plugin-icon

ArgentWolf Email Verification

作者:Alan Johnson·
Keeps newly self-registered WordPress accounts inactive until the owner verifies the registered email address.
版本
1.0.0
最后更新
Aug 5, 2026

ArgentWolf Email Verification provides local, self-hosted email verification for newly registered WordPress users.

The plugin does not call an external email-verification API. It creates a one-time verification link locally and sends the message through WordPress wp_mail() and the site’s configured mail transport.

Core behavior:

  • Existing accounts are preserved as verified when the plugin is first activated.
  • Accounts created deliberately by a logged-in administrator or WP-CLI are automatically verified.
  • Other newly registered accounts are marked Pending.
  • Pending users cannot authenticate with a normal password or an Application Password.
  • WordPress’s normal new-user email is suppressed while an account is pending.
  • Users can request another verification message without disclosing whether an account exists.
  • Administrators can view verification status, resend verification, or verify an account manually.
  • Pending accounts can be removed automatically after a configurable retention period.
  • Administrators and pending users who own WordPress content are not removed by cleanup.
  • Ordinary wp_mail() messages to pending account addresses can be suppressed.
  • Mixed-recipient messages continue to verified users and outside addresses after pending addresses are removed.
  • Verification status is available to compatible plugins through a public API.

The plugin does not prove that a mailbox exists without sending a message, replace SMTP service, process bounces, or guarantee inbox delivery.

Settings

The settings page is under Settings > Email Verification.

Delete pending accounts after

Default: seven days. Enter zero to disable automatic deletion. Valid range: zero to 365 days.

Other outbound email

Enabled by default. Normal wp_mail() messages to pending account addresses are suppressed. This cannot intercept another plugin that bypasses wp_mail() and sends through its own transport or remote API.

Cleanup status

Displays the pending-account count and the next scheduled cleanup. Administrators can also run cleanup manually.

Privacy

The plugin stores verification status and limited verification-workflow metadata in WordPress user metadata.

Raw verification tokens are not stored. The plugin stores a keyed token hash, expiration time, message-request time, and limited registration-workflow state.

The plugin includes suggested privacy-policy text and WordPress personal-data exporter and eraser integration. Token and message metadata can be erased, but verification status is retained because removing it could alter account-access security.

Security

  • Verification tokens contain 256 bits of cryptographically secure randomness.
  • Only an HMAC-SHA256 token hash is stored.
  • Verification links expire after 48 hours by default.
  • Requesting a new link invalidates the previous link.
  • Public resend requests are throttled.
  • Public responses do not disclose whether an account exists.
  • Administrators are protected from accidental lockout.
  • Accounts without an explicit Pending marker are treated as verified to preserve established access during upgrades or temporary interruptions.

Developer API

Canonical filters and actions use the argentwolf_email_verification_ prefix. Selected legacy wrav_ev_* aliases remain for compatibility.

Important filters:

  • argentwolf_email_verification_link_lifetime
  • argentwolf_email_verification_resend_cooldown
  • argentwolf_email_verification_cleanup_batch_size
  • argentwolf_email_verification_auto_verify_new_user
  • argentwolf_email_verification_email_subject
  • argentwolf_email_verification_email_message
  • argentwolf_email_verification_after_verification_url
  • argentwolf_email_verification_should_delete_pending_user

Important actions:

  • argentwolf_email_verification_user_verified
  • argentwolf_email_verification_pending_user_deleted
  • argentwolf_email_verification_pending_user_cleanup_skipped
  • argentwolf_email_verification_mail_suppressed
  • argentwolf_email_verification_error

The error action receives a stable error code and a context array. It lets a logging or monitoring integration record operational failures without the plugin writing directly to the PHP error log.

免费基于付费套餐
通过安装,您同意 WordPress.com 服务条款第三方插件条款
目前已测试版本
WordPress 7.0.2
这个插件是可用的下载,适用于您的站点。