[memb_registration_form]
Description
Renders a full registration form. Two modes are supported:
- Prebuilt templates:
template="basic"ortemplate="full"render zero-config forms. - Custom mode: HTML placed between the shortcode tags becomes the form body.
The form pipeline: hidden for logged-in users; normalizes and sanitizes attributes; generates a honeypot field name and timestamp when enabled; HMAC-signs the critical configuration parameters so the processor can detect tampering; surfaces error/success messages from a prior submission; enqueues CAPTCHA scripts (reCAPTCHA v2/v3 or Cloudflare Turnstile) when enabled.
Administrators see a debug message when a selected template produces no output.
The HTML this shortcode renders comes from a template you can override in your theme. See Shortcode Templates.
Shortcode Examples
[memb_registration_form]
Full template with autologin, tags, and CAPTCHA:
[memb_registration_form template="full" autologin="true" tagids="123" recaptcha_v3="true" success_url="/welcome/"]
Custom HTML body:
[memb_registration_form required_fields="email,first_name,last_name"]
<label>Email</label><input name="email" type="email">
...
[/memb_registration_form]
Shortcode Parameters
template
Prebuilt template name: basic or full. Falls back to basic when
the template file doesn't exist. Ignored when inner content is
present. Default: 'basic'.
required_fields
Comma-separated required field list. Default: 'email,first_name'.
success_url
Redirect URL after successful registration. '~' means the current
page. Default: '~'.
failure_url
Redirect URL on failure. Default: '' (stay on page).
autologin
When truthy, the new user is logged in immediately after registering.
Default: false.
allow_existing
When truthy, registration for an existing email is allowed instead of
erroring. Default: false.
login_existing
When truthy (and allow_existing), an existing user is logged in
rather than blocked. Default: true.
tagids
Comma-separated tag IDs applied to the new user. Default: ''.
honeypot
Enables the honeypot anti-spam field. Default: true.
min_password_length
Minimum password length. Default: 8.
min_password_strength
Minimum password strength (site default used when empty).
Default: ''.
rate_limit_max
Maximum registration attempts per window. Default: 3.
rate_limit_window
Rate limit window in seconds. Default: 300.
recaptcha_v2
Enables reCAPTCHA v2 on the form. Default: false.
recaptcha_v3
Enables reCAPTCHA v3 on the form. Default: false.
turnstile
Enables Cloudflare Turnstile on the form. Default: false.
css_class
CSS class for the form element. Default: ''.
css_id
HTML ID for the form element (auto-generated when empty).
Default: ''.
Shortcode Attributes
| Attribute | Value |
|---|---|
| Conditional | No |
| Nestable | No |
| Accepts formatting | No |
Hooks
On submission: wpal/torii/registration/form/post/pre (filter, POST
data) runs first; wpal/torii/registration/form/fields (filter)
shapes the field list; form/field_synonyms and form/custom_fields
(filter) map and extend submitted data; wpal/torii/provider/email/exists
(filter) decides duplicate-email handling. On success,
wpal/torii/registration/form/completed (action, user ID, POST) fires
and form/redirect (filter) sets the destination; on failure,
form/error (action, error code, POST) fires. When an existing user
logs in instead, form/login_existing (action, user ID, POST) fires.