{"id":380361,"date":"2026-10-05T21:42:18","date_gmt":"2026-10-05T21:42:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/codflow\/"},"modified":"2026-10-05T21:42:05","modified_gmt":"2026-10-05T21:42:05","slug":"codlino-cod-order-forms","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/codlino-cod-order-forms\/","author":23579272,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.6.1","stable_tag":"0.6.1","tested":"7.1.3","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"Codlino \u2013 COD Order Forms for WooCommerce","header_author":"Taha Belmezrar","header_description":"Simple cash-on-delivery forms for WooCommerce and Elementor.","assets_banners_color":"","last_updated":"2026-10-05 21:42:05","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/profiles.wordpress.org\/tahabelmezrar\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":208,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.6.1":{"tag":"0.6.1","author":"tahabelmezrar","date":"2026-10-05 21:42:05","revision":3729688}},"upgrade_notice":{"0.6.1":"<p>Refined dashboard and order-form styling, coordinated color presets and improved\nmobile spacing. Existing saved colors are preserved. Apply a preset under\nAppearance to use the new palette on an existing form.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3729688,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3729688,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.6.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3729688,"resolution":"1","location":"assets","locale":"","width":1265,"height":712},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3729688,"resolution":"2","location":"assets","locale":"","width":1265,"height":712}},"screenshots":{"1":"Codlino admin workspace with organized form settings and navigation.","2":"Classic, Express and Premium cash-on-delivery form designs."}},"plugin_section":[],"plugin_tags":[31179,76538,601,286],"plugin_category":[42,45],"plugin_contributors":[284592],"plugin_business_model":[],"class_list":["post-380361","plugin","type-plugin","status-publish","hentry","plugin_tags-cash-on-delivery","plugin_tags-elementor","plugin_tags-forms","plugin_tags-woocommerce","plugin_category-contact-forms","plugin_category-ecommerce","plugin_contributors-tahabelmezrar","plugin_committers-tahabelmezrar"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/codlino-cod-order-forms\/assets\/icon-128x128.png?rev=3729688","icon_2x":"https:\/\/ps.w.org\/codlino-cod-order-forms\/assets\/icon-256x256.png?rev=3729688","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/codlino-cod-order-forms\/assets\/screenshot-1.png?rev=3729688","caption":"Codlino admin workspace with organized form settings and navigation."},{"src":"https:\/\/ps.w.org\/codlino-cod-order-forms\/assets\/screenshot-2.png?rev=3729688","caption":"Classic, Express and Premium cash-on-delivery form designs."}],"raw_content":"<!--section=description-->\n<p>Arabic dashboard, multiple independently configured forms, Elementor shortcode\n[codlino_form id=\"123\"], RTL layout and responsive styling. Each form orders a published simple or variable WooCommerce product, with an\noptional quantity selector. Orders use WooCommerce CRUD APIs,\nCOD, on-hold status, stock handling and the standard receipt page; HPOS declared.<\/p>\n\n<p>Start a new form with no fixed fields and create up to 30 fields: text, textarea,\nemail, phone, number or select. Use a small required checkbox under each field. Choose optional\nprice display and colors for the box, fields, field borders, button and button text.\nFields are visible in WooCommerce order details. Optional role mapping populates\ncustomer name, city, phone, address and email. Legacy fixed fields migrate to\neditable\/deletable fields without changing existing form IDs.<\/p>\n\n<p>Three ready-made styles (Classic, Express, Premium) apply their palette and layout\nwithout replacing fields. Select Arabic\/Latin fonts, button text size, vertical\npadding, width, gap above the button and optional gentle shake animation.\nRemote selected fonts load from Google Fonts; Janna must be loaded by your site.\nReduced-motion preferences disable animation. Optional Moroccan mobile format\nvalidation accepts 06\/07 and 212\/+212\/00212 international formats on the server.<\/p>\n\n<p>Optional phone\/IP duplicate blocking lasts 24 hours after an accepted order,\nwith editable messages. Optional HTTPS JSON webhooks run asynchronously with\nup to three attempts. Webhook failure never cancels an accepted WooCommerce order.\nPowered by Taha Belmezrar.<\/p>\n\n<h3>Operational details<\/h3>\n\n<ul>\n<li>One product per form; optional quantity (1\u2013100 maximum, subject to stock).<\/li>\n<li>Variable products support up to 200 variations. Configure attributes, prices,\nstock and variation images in WooCommerce. Choose buttons, colors, images or\nselect lists per attribute in Codlino. Prices displayed are per unit.<\/li>\n<li>No coupons, shipping-zone pricing or upsells.<\/li>\n<li>Assign a field role to map it to customer details; unmapped fields are metadata.\nEmail role populates billing email; WooCommerce handles notifications. One field\nper role is allowed. Publishing requires at least one field. The builder uses JavaScript.<\/li>\n<li>Store country is used. No state\/postcode mapping; verify tax rules for this model.<\/li>\n<li>Delivery line costs zero. On-hold orders are unpaid.<\/li>\n<li>Site font is the default. Janna is local; Cairo, Tajawal, Noto Sans Arabic, Inter,\nPoppins and Open Sans use Google Fonts only when selected (internet required).<\/li>\n<li>Duplicate protection counts accepted Codlino submissions where protection was\nenabled, across protected forms on this site. Historical orders and orders from\nother checkout flows are not scanned. Cancellation does not remove the 24h block.<\/li>\n<li>Phone protection makes phone required. It normalizes common country-code formats;\nMoroccan validation is a separate optional switch; it checks syntax, not ownership\nor whether a number is allocated\/active. A mapped phone is required for either switch.<\/li>\n<li>IP means public network address: several customers may share one IP. REMOTE_ADDR\nis used; trusted proxies require the codlino_client_ip filter configured by an admin.<\/li>\n<li>Generic webhooks require direct HTTPS JSON endpoints returning 2xx without redirects.\nGoogle Sheets mode includes an Arabic setup guide, generated Apps Script receiver,\ncopy button and admin-only test. It follows only Google content redirects via GET\nand verifies a matching JSON write acknowledgment. Each form uses a private token.\nTests add a dummy Sheet row, never a WooCommerce order. WP-Cron runs real delivery\/retries.<\/li>\n<li>A guard table is created on upgrade. Expired blocks stop blocking by timestamp,\neven before daily cleanup. WP-Cron also retires temporary request records.<\/li>\n<li>Request retry protection lasts 48 hours. AJAX refreshes nonce\/request IDs for\ncached pages. Without JavaScript, exclude form pages from full-page caching.<\/li>\n<li>Deactivation\/removal preserves forms, orders and configuration.<\/li>\n<\/ul>\n\n<h3>External services and privacy<\/h3>\n\n<p>Codlino does not phone home to its author and has no analytics or licensing\nconnection. A merchant can use the form and create orders with all external\nintegrations disabled. The default font uses the site's own styles.<\/p>\n\n<h4>Google Fonts (optional)<\/h4>\n\n<p>Selecting Cairo, Tajawal, Noto Sans Arabic, Inter, Poppins or Open Sans loads a\nstylesheet from fonts.googleapis.com and font files from fonts.gstatic.com.\nRequests happen in the admin preview and visitors' browsers where that font is\nused. Google receives the browser IP address and normal HTTP request information.\nChoose the site font or locally supplied Janna to avoid these Google requests.\nService: https:\/\/fonts.google.com\/\nTerms: https:\/\/policies.google.com\/terms\nPrivacy: https:\/\/policies.google.com\/privacy<\/p>\n\n<h4>Google Apps Script and Google Sheets (optional)<\/h4>\n\n<p>The merchant configures and deploys the bundled receiver using their own Google\naccount and spreadsheet. Enabling the integration sends accepted order data\nfrom the WordPress server to the configured script.google.com\/macros\/s\/...\/exec\nendpoint. Data includes order\/form\/event identifiers, customer name, phone,\ncity, country, products, selected attributes, quantity, totals, currency, status\nand configured form fields. A private per-form receiver token authenticates the\nPOST. Google may serve its response at script.googleusercontent.com\/macros\/echo;\nCodlino reads it by GET without forwarding the POST body or token. Google also\nreceives the server IP address and normal HTTP request information. Clicking\nTest sends synthetic sample data and creates a test row, with no WooCommerce\norder. Real delivery and retries run through WP-Cron.\nService: https:\/\/developers.google.com\/apps-script\nTerms: https:\/\/policies.google.com\/terms\nPrivacy: https:\/\/policies.google.com\/privacy<\/p>\n\n<h4>Merchant-configured generic webhooks (optional)<\/h4>\n\n<p>Enabling a webhook sends the same order payload, without the Sheets token, to\nthe merchant's own HTTPS endpoint. Clicking Test sends synthetic sample data.\nThe endpoint provider's terms\/privacy policy apply; merchants must review them\nand disclose relevant processing to shoppers before enabling their integration.<\/p>\n\n<h4>Local storage<\/h4>\n\n<p>Orders and customer details are stored in WooCommerce. Form settings, webhook\nendpoints and receiver tokens are stored in the WordPress database. Order\nmetadata keeps submitted form fields, selected attributes and delivery state;\nenabled Sheets delivery stores its endpoint and token with the order for retries.\nDuplicate phone\/IP guards use salted HMAC identifiers with 24-hour expiry;\nrequest records expire after 48 hours. Orders retain the WooCommerce customer\nIP and submitted details subject to the merchant's WooCommerce retention policy.\nDeactivation\/removal preserves settings, forms and orders. Merchants manage\nWooCommerce customer-data retention and any external spreadsheet\/webhook copies.<\/p>\n\n<h3>Extension points<\/h3>\n\n<p>codlino_validate_submission($error, $fields, $form_id)\ncodlino_order_created($order, $form_id)\ncodlino_client_ip($ip)\nOrder metadata retains _codflow_form_id, _codflow_full_name, _codflow_request_id,\n_codflow_fields and optional webhook delivery metadata for upgrade compatibility.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Activate WooCommerce 8.2+ and enable Cash on delivery.<\/li>\n<li>Upload codlino-cod-order-forms-0.6.1.zip. When upgrading from CODFlow,\ndeactivate CODFlow first, then install and activate Codlino.<\/li>\n<li>Create a published simple or variable product. Include delivery in its price; for physical\nproducts leave COD shipping-method restrictions empty.<\/li>\n<li>Open Codlino, create\/edit a form, choose its product and save as published.<\/li>\n<li>Embed its shortcode in Elementor or a WordPress Shortcode block.<\/li>\n<li>Verify orders and enabled integrations on staging before live traffic.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20license%20key%20or%20an%20account%3F\"><h3>Do I need a license key or an account?<\/h3><\/dt>\n<dd><p>No. All features included in this plugin work without a paid license key or an\nauthor account. Google integrations require the merchant's own Google account.<\/p><\/dd>\n<dt id=\"is%20elementor%20required%3F\"><h3>Is Elementor required?<\/h3><\/dt>\n<dd><p>No. Use [codlino_form id=\"123\"] in a WordPress Shortcode block or an Elementor\nShortcode widget. WooCommerce is required; Elementor is optional.<\/p><\/dd>\n<dt id=\"does%20disabling%20the%20webhook%20stop%20woocommerce%20orders%3F\"><h3>Does disabling the webhook stop WooCommerce orders?<\/h3><\/dt>\n<dd><p>No. Orders are saved directly in WooCommerce. External delivery is optional.<\/p><\/dd>\n<dt id=\"does%20installing%20this%20plugin%20send%20data%20to%20the%20author%3F\"><h3>Does installing this plugin send data to the author?<\/h3><\/dt>\n<dd><p>No. Optional Google Fonts and merchant-configured integrations are described\nunder External services and privacy.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.6.1<\/h4>\n\n<p>Refined admin and storefront styling with consistent emerald, ivory and ink\npalettes, responsive spacing, clear focus states and coordinated presets.\nExisting merchant color settings remain preserved.<\/p>\n\n<h4>0.6.0<\/h4>\n\n<p>Rename to Codlino \u2013 COD Order Forms for WooCommerce with text domain\ncodlino-cod-order-forms. Add allowlisted, typed request sanitizers and explicit\npermission\/nonce checks at admin save endpoints. Replace manual core admin\nheader\/footer loading with redirects and per-user admin validation notices.\nRetain persisted identifiers and legacy shortcode\/cron compatibility.<\/p>\n\n<h4>0.5.6<\/h4>\n\n<p>Constrain the admin menu icon to 20px on every WordPress admin screen.<\/p>\n\n<h4>0.5.5<\/h4>\n\n<p>Selected Codlino icon in the admin menu, dashboard header and information section.\nSoft section backgrounds and clearer navigation colors.<\/p>\n\n<h4>0.5.4<\/h4>\n\n<p>Admin dashboard refresh: emerald brand header, distinct section accents, clearer\ninputs, cards, focus states and responsive navigation. Frontend styling unchanged.<\/p>\n\n<h4>0.5.3<\/h4>\n\n<p>Set the enqueued Google font resource version and place the documented Apps Script\nresponse-host analyzer exception at the validated host literal. No delivery or\nsecurity behavior changes.<\/p>\n\n<h4>0.5.2<\/h4>\n\n<p>Plugin Check fixes: translator comments, prefixed template variables, safe field\nattributes, WordPress font enqueue\/late printing, sanitized server input and\nprepared SQL identifiers. Document narrowly scoped analyzer exceptions for\nnonce-verified delegation, read-only navigation and atomic uncached guard queries.\nGoogle Sheets acknowledgment handling is unchanged and documented as service\ncommunication. Tested up to reflects the merchant-reported WordPress 7.1 site.<\/p>\n\n<h4>0.5.1<\/h4>\n\n<p>Publication preparation: document optional external services and local storage,\nclarify account requirements, and correct the 0.4.1 changelog version.<\/p>\n\n<h4>0.5.0<\/h4>\n\n<p>Save in place and advance through setup sections. Empty forms save as drafts with\nan Arabic popup. WooCommerce variations with colors\/images\/sizes and optional\nquantity. Server-authoritative variation prices, eligibility and stock.\nSelected attributes and quantity are included in webhook\/Sheets data.<\/p>\n\n<h4>0.4.1<\/h4>\n\n<p>Light dashboard refresh: white surfaces, quiet green accent, numbered sections,\nclearer text and controls, mobile navigation and refined frontend presentation.<\/p>\n\n<h4>0.4.0<\/h4>\n\n<p>Built-in Google Sheets setup guide and Apps Script generator, private per-form\nreceiver token, verified Google response handling and admin webhook test.<\/p>\n\n<h4>0.3.0<\/h4>\n\n<p>Fields from scratch, per-field required checkbox and customer role mapping.\nThree templates, font selection, button size\/gap\/motion and Moroccan phone validation.<\/p>\n\n<h4>0.2.0<\/h4>\n\n<p>Arabic dashboard and branding, custom field builder, configurable colors,\noptional HTTPS webhook, optional 24-hour phone\/IP duplicate blocking.<\/p>\n\n<h4>0.1.1<\/h4>\n\n<p>RTL layout, hidden required markers, optional fields and price visibility.<\/p>\n\n<h4>0.1.0<\/h4>\n\n<p>Initial MVP.<\/p>","raw_excerpt":"Customizable Arabic cash-on-delivery forms for WooCommerce with optional Sheets integration.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/380361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=380361"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/tahabelmezrar"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=380361"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=380361"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=380361"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=380361"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=380361"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=380361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}