Privacy Policy<\/a> if you choose to use this feature.<\/p>\n\n<p><strong>Requires WooCommerce<\/strong><\/p>\n\n<p>This plugin extends WooCommerce checkout and requires WooCommerce to be installed and active.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/costatech-cod-checkout-verification-woocommerce<\/code>, or install the plugin through the WordPress plugins screen directly.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress.<\/li>\n<li>Make sure WooCommerce is installed and active.<\/li>\n<li>Go to <strong>WooCommerce \u2192 COD OTP Settings<\/strong> to configure OTP length, expiry, delivery method, and which payment methods require verification.<\/li>\n<li>If you want SMS delivery, enter your Twilio Account SID, Auth Token, and phone number under the same settings page.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20work%20without%20sms%2Ftwilio%3F\"><h3>Does this work without SMS\/Twilio?<\/h3><\/dt>\n<dd><p>Yes. Set the delivery method to \"Email Only\" and no third-party service is used at all.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20the%20woocommerce%20blocks%20checkout%3F\"><h3>Does this work with the WooCommerce Blocks checkout?<\/h3><\/dt>\n<dd><p>Yes. It works with both the classic (shortcode) checkout and the block-based checkout introduced in newer WooCommerce versions, using WooCommerce's official checkout extensibility APIs.<\/p><\/dd>\n<dt id=\"which%20payment%20methods%20can%20require%20otp%20verification%3F\"><h3>Which payment methods can require OTP verification?<\/h3><\/dt>\n<dd><p>Cash on Delivery, Direct Bank Transfer (BACS), and Cheque Payment \u2014 WooCommerce's built-in offline gateways. You can enable verification for any combination of the three. Online payment methods (cards, PayPal, etc.) are never affected.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20the%20customer%20doesn%27t%20verify%20the%20code%3F\"><h3>What happens if the customer doesn't verify the code?<\/h3><\/dt>\n<dd><p>WooCommerce will not allow the order to be placed until a valid, unexpired code has been verified \u2014 this is enforced on the server, not just hidden in the browser.<\/p><\/dd>\n<dt id=\"is%20customer%20data%20sent%20anywhere%20besides%20my%20own%20site%3F\"><h3>Is customer data sent anywhere besides my own site?<\/h3><\/dt>\n<dd><p>Only if you enable SMS delivery, in which case the phone number and OTP code are sent to Twilio to deliver the text message. Email delivery uses your site's own <code>wp_mail()<\/code> and involves no external service.<\/p><\/dd>\n<dt id=\"will%20this%20actually%20reduce%20rto%20%28return%20to%20origin%29%20and%20fake%20cod%20orders%3F\"><h3>Will this actually reduce RTO (Return to Origin) and fake COD orders?<\/h3><\/dt>\n<dd><p>Yes \u2014 this is the core purpose of the plugin. Requiring a customer to verify a live OTP sent to their own phone or email before an order is accepted filters out fake orders, prank orders, and mistyped contact details, which are the leading causes of failed COD deliveries and RTO losses.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.3<\/h4>\n\n<ul>\n<li>Fixed the auto-cancel cron repeatedly re-cancelling and re-emailing the same order every run instead of handling it once.<\/li>\n<\/ul>\n\n<h4>1.4.2<\/h4>\n\n<ul>\n<li>Registered the missing 5-minute cron schedule so unverified orders are actually auto-cancelled.<\/li>\n<li>Removed an inline script from the classic checkout markup.<\/li>\n<li>Renamed the plugin.<\/li>\n<\/ul>\n\n<p>See <code>changelog.txt<\/code> for the full version history.<\/p>","raw_excerpt":"Stop fake Cash on Delivery (COD) orders and reduce RTO losses with mandatory SMS\/Email OTP verification for WooCommerce checkout.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/375468","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=375468"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/costatech"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=375468"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=375468"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=375468"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=375468"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=375468"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=375468"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}