WALoops OTP Login
Add WhatsApp OTP login & registration to WordPress in minutes. 100 free OTPs/month, no credit card required.
Solid choice
WALoops OTP Login is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 11 hours ago, and scores 64/100 on our health check.
- Actively developed β last update 11 hours ago
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release β each site that auto-updates counts as a download.
Rankings
Where WALoops OTP Login stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| otp login | #61 |
| passwordless login | #96 |
| phone login | >100 |
| whatsapp login | >100 |
| whatsapp otp | #35 |
About WALoops OTP Login
From the official readme Β· v1.6.3Description
Add WhatsApp OTP login to WordPress in 2 minutes.
A password-free login and registration option, delivered over WhatsApp β works alongside your existing login form, on any theme, with or without WooCommerce. No password to remember, no password to reset, no password to leak.
Free forever β 100 OTPs/month
Get a free API key by creating a WALoops account from the plugin’s settings page (no credit card) and start sending real WhatsApp OTPs from WALoops’ shared WhatsApp number immediately.
Everything you need, nothing you don’t
- Adds, never replaces β sits alongside your normal login and registration forms as an extra option, never in place of them
- 3 ready-made designs β Modern, Minimal, and Card form styles, pick one in Settings, no CSS required
- Works in minutes β no Meta Developer account needed on the Free or Introduction (shared-number) plans
- Bring your own number β Introduction and Starter Ecommerce plans let you send from your own WhatsApp Business number
- WooCommerce checkout β offer WhatsApp OTP verification right at checkout on the Starter Ecommerce plan
- Email code login too β optionally offer a 6-digit code sent by email alongside (or instead of) WhatsApp; it uses your site’s normal email, needs no API key, and a new email address becomes a new account
- Shortcode-friendly β place the form anywhere with
[wa_otp_login], or drag it on as a native Elementor widget or WPBakery Page Builder element - Spam-proof your other forms β a “WhatsApp OTP Verify” field/tag for Contact Form 7, WPForms, Gravity Forms, and Formidable Forms blocks submission until the visitor’s number checks out (experimental for Ninja Forms β test before relying on it)
- Goes global β a country dial-code selector on every phone field, pre-filled from the visitor’s browser language and always changeable
- Fully translatable (text domain:
waloops-otp-login)
Simple, WordPress-friendly pricing
Start free. Upgrade only when you actually need more volume or your own number.
- Free β $0/month. Everything you need to try WhatsApp OTP login on a live site: 100 OTPs/month from our shared number, all 3 form styles, login/register/shortcode placement.
- Introduction β $5/month. For sites outgrowing the free quota: 1,000 OTPs/month, use our shared number or connect your own, switch any time.
- Starter Ecommerce β $9.99/month. For high-traffic and WooCommerce sites: unlimited OTPs on your own connected WhatsApp Business number, checkout verification, and priority support.
How it works
- Install and activate the plugin.
- Go to Settings > WhatsApp OTP Login and click Create a free WALoops account β you’ll land straight on your API key. Paste it into the field on this same settings page.
- Pick where the OTP option should appear (login page, registration page, WooCommerce checkout) β or drop the
[wa_otp_login]shortcode anywhere. - Done. Visitors can now log in or register with just their WhatsApp number.
- To verify a phone number on your own Contact Form 7, WPForms, Gravity Forms, or Formidable Forms form instead: add a
[wa_otp_verify your-phone]tag in the CF7 form editor, or drag/add the “WhatsApp OTP Verify” field into the other three builders β no extra setup needed once your API key is saved. - Using Elementor or WPBakery Page Builder? Drag the “WhatsApp OTP Login” widget/element onto any page instead of using the shortcode.
External services
This plugin connects to WALoops’ WhatsApp OTP service (https://app.waloops.com/) to deliver one-time-password messages over WhatsApp. This connection is required for the plugin to work β there’s no way to send a WhatsApp message without it.
What is sent, and when:
- Creating a free WALoops account: when you click “Get Free API Key” on the settings page, the email address and WhatsApp number you typed, and your site’s URL, are sent to WALoops to create your account and return your API key. Nothing is sent until you click. If you also tick the optional box “Message me on WhatsApp to help me set this up” (unchecked by default), WALoops may send you a WhatsApp message on that number to help with setup; you can reply STOP at any time.
- When a visitor requests a verification code (login, registration, checkout, or a Contact Form 7 / WPForms field): their phone number is sent to WALoops so it can send them a WhatsApp message containing the code.
- When a visitor submits a code: their phone number and the code they entered are sent to WALoops to be checked.
- On the settings page: your account’s monthly usage is fetched from WALoops so it can be shown to you. If you choose to connect your own WhatsApp Business number, your Meta access token and phone number ID are also sent to WALoops, to verify and store for your account.
-
Abandoned Cart Reminder (Starter plan, off by default β only shown to eligible accounts): once turned on, a shopper’s phone number, name, and cart contents (items, total, currency, coupon codes, checkout URL) are sent to WALoops after they enter a phone number at checkout and leave without ordering within the configured wait time, so it can send them a WhatsApp reminder. This is decided and timed entirely on your own site (WordPress schedules and cancels the check itself); nothing is sent to WALoops while a shopper is still actively checking out.
-
Email code login (optional, off by default): the code is generated and checked entirely on your own site. Nothing about it is sent to WALoops.
Email delivery (Settings > Email delivery): by default the code email goes out through WordPress’s own wp_mail() (and any SMTP plugin you use), or PHP mail() if you pick it. If you instead pick an email provider (Gmail, Outlook / Microsoft 365, Zoho, Yahoo, SendGrid, Brevo, Mailgun, Amazon SES, Postmark) or your own SMTP server, the plugin logs in to that provider’s SMTP server with the credentials you enter and hands it the visitor’s email address and the message, only when a code is sent (or when you click Send test). Nothing is sent to a provider you haven’t chosen. Their terms apply: Google, Microsoft, Zoho, Yahoo, SendGrid, Brevo, Mailgun, Amazon SES, Postmark.
No data is sent to any other third party. See WALoops’ Terms of Service and Privacy Policy.
Frequently asked questions
Do I need a Meta/Facebook Developer account?
No β not on the Free or Introduction plans, where you can send from WALoopsβ shared WhatsApp number. Connecting your own number (optional on Introduction, required on Starter Ecommerce) does require your own WhatsApp Business Cloud API app.
What happens when I run out of free OTPs for the month?
Sends are blocked with a clear βmonthly limit reachedβ message until the next calendar month starts, or until you upgrade.
Does this replace my normal login form?
No. Itβs added as an extra option alongside your existing username/password login and registration forms.
Can I customize the WhatsApp message text?
WhatsApp only allows pre-approved wording for one-time-passcode (Authentication-category) messages β you canβt write fully custom copy. Right now the message is β{code} is your verification code. For your security, do not share this code.β More variants (with an expiry line, code-only) will appear as an option once theyβre approved with Meta.
Is my visitorsβ data safe?
Phone numbers and OTP codes are transmitted over HTTPS and are used solely to deliver and verify the one-time password. See the βExternal servicesβ section above for exactly whatβs sent and when.
Why did an abandoned-cart reminder go out later than the wait time I set?
The reminder timer is scheduled on WordPressβs own cron, which only actually runs when someone visits your site β on a low-traffic store that can mean a delay past the configured wait time. For reliable, on-time delivery, ask your host to add a real server cron job that calls your siteβs wp-cron.php every minute or two (most hosting control panels have a βCron Jobsβ section for this) β the exact URL to use is shown on the Settings page once Abandoned Cart Reminder is available on your account.
Does this work with international phone numbers?
Yes. Every phone field has a country dial-code selector (pre-filled from the visitorβs browser language, always changeable) β thereβs no restriction to a specific country, as long as WhatsApp is reachable at that number.
How does the form-builder verification work?
Add the [wa_otp_verify your-phone] tag (CF7) or the βWhatsApp OTP Verifyβ field (WPForms, Gravity Forms, Formidable Forms) to your form. A visitor enters their WhatsApp number, receives a code, and enters it β the form canβt be submitted until that check passes. No phone number is stored by this plugin for this feature; verification is a signed, short-lived token checked again on submission, the same way a nonce works.
Which form builders are supported?
Contact Form 7, WPForms, Gravity Forms, and Formidable Forms are fully supported. Ninja Forms support is experimental β please test it on your own site before relying on it. Elementor Pro Forms, Fluent Forms, and SureForms arenβt supported yet.
Changelog
Adds an optional email-code login method (off by default β enable it under Login methods in Settings).
1.6.3
- New: sites on the Free plan see a card on the settings page explaining the Introduction plan ($5/month), which sends login codes from your own WhatsApp Business number (your name and logo) instead of the shared number. Shown only on this plugin’s settings page; paid plans never see it.
1.6.2
- New: bundled translations for Spanish (Spain, Mexico, Colombia, Argentina, Chile, Peru), Portuguese (Brazil), French, German, Italian, Arabic, Hindi, Indonesian and Turkish. The login form, messages and settings screens follow the site language (Settings > General > Site Language). Community translations from translate.wordpress.org take priority once they exist.
- Fix: the Ninja Forms field and a few settings-screen messages were always shown in English.
1.6.1
- New: once 20 visitors have signed in with a WhatsApp code, administrators see a one-time notice asking for a review on WordPress.org. “Maybe later” hides it for 30 days; “Leave a review” or “I already did” hides it for good.
- New:
wa_otp_login_verifiedaction, fired after a visitor signs in with a WhatsApp code.
1.6.0
- New: optional Email code (OTP) login and registration, next to WhatsApp OTP. A visitor enters their email, gets a 6-digit code (valid 10 minutes, single use, 5 wrong tries before it’s burned, rate-limited per email and per IP) and is logged in β a first-time email becomes a real account (a WooCommerce customer on WooCommerce sites), an existing one is logged in. Sent with
wp_mail(), so it needs no API key and works even if you only want email. Off by default; turn it on under Login methods in Settings. When both methods are on, the form gets WhatsApp | Email code tabs and you choose which opens first. New filterwa_otp_login_email_login_allowedlets you keep email-code login away from sensitive accounts (e.g. administrators).
1.5.0
- New: Abandoned Cart Reminder (Starter plan, off by default) β sends a WhatsApp reminder when a WooCommerce shopper enters a phone number at checkout and leaves without ordering. WordPress itself decides when a cart counts as abandoned (a delayed check, rescheduled on every checkout change and cancelled once the order completes) and reports it once to your WALoops account, which fires it as a “Checkout Abandoned” Connection under Automation β build the actual reminder message there. Works independently of whether the WhatsApp OTP login widget itself is enabled. Also now tracks email-only carts (no phone entered) with a channel flag for a future email reminder β not yet sent.
1.4.0
- New: “Form Builder” admin page β the Login form stays fixed to just a Mobile Number (that’s all OTP login needs), but the Register form now always collects a Full Name alongside the Mobile Number, plus a tick-box list of optional fields (Email, Company Name, Address, City, Date of Birth) you can turn on. Collected values are saved to the new WordPress account: Full Name sets the account’s name/display name, Email replaces the generated placeholder address, everything else is stored as user meta.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own β no account needed.
Best WALoops OTP Login alternatives
All otp login plugins βFAQ
WALoops OTP Login: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org Β· checked Oct 11, 2026
Is WALoops OTP Login free?
Yes. WALoops OTP Login is free to download and use from the official WordPress.org plugin directory.
Is WALoops OTP Login safe to use in 2026?
WALoops OTP Login is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 11 hours ago, and scores 64/100 on our health check.
How many websites use WALoops OTP Login?
WALoops OTP Login is active on <10 WordPress websites and has been downloaded 315 times since it launched in September 2026. It was downloaded 243 times in the last 30 days.
Does WALoops OTP Login work with WordPress 7.1?
Yes. The developer has tested WALoops OTP Login up to WordPress 7.1.3, the latest release. It requires WordPress 5.8 or newer.
What PHP version does WALoops OTP Login need?
WALoops OTP Login requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was WALoops OTP Login last updated?
The latest version, 1.6.3, was released on October 11, 2026 (11 hours ago).
Who makes WALoops OTP Login?
WALoops OTP Login is developed and maintained by Varni Infotech.
What are the best alternatives to WALoops OTP Login?
The most popular alternatives to WALoops OTP Login are Login & Register Customizer (30K+ installs), WSMS (formerly WP SMS) (7K+ installs) and miniOrange OTP Login, Verif⦠(5K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages β with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org β no credit card