=== PubForms ===
Contributors: pubtly, steveomics
Tags: forms, contact form, form builder, privacy
Requires at least: 6.3
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.3.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Simple, privacy-friendly forms for WordPress. Build a form with a shortcode or block and keep every submission in your own site.

== Description ==

PubForms lets you build a form in the WordPress admin, drop it into any page with a shortcode or the PubForms block, and read the submissions in your own dashboard.

* **20+ field types**: text, email, paragraph, phone, URL, number, date, time, month, week, dropdown, multiple choice, checkboxes, quiz, file upload, signature, calculation, section heading, HTML, hidden and more
* Build contact forms and other common forms in seconds with ready-made templates
* Every submission is emailed to you and stored safely in your own database
* Read, search, sort and export entries to a spreadsheet (CSV) at any time
* **Conditional logic** — show or hide a field based on how someone answers
* **Field calculations** — total or multiply number fields automatically
* **Style it your way**: pick a look, layout (stacked, grid or flow), spacing, corners, button position and colours in the block sidebar, or set them on the shortcode
* **Anti-spam** you can switch on once for every form: Cloudflare Turnstile, hCaptcha or a built-in question, plus a hidden trap field, rate limiting, a minimum fill time, a link limit and a blocked-words list that work with no CAPTCHA at all
* Every input is validated and sanitised, so forms are safe from injection-style attacks
* Optional multi-page forms and save-&-resume for longer submissions

Everything runs on your own server: no IP addresses or browser details are stored with entries. Nothing is sent to a third-party service unless you turn on Cloudflare Turnstile, hCaptcha or a webhook (see External services below).

== External services ==

PubForms works fully on its own. It contacts an outside service only if you switch one of these features on.

= Cloudflare Turnstile (optional CAPTCHA) =
Used when you choose Cloudflare Turnstile under PubForms > Settings and save your Turnstile keys. A form then loads Cloudflare's script from `https://challenges.cloudflare.com/turnstile/v0/api.js`, and the visitor's browser talks to Cloudflare to complete the check. When the form is submitted, your server sends the visitor's check token and your secret key to `https://challenges.cloudflare.com/turnstile/v0/siteverify` to confirm it. The "Test these keys" button on the Settings screen does the same for one test token. Terms: https://www.cloudflare.com/website-terms/ - Privacy policy: https://www.cloudflare.com/privacypolicy/

= hCaptcha (optional CAPTCHA) =
Used when you choose hCaptcha under PubForms > Settings and save your hCaptcha keys. A form then loads hCaptcha's script from `https://hcaptcha.com/1/api.js`, and the visitor's browser talks to hCaptcha to complete the check. When the form is submitted, your server sends the visitor's check token and your secret key to `https://hcaptcha.com/siteverify` to confirm it. The "Test these keys" button does the same for one test token. Terms: https://www.hcaptcha.com/terms - Privacy policy: https://www.hcaptcha.com/privacy

= Webhooks (optional) =
If you add webhook URLs to a form, each confirmed submission is sent as JSON to those addresses, which you choose. What the receiving service does with it is governed by that service.

The built-in question, trap field, rate limit, minimum fill time, link limit and blocked-words list all run on your own server and contact nothing.

== Installation ==

1. Upload the plugin folder to `/wp-content/plugins/` and activate it.
2. Go to PubForms > Add New, build your form and publish it.
3. Paste the shortcode shown on the form screen into a page, or add the PubForms Form block.
4. Make sure your site can send email (an SMTP plugin is recommended) so notifications arrive.

== Frequently Asked Questions ==

= Where are submissions stored? =
In a table in your WordPress database. They are not sent anywhere else.

= Why are notification emails not arriving? =
WordPress sends mail through your server, which many hosts do not deliver reliably. Use an SMTP or transactional email plugin.

= How is PubForms different? =
It is built around privacy and simplicity: entries live in your own database, no visitor IP address or browser details are stored with them, there is no account or subscription, and spam protection works without any third-party CAPTCHA if you prefer. For rate limiting only, a one-way hash of the visitor's address is kept for an hour and never shown.

= Do I need a CAPTCHA account? =
No. The built-in question, hidden trap field, rate limit, minimum fill time, link limit and blocked-words list need no account. Cloudflare Turnstile and hCaptcha are optional and need their own free keys.

= Can I change how an embedded form looks? =
Yes. Select the PubForms Form block and use the Layout, Form style and Colors panels in the sidebar. The shortcode takes the same options, for example `[pubforms id="123" preset="soft" layout="grid" density="compact" accent="#db2777"]`.

== Screenshots ==

1. The form builder with the template picker and colour-coded field cards.
2. A published form on a page, protected by Cloudflare Turnstile.
3. A dropdown field on a published form.
4. The Entries overview for your forms.

== Upgrade Notice ==

= 0.3.0 =
Adds a site-wide spam-protection setting, block styling options, and write-only secret keys. Review PubForms > Settings after updating: forms that did not choose a CAPTCHA now follow the site-wide setting.

== Changelog ==

= 0.3.0 =
* Template picker: choose a starting template from cards; the fields and settings below update as soon as you pick one
* Modern builder: colour-coded field cards by type, compact rows, tidy options grid
* Modern front-end form styling with an accent colour you can override (`--pubforms-accent`)
* Block and shortcode style options: preset, layout (stacked, grid, flow), spacing, label position, corners, shadow, width, button position, colours
* Site-wide spam protection: choose one method (Cloudflare Turnstile, hCaptcha or a built-in question) for every form; a form can override or opt out
* Built-in question challenge with your own question list, plus a minimum fill time, link limit and blocked-words list
* Turnstile and hCaptcha secret keys are now write-only on the Settings screen, with a "Test these keys" button
* Suggested privacy wording now appears in the WordPress privacy-policy guide
* Assets reload automatically when files change


= 0.2.0 =
* New field types: file upload, phone, date, time, week, month, URL, radio, checkboxes, hidden, section heading, HTML, signature, calculation, quiz (graded)
* Per-field polish: placeholder, default value, help text, column width
* Conditional logic and multi-page forms with a progress bar
* Optional Cloudflare Turnstile / hCaptcha spam protection
* Save & Resume and abandonment capture
* Webhooks for confirmed entries
* Survey/poll/quiz results; CSV export filters; private entry notes; global settings; WordPress privacy tools

= 0.1.0 =
* First version: form builder, shortcode and block, entries with CSV export, email notifications.
