Plugin Pulse
← Pulse

OTP Login With Phone Number, OTP Verification

by Hamid Alinia · Login & Users

Also makes 2 other plugins · 900+ installs across the portfolio →

Passwordless OTP login for WordPress. Login or register with phone number via SMS or Firebase. Compatible with WooCommerce. GDPR-compliant.

How scoring works →
90 Health · A
Maintenance 100/100
Rating quality 94/100
Support 70/100

90 health vs 59 average across 1,442 Login & Users plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

83 / 100

Well optimized

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 92/100
Listing tuning 100/100
Support resolution 0/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,425 days · wp.org + Plugin Pulse archive

+28% vs prior 30d
55Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

2.0K

now · peak 7.9K

2.1K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

OTP Login With Phone · #7060 you Email OTP Authentica · #13877 Temporary Login With · #457 Login & Register For · #896

Rating trend

Star average over time · dips mark rough releases

4.9Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

2.3Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

16

releases in the last 12 months

2mo ago

latest release · v1.8.70

256

tagged releases on record

Recent releases

1.8.70 · 2mo ago1.8.69 · 2mo ago1.8.68 · 2mo ago1.8.66 · 2mo ago1.8.65 · 2mo ago1.8.64 · 2mo ago1.8.63 · 3mo ago1.8.62 · 5mo ago1.8.61 · 6mo ago1.8.60 · 7mo ago1.8.59 · 8mo ago1.8.58 · 10mo ago1.8.57 · 10mo ago1.8.56 · 10mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 82% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.8 82%
v1.7 12%
Older / other versions 6.9%

Estimated active installs

The public count shows “900+”. Our estimate pins where the real number sits.

tracked estimate
900–1K ≈970

Refined from the date this plugin crossed into its current band.

Install history · since 2021-02-21 · 1,425 observations

900Installs · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
1.8.72
Last updated
8d ago
Added
2020-08-06 · 6 yrs old
Requires WP
5.9
Tested up to
7.0.4
Requires PHP

Reviewer account pattern

from wp.org reviewer profiles

16 of the last 27 four- and five-star reviews came from accounts created within a month of posting the review, and 7 of those landed between 2023-08-23 and 2023-09-06.

Registering a wp.org account just to leave a review is common and often entirely legitimate. The share here is unusually high for the sample, so it's worth keeping in mind while reading the reviews.

Recent reviews

All reviews on wp.org ↗
  1. v1988
    2mo ago

    Big mistake buying this plugin. Paid for pro, support went silent. It’s full of bugs and completely unusable. No response from anyone. Total scam. do not pay for pro version guys This topic was modified 2 weeks, 2 days ago by v1988. Reason: total scam

    Read on wp.org ↗
  2. webmaster1105
    10mo ago

    Awesome plugin. I was able to set it up in a few minutes. If you face any issues, you can chat with author from the plugin setting page of your website itself. With Firebase, I got a free limit of 1000 sms per day. So it’s working great for my website now. Looking forward to buy the paid version in future, jsut to support the author.

    Read on wp.org ↗
  3. Sajjad Nazari
    10mo ago

    It was a grate experience for to using good plugin and their support team was good at it.

    Read on wp.org ↗
  4. pixer
    11mo ago

    1. Shows ads. 2. Shows developers real face in my admin dashboard 😐 3. The core basic functionality (connection to KaveNegar SMS service provider) is locked behind Pro version. Almost all SMS gateways are locked behind a paywall. 4. “Enable usage tracking” option checked by default (without users knowladge). This topic was modified 9 months ago by pixer.

    Read on wp.org ↗
  5. badraldossari
    1.1y ago

    The plugin is great, but there are some compatibility issues with the WoodMart theme.Also, when the “Abandoned Cart” feature is enabled, it causes problems. I hope these issues will be fixed in future updates. Additionally, I suggest adding more login form templates instead of relying on just one.

    Read on wp.org ↗
  6. ludmilasv
    1.2y ago

    Thanks a lot, your plugin saved me so much time for development!One small bug: the shortcode renders 5 forms, and all of them have a field with the same id. So, I have a warning in console: Found 5 elements with non-unique id #security.

    Read on wp.org ↗
  7. nikhiljdhv
    1.3y ago

    So I recently migrated one of my clients website from Shopify to Woo and they needed a otp based login. All other options seemed a little too much and I wanted something very straightforward. Add the phone number, get an otp and login. These guys do just that. No fuss! And the best part is, the customer support was spot on. I had trouble syncing the old Shopify customers with this app but the support team guided me very efficiently and got the issue resolved in no time. I highly recommend this plugin and I’m soon going to opt for the paid version.

    Read on wp.org ↗
  8. ehsan
    1.5y ago

    support india and Saudi Arabia and another country and the pro version of this plugin is much cheaper than other plugins

    Read on wp.org ↗

Known vulnerabilities

via Wordfence Intelligence

15 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-06 CVE-2026-65570 Authentication Bypass Using an Alternate Path or Channel Affects <= 1.8.70 Patched in 1.8.71
  2. 2026-05-28 CVE-2026-3655 Improper Authentication Affects 1.8.50 - 1.8.60 Patched in 1.8.61
  3. 2025-08-14 CVE-2025-8342 Missing Authorization Affects <= 1.8.47 Patched in 1.8.48
  4. 2024-09-14 CVE-2024-6482 Improper Privilege Management Affects <= 1.7.49 Patched in 1.7.50
  5. 2024-06-28 CVE-2024-37429 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.7.35 Patched in 1.7.36
  6. 2024-06-18 CVE-2024-6125 Weak Password Recovery Mechanism for Forgotten Password Affects <= 1.7.34 Patched in 1.7.35
  7. 2024-05-28 CVE-2024-5150 Authentication Bypass Using an Alternate Path or Channel Affects <= 1.7.26 Patched in 1.7.27
  8. 2024-05-03 CVE-2024-34371 Missing Authorization Affects <= 1.7.18 Patched in 1.7.20
  9. 2024-04-22 CVE-2024-32832 Missing Authorization Affects <= 1.6.93 Patched in 1.6.94
  10. 2024-04-15 CVE-2024-32507 Authorization Bypass Through User-Controlled Key Affects <= 1.7.16 Patched in 1.7.17
  11. 2024-04-10 CVE-2024-31424 Cross-Site Request Forgery (CSRF) Affects <= 1.6.93 Patched in 1.6.94
  12. 2023-09-12 CVE-2023-4916 Cross-Site Request Forgery (CSRF) Affects <= 1.5.6 Patched in 1.5.7
  13. 2023-01-12 CVE-2023-23492 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.4.2 Patched in 1.4.2
  14. 2022-07-05 CVE-2022-0598 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.3.7 Patched in 1.3.8
  15. 2022-02-16 CVE-2022-0593 External Control of File Name or Path Affects < 1.3.7 Patched in 1.3.7

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 13 languages, 1 at 90% or more

Chinese (Taiwan) 93%
Arabic 78%
Persian 78%
Turkish 78%
Russian 63%
German 52%
Spanish (Spain) 27%
Ukrainian 23%
Spanish (Colombia) 22%
Spanish (Ecuador) 22%
Spanish (Mexico) 22%
Spanish (Venezuela) 22%
German (Formal) 1%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-04-29 1K+ → 900+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for OTP Login With Phone Number, OTP Verification into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/login-with-phone-number" width="480" height="300" style="border:0" loading="lazy" title="OTP Login With Phone Number, OTP Verification — Plugin Pulse"></iframe>
Preview card ↗

OTP Login With Phone Number, OTP Verification: 900+ active installs, 4.9★ (81 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/login-with-phone-number