BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
Rishav AuthNova OTP icon
Maintained Tested up to 6.9.9 #46 in email verification

Rishav AuthNova OTP

OTP verification for WordPress login, registration, and password reset using email and SMS delivery.

Active installs<10New
Downloads · 30d54▲ +45.9% vs prev. 30d
Rating—0 reviews
Health score42/100Fair
All-time downloads384Since Apr 2026
Support resolved—No recent threads
RequiresWP 5.8PHP 7.4+
Downloads · 7d12▼ -25% week over week
Our verdict

Use with caution

Rishav AuthNova OTP works, but test it on a staging site before relying on it in 2026. Was last updated 6 months ago, and scores 42/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far
  • Only tested up to WordPress 6.9 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

123Jul 7Aug 20Oct 4
Yesterday1
Daily average (1y)2
Peak day30Apr 17, 2026
Last 12 months391

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where Rishav AuthNova OTP stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
email verification >100 3,506 Best email verification plugins →
login security >100 4,174 Best login security plugins →
otp >100 391 Best otp plugins →
sms >100 1,485 Best sms plugins →
two factor >100 636 Best two factor plugins →

About Rishav AuthNova OTP

From the official readme · v1.0.0

Description

Rishav AuthNova OTP adds a one-time-password verification layer to core WordPress authentication flows.

Features include:

  • Configurable OTP length and charset (numeric or alphanumeric)
  • OTP expiry and retry limits with temporary lockouts
  • Login OTP verification step (after password check)
  • OTP-gated registration flow
  • OTP-gated password reset flow
  • Delivery via wp_mail, SendGrid, and Twilio
  • OTP storage using hashes (never plaintext)
  • Resend OTP with cooldown and challenge rotation

Security highlights:

  • OTP values are hashed before storage and are never saved as plaintext
  • OTP hashes use keyed HMAC storage and constant-time verification
  • OTP challenges expire automatically and enforce retry limits per challenge
  • Request throttling applies cooldown and exponential backoff per IP and identifier
  • Lockout windows reduce repeated invalid OTP submissions
  • Nonces are applied on sensitive form submissions
  • Public auth responses are intentionally generic to reduce account-enumeration leakage
  • Delivery uses synchronous-first send with bounded async retry fallback and challenge-level delivery status tracking

Security limitations:

  • This plugin does not replace passwords, HTTPS, WAF/rate-limiting at the edge, or secure hosting controls
  • OTP delivery depends on the configured email/SMS provider uptime and deliverability
  • Administrators should combine this plugin with standard WordPress hardening and monitoring

Reliability notes:

  • OTP delivery is attempted synchronously first to reduce silent failures
  • If synchronous delivery fails and background delivery is healthy, the plugin schedules bounded retries
  • If background delivery is unhealthy (for example DISABLE_WP_CRON), fallback queueing is skipped and users receive a retry-safe error
  • Resend cooldown state is server-authoritative and exposed through a status endpoint used by frontend countdown UX
  • Background queue payload contains only challenge ID (no raw OTP or destination data)

External Services

This plugin can connect to third-party services to deliver OTP messages. These services are optional and only used if enabled in plugin settings.

Twilio (SMS Delivery)

  • Service: Twilio Programmable Messaging API
  • Purpose: Send OTP codes by SMS
  • Data sent: destination phone number, sender phone number, OTP message text, account SID for authentication
  • Credential handling: Twilio credentials are stored in WordPress options and used only when sending OTP messages
  • When sent: when OTP delivery method includes SMS and an OTP is generated for login, registration, password reset, or resend
  • Why sent: to deliver time-sensitive OTP codes to the user by SMS
  • Terms of Service: https://www.twilio.com/legal/tos
  • Privacy Policy: https://www.twilio.com/en-us/legal/privacy

SendGrid (Email Delivery)

  • Service: SendGrid Mail Send API
  • Purpose: Send OTP codes by email
  • Data sent: recipient email address, sender email/name, message subject, OTP message body, API key for authentication
  • Credential handling: SendGrid API key is stored in WordPress options and used only when sending OTP messages
  • When sent: when email provider is set to SendGrid and an OTP is generated for login, registration, password reset, or resend
  • Why sent: to deliver time-sensitive OTP codes to the user by email
  • Terms of Service: https://sendgrid.com/policies/terms/
  • Privacy Policy: https://sendgrid.com/policies/privacy/

Configuration

  1. Set OTP length, type, expiry, retry limit, and lockout duration.
  2. Choose delivery method: Email, SMS, or Both.
  3. Configure provider credentials for SendGrid and/or Twilio if needed.
  4. Enable or disable OTP on login, registration, and password reset flows.

Installation

  1. Upload the plugin folder to /wp-content/plugins/.
  2. Activate the plugin through the Plugins screen in WordPress.
  3. Go to Settings > OTP Authentication.
  4. Configure OTP rules and delivery providers.

Frequently asked questions

Does this plugin store OTP values in plain text?

No. OTP values are hashed before storage and verified using hash comparison.

Can I use SMS delivery?

Yes. Twilio is supported for SMS delivery.

Can I use email API delivery?

Yes. SendGrid API is supported, and wp_mail is available as a fallback.

Does this work with the default wp-login.php flow?

Yes. The plugin integrates with WordPress login, registration, and lost-password actions.

What user field is used for phone numbers?

By default, the plugin reads phone_number user meta. You can change the meta key in plugin settings.

Changelog

Initial stable release.

1.0.0

  • Initial release.
  • Added OTP flows for login, registration, and reset.
  • Added SendGrid and Twilio integrations.
  • Added resend cooldown UX and secure challenge rotation.
  • Added configurable OTP policy controls in the admin settings page.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best Rishav AuthNova OTP alternatives

All email verification plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Customer Email Verification for WooCommerce Customer Email Verification for WooCommerce Enhance WooCommerce security with Email Verification. Ensure genuine customer interactions… by WPFactory 8K+ ★★★★★★★★★★ 4.8 (47) 2 months ago 68
2 miniOrange OTP Login, Verification and SMS Notifications miniOrange OTP Login, Verification and SMS Notifications OTP via SMS, Email/WhatsApp. WooCommerce SMS Notifications, Phone OTP Login, Passwordless… by miniOrange 5K+ ★★★★★★★★★★ 4.7 (439) 5 days ago 88
3 Customer Email Verification for WooCommerce Customer Email Verification for WooCommerce Block fake WooCommerce registrations with OTP email verification. Customers verify their… by Zorem 2K+ ★★★★★★★★★★ 4.4 (19) 3 weeks ago 70
4 Double Opt-In for Contact Form 7 – Secure, GDPR-Compliant Email Verification Double Opt-In for Contact Form 7 Protect your Contact Form 7 forms with GDPR-compliant Double Opt-In. Ensure valid emails… by Forge12 Interactive GmbH 1K+ ★★★★★★★★★★ 5 (9) 3 days ago 86
5 ZeroBounce Email Verification & Validation ZeroBounce Email Verification & Validation ZeroBounce validates emails on your WordPress site in real-time, blocking invalid and risky… by zerobounce 900+ ★★★★★★★★★★ 4.8 (4) 1 month ago 60
6 Clearout Email Validator – Real-Time Email Verification on WordPress Forms Clearout Email Validator Block invalid emails like temporary, disposable, etc. with our real-time email… by clearoutio 500+ ★★★★★★★★★★ 4.2 (13) 4 weeks ago 79
7 DeBounce Email Validator DeBounce Email Validator Real-time email validation for WordPress forms. Block invalid, disposable, and risky emails… by debounce 300+ ★★★★★★★★★★ 3.9 (16) 2 months ago 73
8 QuickEmailVerification QuickEmailVerification The QuickEmailVerification email verification plugin to avoid fake, bad and nonexistent… by quickemailverification 200+ ★★★★★★★★★★ 5 (5) 4 days ago 81
9 Email Verification for Elementor Forms Email Verification for Elementor Forms Add email verification to Elementor forms: users confirm via code, ensuring valid… by rloes 100+ ★★★★★★★★★★ 5 (2) 2 years ago 32
10 Email verification on signups Email verification on signups Send verification links to newly registered users and ask them to confirm their email… by Dornaweb 100+ ★★★★★★★★★★ 5 (4) 2 years ago 32

FAQ

Rishav AuthNova OTP: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 5, 2026

Is Rishav AuthNova OTP free?

Yes. Rishav AuthNova OTP is free to download and use from the official WordPress.org plugin directory.

Is Rishav AuthNova OTP safe to use in 2026?

Rishav AuthNova OTP works, but test it on a staging site before relying on it in 2026. Was last updated 6 months ago, and scores 42/100 on our health check.

How many websites use Rishav AuthNova OTP?

Rishav AuthNova OTP is active on <10 WordPress websites and has been downloaded 384 times since it launched in April 2026. It was downloaded 54 times in the last 30 days.

Does Rishav AuthNova OTP work with WordPress 7.1?

Rishav AuthNova OTP is officially tested up to WordPress 6.9.9, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does Rishav AuthNova OTP need?

Rishav AuthNova OTP requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was Rishav AuthNova OTP last updated?

The latest version, 1.0.0, was released on April 17, 2026 (6 months ago).

Who makes Rishav AuthNova OTP?

Rishav AuthNova OTP is developed and maintained by rishav001.

What are the best alternatives to Rishav AuthNova OTP?

The most popular alternatives to Rishav AuthNova OTP are Customer Email Verification… (8K+ installs), miniOrange OTP Login, Verif… (5K+ installs) and Customer Email Verification… (2K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.