Priskribo
LocalForm is a form builder for WordPress. Add your questions, drag them into order, pick your colors, and hit publish. Your form gets its own page and a link you can share right away – no page building, no shortcode wrangling, no fighting your theme’s CSS.
The name says what it does: every response stays local, on your own site, under your own domain and branding. Nothing is sent to a third-party form service, so you stay in control of your visitors’ data. And there is nothing to set up before your first form is live – install, activate, and start building.
If you have been collecting answers with a cloud form service such as Google Forms or Microsoft Forms, LocalForm covers the same ground – write your questions, share a link, read the results back as a summary – except the form lives on your own domain and the answers never leave your site.
What you can build
- Contact forms. Name, email and a message, with an email in your inbox every time someone writes in. Start from the template and publish in a minute.
- Surveys and feedback forms. Ask your questions and read the results back as a summary with counts and charts, right in the admin.
- Sign-ups and intake forms. Collect the details you need and get an email every time someone submits.
- Quizzes and knowledge checks. Give the questions an answer key, set a pass mark, and every response is marked for you – with the score, the right answers and your own explanation shown the moment someone submits.
- Event registrations. Set the event date, time, location, organizer and price, cap the number of registrations, open and close the form on a schedule, and send every registrant a confirmation email.
Why LocalForm?
- Simple to use. A distraction-free builder: add questions, drag to reorder, pick your colors, publish.
- Share a link. Every form gets its own page with a URL you choose – or drop it into an existing page with a shortcode or block.
- Your data stays yours. Responses are stored on your own site and can be downloaded as an Excel or CSV file whenever you like.
- No surprises. No account, no license key, no trial period, and no limit on the number of forms or submissions.
- Nothing calls home. No analytics, no telemetry, and fonts are served from your own domain – so building a form never sends your visitors anywhere else.
- Works with AI assistants. Built-in MCP support lets an assistant like Claude build and edit your forms for you, on your own site – see below.
Features
Building forms
- Drag-and-drop builder in the WordPress admin – no code, no page builder needed.
- Starter templates for a contact form, a feedback survey, an event registration, an RSVP and a quiz – they open the builder with the questions already written, and every one of them stays editable. Nothing is saved until you hit Save.
- Already built the form somewhere else? Forms > Import brings it across from Contact Form 7, WPForms or Google Forms – the questions, their options and which ones are required. Contact Form 7 and WPForms forms are read straight off your own site, and neither plugin has to still be active. A Google Form comes across from its share link. Every import arrives as a draft with a report saying what could not be brought over, so you read it through before anything goes live.
- Question types: text, long text, email, phone, number, dropdown, single choice, checkboxes, consent, date, date range and rating. Any of them can be marked as part of a quiz where marking makes sense – see Quizzes below.
- A consent question renders as a single tick box with your own wording beside it – put a link to your privacy policy in it and require it before the form can be sent.
- Add section titles, text and images between questions to explain or break up a long form.
- Multi-step forms, with no extra setup: add a section title and everything after it becomes the next step, with a progress bar, a step counter and Back and Next buttons. A long registration or intake form asks a few questions at a time instead of showing a wall of them.
- Choose the colors and the font; pick from seven bundled font families.
- Organize your forms with tags and filter the forms list by them.
- Light mode hides the webhook URL, the redirect URL and the custom fields on a form’s Settings tab, for a builder that shows only the questions – per form, or as the default for new forms.
Sharing your form
- Every form gets its own page at a web address you choose.
- Place a form inside an existing page or post with the
[localform id="123"]shortcode or the LocalForm block, which shows the real form while you edit. - A QR Code block puts a scannable link to a form on any page – for a flyer, a poster or a slide.
- Share dialog in the builder: copy the link, copy the embed code, or download a QR code for print and posters.
- Forms are shown full-screen by default, or in your theme’s normal page layout if you prefer.
Collecting responses
- Visitors get instant validation and a thank-you message you can write yourself, without the page reloading.
- Get an email whenever someone submits, and send the person who submitted a confirmation email you can customize with their answers.
- Attach a calendar invitation to that confirmation email, so a registrant adds the event to Outlook, Google Calendar or Apple Calendar with one tap on their phone instead of retyping the date. It carries the event’s date, time, location and organizer, and an event without a time is added as an all-day one.
- Cap the number of registrations and set an opening and closing date and time, with your own message shown when the form is full or closed.
- Stop taking responses whenever you like: an Accepting responses switch on the form, and a Stop accepting link on the forms list, close a form on the spot without touching a date or deleting anything.
- See whether your notification emails are actually going out. Every message LocalForm sends is recorded – who it went to, what it was about, whether the mailer took it – with a Send test email button beside it, and a warning on your own LocalForm screens the first time one fails.
- Built-in spam protection: a hidden trap field that differs per site and rotates daily, a check that the submission came from a real browser, rate limiting, blocking for repeat bot attempts, and duplicate-submission checks. None of it asks a visitor to prove anything.
- A content filter for the spam a real browser sends: a link limit, and blocklists for words, email domains and IP addresses. It reads what actually arrived, which is what catches the junk that passes every invisible check.
- An optional challenge – Cloudflare Turnstile or hCaptcha – for a site under sustained attack. Off by default, and best set to appear only for a visitor whose own device has already tripped the automated checks, so an ordinary visitor never meets one and no third-party script is loaded on their page.
- A blocked-attempts log: what was turned away, from which form and why, with a seven-day summary. It is what turns the settings above from guesswork into tuning – and it is how you notice protection catching a real person. No IP addresses are stored; each entry carries a one-way hash instead.
- Per-form spam settings, for the internal form a whole office fills in from one shared address and the one public form being hammered. Every form else follows the site.
- Decide who may fill a form in: anyone with the link, anyone signed in to your site, or only the roles you pick. Everyone else gets your own message instead of the form, with a sign-in link if that is all they are missing, and the refusal is enforced on the server rather than merely hidden in the page. Every response then records which account left it, shown in the responses list, in your exports and on the printout – so an internal report, a staff form or a training quiz becomes a record with a name on it rather than an anonymous one.
Quizzes
- Turn any form into a marked one: tick the correct options, or type the answers you accept, and LocalForm scores every response.
- Works on single choice, dropdown, checkbox, short text and number questions. Give the harder question more points; leave a question without an answer key and it is asked but not marked.
- Set a pass mark and every response reads Passed or Not passed. Leave it empty to report a score and let nobody fail.
- The person answering can be shown their score, which questions they got right, the correct answer where they did not, and a sentence of explanation you wrote – so a test doubles as the lesson.
- The score goes in the confirmation email, in the responses list, in every export, and on the printout – which is what makes a response usable as a training record.
- The Responses summary tells you how the group did and, question by question, how many got it right: the one everybody missed is highlighted.
- Scores are worked out from the answer key each time they are read, never stored. Correct a key you got wrong and every response you have already collected is marked again – and switching grading on for the first time scores the answers a form collected before it was a quiz.
Reading and keeping your results
- A count in the admin menu of the responses that arrived since you last looked, per form on the forms list – the same badge WordPress puts on Comments, so a published form tells you it is being answered.
- Browse every submission per form in the admin, a page at a time, with a date range and a search box to narrow the list down.
- Summary view per question: counts and bar charts for choice questions, lowest/average/highest for numbers, per-day counts for dates, and the most recent answers for open questions.
- Download responses as Excel (XLSX) or CSV – comma or semicolon separated, so Excel in Dutch, Belgian or German settings opens it in columns rather than one long line. Whatever the date range and search box are showing is what gets downloaded.
- An Excel export with a Summary sheet alongside the responses: per-question counts, averages and percentages, ready to pivot or paste into a report.
- Print any single response, or save it as a PDF, from the Print link beside it.
- Export from the command line with
wp localform export, or read responses over the REST API – both with the same date and search filters. - Answers to a data request are handled by WordPress’s own Tools > Export Personal Data and Tools > Erase Personal Data, which now include LocalForm responses.
- Let a colleague read the responses without making them an administrator: two permissions of LocalForm’s own, granted per role, so the coordinator sees the registrations and nothing else.
- Back up every form, submission and setting to a single file, and restore it here or on another site.
Building forms with an AI assistant (MCP)
LocalForm speaks MCP – the Model Context Protocol – so an AI assistant such as Claude can build your forms for you. Ask for “a registration form for the summer school on 12 and 13 August, with a student rate”, and the form is created on your site, with its page, ready for you to review.
- Three WordPress Abilities are registered – list forms, read a form, and create or update one – and become MCP tools as soon as the MCP Adapter plugin is installed.
- It is your site doing the work. The assistant connects to WordPress; LocalForm sends nothing out, and no form or response is uploaded anywhere.
- Everything goes through the same validation as the builder, so an assistant cannot save something you could not have built by hand, and reconfiguring a form never touches the responses already collected.
- Sign in with an Application Password and the usual WordPress permissions apply: only an administrator can read or change a form.
LocalForm Pro
Everything described above is in the free plugin and stays that way – none of it is a trial, a teaser or a limited version. LocalForm Pro is a separate paid add-on for the sites that need more, sold at localform.dev and installed alongside the free plugin. If none of the following applies to you, you are not missing anything.
- Payments. Charge for a registration and take the money at submit, through Stripe, Mollie or your own WooCommerce shop.
- Build with AI. Describe the form you want and watch it built on your site, from inside the admin.
- Registering several people. One person books for their whole party, and the maximum counts people rather than bookings.
- Waiting list. A full form keeps taking registrations and tells people where they stand, so a late cancellation gets filled.
- Mailing lists. Add the person who filled in your form to a list at Flexmail, Brevo, MailerLite or Mailchimp, gated on a consent question of your own.
- Conditional fields. Show a question only when another answer matches a rule.
- More event detail. Several dates per event, each with its own times and count, and a labelled price list.
- More question types. File upload, a Yes/No switch, and a one-click block of invoice questions.
- Webhook and field controls. Global webhook fields, field name rules, reusable field templates, and prefill from URL parameters.
- Attendance sheets and scheduled exports. A tick-off list per event date, and a form’s responses emailed out daily, weekly or monthly.
- Elementor widgets. A form on any Elementor page, or a list of upcoming events with a register link per date.
The Pro add-on is not hosted on WordPress.org; it is documented at docs.localform.dev.
LocalForm is fully translatable, with translations contributed through translate.wordpress.org.
External services
This plugin does not connect to any external service on its own. It contains no analytics, telemetry, license checks or remotely hosted assets.
The MCP support described above adds no outbound request either: it registers WordPress Abilities, which an AI client calls by connecting to this site over the REST API, authenticated as a WordPress user. The plugin never contacts an AI provider, and holds no API key for one.
Importing …
Ekrankopioj
Blocks
This plugin provides 2 blocks.
- LocalForm Embed one of your LocalForm forms – a contact form, survey or event registration.
- LocalForm QR Code A scannable QR code linking to one of your forms – for a printed flyer, a poster or a slide.
Instalo
- In your WordPress admin, go to Plugins > Add New, search for “LocalForm”, and click Install Now. Or upload the plugin files to
/wp-content/plugins/localform/. - Activate the plugin through the ‘Plugins’ screen in WordPress.
- Go to ‘Forms’ in the admin menu and click ‘Add form’ to build your first one.
- Publish the form and use the Share button to copy its link.
OD
-
Can I bring my forms over from another plugin?
-
Yes. Forms > Import reads the forms Contact Form 7 and WPForms have on your site – neither plugin needs to still be active, since their forms stay in the database after they are switched off – and rebuilds a Google Form from its share link. The questions come across; the responses the old form already collected stay where they are, so export them from the old plugin if you need to keep them.
Every imported form arrives as a draft, with a report listing anything that could not be brought across – a file upload question, a Google Forms grid – so you can add it by hand before publishing.
-
Do I need an account or a license key?
-
No. There is no sign-up, no license key and no trial. Install the plugin and everything described here works straight away, with no limit on the number of forms or submissions.
-
Is there a paid version, and what does it add?
-
Yes – LocalForm Pro, a separate add-on sold at localform.dev. Nothing in the free plugin is limited, gated or timed to push you towards it: no submission cap, no form cap, no trial and no license key, and that is not going to change. Pro is for sites that need things the free plugin deliberately does not do – taking payment for a registration through Stripe, Mollie or a WooCommerce shop the site already runs, adding whoever ticked your newsletter box to Flexmail, Brevo, MailerLite or Mailchimp, showing a question only when another answer matches a rule, several dates or several price tiers on one event, file uploads, a “Build with AI” panel inside the admin, Elementor widgets, and a set of webhook and field-naming controls for wiring forms into another system. The full list is under “LocalForm Pro” in the description above, and the documentation is at docs.localform.dev.
-
Does the plugin nag me?
-
Once, and only if you want it to. After your site has collected 25 responses, LocalForm asks on its own screens whether you would leave a review – with “Not now” and “Don’t ask again” next to it, both remembered. Untick “Ask for a review on WordPress.org” under Settings > General and it never asks. Nothing else in the plugin interrupts you, and nothing is reported back to us either way.
-
Does LocalForm put a link to itself on my site?
-
Not unless you ask it to. There is a “Credit LocalForm under my forms” tick box under Settings > General, off unless you switch it on, which adds a small “Powered by LocalForm” line below your forms. Leave it alone and your visitors never see our name anywhere. If you do switch it on, the link carries nothing about your site and nobody who follows it is reported back to you or to us.
-
Can I use this instead of a cloud form service?
-
That is what it is built for. If you are used to Google Forms, Microsoft Forms or a similar service, you will recognise the way LocalForm works: add your questions, publish, share the link, and read the answers back as a summary. The differences are that the form sits on your own domain and carries your own branding, the responses are stored on your site rather than in someone else’s account, and your visitors are not sent to a third-party page to answer. LocalForm is not affiliated with, or endorsed by, any of those services.
-
Can it add people to my Mailchimp or Brevo list?
-
Yes, with LocalForm Pro – Flexmail, Brevo, MailerLite and Mailchimp are all supported. You connect the service once, point a form at one of your lists, and name the tick box on the form that has to be ticked first: consent is a question your visitor answers, not a setting you switch on for them. Somebody who did not tick it is not subscribed, and somebody who unsubscribed from your list earlier is not quietly put back on it.
The free plugin sends nothing anywhere on its own. If you want to wire responses into a mailing list yourself, the free plugin’s webhook will post every submission to an automation tool such as Zapier, Make, n8n or Power Automate, and you can add the subscriber from there.
-
Can I split a long form over several steps?
-
Yes, and there is nothing to switch on. Add a section title where you want a break, and every question after it becomes the next step: the form then shows one step at a time, with a progress bar, a “Step 2 of 4” counter and Back and Next buttons. A form with no section titles stays a single page. Answers are only sent when the last step is submitted.
-
Can I send registrants a calendar invitation?
-
Yes. Give the form an event date under Settings > Event, then tick “Attach a calendar invitation (.ics)” under Email Notifications. Every registrant’s confirmation email arrives with a calendar file holding the date, time, location and organizer, which Outlook, Google Calendar, Apple Calendar and the rest add with a tap. A form without an event date sends the confirmation as before, with nothing attached.
-
Can I build a poll or a quiz?
-
Both. For a poll, a single Single Choice or Checkbox question works well, and the Responses summary gives you counts and a bar chart per option without any extra setup. For a quiz, switch on Quiz under the form’s Settings and give the questions an answer key: tick the correct options, or type the answers you accept. Every response is then scored, with your own points per question and an optional pass mark, and the person answering can be shown their score, which questions they got right, the correct answer where they did not, and a sentence of explanation you wrote. Single choice, dropdown, checkbox, short text and number questions can all be marked; leave a question without an answer key and it is asked but not scored.
-
Where do my responses go?
-
They are saved on your own site, in your own WordPress database, and only you can see them. LocalForm does not send them to any form service, and there is no dashboard elsewhere holding a copy.
-
Does LocalForm help with GDPR?
-
Keeping responses on your own server, under your own hosting agreement, is a real advantage for data residency and minimisation compared with routing them through a third-party form service. When someone asks for a copy of their data or asks you to delete it, WordPress’s own Tools > Export Personal Data and Tools > Erase Personal Data now cover LocalForm responses: enter the email address and every response they left, across every form, is included. For the consent side there is a Consent question type: one tick box, your own wording next to it, a link to your privacy policy if you want one, and the answer stored with the response so you can show what was agreed to and when. That said, LocalForm cannot certify your site as “GDPR compliant” by itself – that still depends on things you configure yourself, such as what you ask for, how long you keep it (see “Keep my data when the plugin is deleted” under Settings > Data), your own privacy policy, and any consent you need before collecting personal data. There is no telemetry or third-party call for a submission to leak through in the first place.
-
Do I have to start from a blank form?
-
No. The Forms screen has a “Start from a template” row with a contact form, a feedback survey, an event registration and an RSVP. Picking one opens the builder with the questions already written – rename them, reorder them, delete the ones you do not want. Nothing is written to your site until you press Save, and a saved form keeps no link to the template it started from.
-
How do people find my form?
-
Every form gets its own page with a web address you choose – just share that link, by email, on social media, or as the QR code you can download from the Share button. You can also place the form inside a page or post you already have.
-
Can I put a form in an existing page?
-
Yes. Add the LocalForm block in the block editor – it renders the real form on the canvas, so you can see how it sits in the page before publishing – or paste the
[localform id="123"]shortcode. The form’s own page keeps working at the same time. -
Do I get an email when someone fills in my form?
-
Yes. Each form can email you on every submission, and can also send the person who submitted a confirmation email. You can write that message yourself and drop their answers into it – for example the form title, the event date, or any question you asked.
-
Can I stop taking registrations after a certain number, or on a certain date?
-
Yes. Set a maximum number of registrations and/or an opening and closing date and time per form. Once the form is full or closed, visitors see a message you write instead of the form. The maximum requires responses to be saved in WordPress.
-
Can I limit a form to certain people?
-
Yes. Under the form’s Settings > Access, choose who can fill it in: anyone with the link (the default), anyone signed in to your site, or only the roles you tick. Someone who is not allowed sees the form’s title and a message you can write yourself – plus a sign-in button if being signed out is all that is wrong – and a submission from them is refused by the server, not just hidden in the page. Every response then records which WordPress account left it, and a “Submitted by” column appears in the responses list, in your exports and on the printout, which is what makes a staff form or a training quiz usable as a record.
Anyone who can manage forms is always let through, so you can preview a restricted form without keeping a test account – with a notice above it reminding you that everybody else is being turned away.
Limiting a form to particular people rather than roles is not built in; a membership plugin can do it through the
localform_user_may_submitfilter. -
Will the form match my site’s design?
-
You choose the colors and font for each form, and forms are shown on a clean full-screen page by default so nothing in your theme gets in the way. If you would rather the form sit in your theme’s normal page layout, there is a per-form setting for that.
-
How do you stop spam submissions?
-
In layers, and without asking your visitors to prove anything. A hidden trap field real visitors never see; a check that the submission came from a browser that actually opened the form, and did not fill it in in milliseconds; a content filter that reads what arrived and rejects a wall of links, a blocklisted word or a throwaway email domain; a cap on how often one address may submit; and a block on accidental duplicates. Everything is under Forms > Settings > Security, and the Blocked attempts tab there shows what has been turned away and why, so you can tune it from what is actually happening rather than by guessing.
If a site is being hit hard enough that none of that is enough, you can switch on a challenge (Cloudflare Turnstile or hCaptcha) – and set it to appear only for a visitor whose own device has already tripped the automated checks, so nobody else ever sees one. It is off until you configure it.
A form can also have its own settings instead of the site’s, which is what you want for an internal form a whole office fills in from one shared IP address.
-
Can I get my responses into Excel?
-
Yes. The Responses screen for each form has an Export button, with a choice of Excel (XLSX) or CSV. If your Excel is set to Dutch, Belgian, German or another language where the decimal mark is a comma, pick the semicolon-separated CSV and it will open in proper columns straight away.
You can also export part of a form’s responses rather than all of them: set a date range or type in the search box, check that the list on screen is what you want, and the download matches it. There is no cap on how many responses an export can hold.
-
Can I move my forms to another site?
-
Yes. Under Forms > Settings > Data, “Download backup” gives you a single file with every form, its submissions and your settings. Upload that file on any other site running LocalForm to bring everything across. If a form already exists there, you choose whether to keep it or replace it with the backed-up one – so restoring the same file twice never duplicates your responses. Webhook logs are not included in the backup.
-
What happens to my forms if I delete the plugin?
-
Deactivating LocalForm never touches your data. Deleting it removes everything by default – your forms, responses and settings. If you want them to survive, turn on “Keep my data when the plugin is deleted” under Forms > Settings > Data before you delete, or download a backup first.
-
Can I send submissions to another tool?
-
Yes. Enter a web address (a webhook) on the form, or as a site-wide default under Forms > Settings > Webhooks, and each submission is sent there as it comes in – handy for connecting to a CRM, a spreadsheet, or an automation tool. Requests are signed with a secret key so the receiving end can confirm they came from you, are retried if the other side is temporarily down, and the last 30 days of deliveries are logged so you can check what was sent. If you would rather not store responses in WordPress at all, you can switch a form to send them onward only.
-
Can I send submissions to Power Automate, Make or Zapier?
-
Yes. Any of them accepts an incoming webhook – paste the URL into the form (or set it site-wide under Forms > Settings > Webhooks) and each submission is POSTed as JSON as it arrives. With Power Automate, use the “When an HTTP request is received” trigger and the submitted answers, form title, event details and custom fields arrive as a structured payload you can map straight into SharePoint, Dataverse or an approval flow.
-
Can an AI assistant build my forms?
-
Yes, and it is built in. LocalForm registers three WordPress Abilities – list forms, read a form, create or update a form – which become MCP tools once you install the MCP Adapter plugin. Point an assistant such as Claude at your site with an Application Password and you can ask for a form in plain language; it is built here, on your own domain, with its page created for you. The assistant signs in with an administrator’s Application Password, and everything it saves goes through the same validation as the builder – so it cannot create something you could not have built by hand. Reconfiguring a form never deletes the responses it has already collected.
The premium add-on, LocalForm Pro, adds the other half of this: a “Build with AI” panel inside the WordPress admin that does the same thing without an outside assistant, using whichever AI provider your site is already connected to.
-
Does the AI support send my forms to an AI company?
-
Not by itself. The free plugin makes no outbound request of any kind – an MCP assistant connects to your site, the way your browser does, and the abilities only read and write your own database. Whatever you type into that assistant goes to whoever you are using it with, exactly as it does when you chat with it about anything else; that is between you and them, and LocalForm is not in the middle of it.
-
Can I send submissions on to another system?
-
Yes. Every form can post each submission to a web address of your choice – a webhook – which is how you plug LocalForm into your own system or into an automation tool like Zapier, Make or Power Automate. Requests are signed and retried automatically if the receiving end is down, with a log of the last 30 days so you can see what went out, and a form can skip saving submissions entirely and only send them onward. There is also a REST API for a form’s field structure, for building a custom renderer or syncing form definitions into another system, authenticated with WordPress Application Passwords.
-
Does LocalForm send any data to an external service?
-
Not unless you tell it to. The plugin makes no outbound requests of its own: no analytics, no license checks, no telemetry, and no remotely hosted fonts. It can only ever reach a service you set up yourself – a webhook URL you entered, the Google Form you asked it to import, or a spam-challenge provider whose keys you added. All three are described under External services below, and a site that configures none of them makes no outbound request at all.
-
Where do the fonts come from?
-
The seven font families (Inter, Roboto, Open Sans, Lato, Montserrat, Poppins and Nunito) are included with the plugin and served from your own site, not from Google Fonts or any other network. Picking one never reveals a visitor’s IP address to a third party. All seven are licensed under the SIL Open Font License 1.1; the license text is included at
assets/fonts/OFL.txt.
Pritaksoj
Kontribuantoj k. programistoj
“LocalForm – Form Builder for Contact Forms, Surveys & Event Registration” estas liberkoda programo. La sekvaj homoj kontribuis al la kromprogramo.
KontribuantojTraduki “LocalForm – Form Builder for Contact Forms, Surveys & Event Registration” en vian lingvon.
Ĉu interesita en programado?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Ŝanĝprotokolo
2.7.0
- A form can now count down its remaining places out loud. Tick “Show how many places are left” under Registration Limits and the form prints “12 places left” with the event facts, dropping as registrations arrive. It is off unless you ask for it, because on an event with two hundred seats and three registrations, saying so in public advertises how empty it is – and it counts exactly what your maximum counts, so a form set to count only paid registrations does not take a place off the number for a checkout somebody walked away from.
- Events can now say when they end, and where they are joined. The Event Details panel has an Ends date and time – for a school running over three days, or an evening that finishes at half nine – and an Online link for a meeting or a stream. The end is what the calendar file attached to a confirmation now runs until, instead of the hour it used to assume. The joining link is deliberately not printed on the form page: a meeting link on a public page is a meeting anybody can walk into, so it goes to the people who registered, in their confirmation email and in their calendar entry, where it becomes the location their calendar puts a join button on. Emails can use it as {event_url}, along with {event_when}, {event_time} and {event_location}.
- A form with an event date now describes that event to search engines, in the head of its own page: what it is called, when it runs, where, who is organising it, what it costs and whether it is still open or sold out. This is what lets a registration form be listed as an event rather than as an ordinary page – the facts were always on the page, and until now only a person could read them. It is written on the form’s own page and nowhere else, so a form you embedded in a page of your own is left to that page; unticking “Show event card on form page” switches it off along with the card, because it is the same facts in another format; and the joining link of an online event is never part of it. A price is published only when your currency symbol names one currency for certain – “kr” is three countries’, so it is left out rather than published as the wrong money.
- The paid add-on’s Pro page now also mentions mailing lists, which it has gained: a form there can add the person who filled it in to a list at Flexmail, Brevo, MailerLite or Mailchimp, gated on a consent question on the form itself. Nothing in the free plugin changed to make room for it – as always, no feature here is limited, disabled or timed, and the free plugin still makes no outbound request of its own beyond the webhook URL you type in yourself.
- The paid add-on is now easier to find, without anything in the free plugin being held back to make you look for it. The pointer that used to appear only on the forms list can now also appear on Responses; the Settings page carries a small card at the foot of its section menu saying what Pro adds; and LocalForm’s own screens end with one line in the WordPress footer instead of the usual “Thank you for creating with WordPress”, with the space under the page it needs so it does not sit against whatever the screen ends with. None of it is a notice you have to close, none of it sits next to a setting you cannot use, and nothing on your site is limited, disabled or timed by any of it – every feature you have stays free and unlimited, as before. The forms-list pointer now also waits its turn when the review request is due, so you are never asked two things on one screen, and all of it still disappears the moment Pro is installed or the
localform_show_promotionsfilter says no. - The builder can now show you the form itself. A Preview button in the toolbar, next to the diagram, swaps the questions you are editing for the page a visitor gets – your colours, your font, your logo, the event details band, the step-by-step navigation, and every edit on screen at that moment, since nothing has to be saved first. It is the real front end rather than an impression of it: the same rendering your visitors get, in a frame of its own so the WordPress admin’s own styling cannot repaint it, with a Desktop/Mobile switch for checking the width most people will actually be on. Nothing filled in there is sent or stored. And a form that is closed, full, not open yet or still a draft previews as its questions, with a line above saying what visitors would be seeing instead – because building a form ahead of the day it opens is exactly when you need to look at it.
- Spam protection now reads what was actually submitted, not only where it came from. A new content filter rejects a submission carrying more links than you allow (five by default – a number no honest answer reaches), one containing a word or phrase from your own blocklist, or one mentioning an email domain you have had enough of; addresses are found anywhere in a submission, so a bot that buries its address in the middle of a message is caught too. There is an IP blocklist for the client that keeps coming back, checked before anything else. This is the layer that catches spam sent through a real browser, which passes every invisible check because a real browser genuinely did open your form.
- Every rejection is now written down. Forms > Settings > Security > Blocked attempts lists what was turned away, from which form and why, with a summary of the last seven days. Until now every one of these failed silently: you could not tell whether the protection was doing anything, and – more to the point – you could not tell when it was catching a real visitor whose browser blocks the check. No IP addresses are stored; each entry carries a one-way hash of the sender’s address, so repeat attempts group together on screen without your site keeping anyone’s address. Entries are deleted after 30 days.
- An optional challenge for a site under sustained attack: Cloudflare Turnstile or hCaptcha, off until you enter keys for one. It is best used on the recommended setting, where nobody sees a challenge until their own device has already tripped the automated checks a couple of times – an ordinary visitor never meets one, and their page loads nothing from the provider at all. Solving a challenge resends what was already filled in, so nothing is retyped, and one solved challenge stands for half an hour.
- A form can now have its own spam settings instead of the site’s. Switch it on in the builder’s Spam Protection card for the two forms that never fitted one set of numbers: the internal form a whole office fills in from one shared IP address, where the site-wide rate limit locks out the tenth colleague to try, and the one public form being hammered, where you want a challenge without imposing one on everything else. Switching the override on starts from the site’s current values so you can see what you are taking over.
- Answers now have a maximum length. Nothing stopped one request putting megabytes of text into a single answer, which was then stored, emailed and posted to your webhook again on the way out. Long text accepts 5000 characters, short text 1000, and a question can set its own limit in the builder – useful where an answer has to be short, or honestly needs more room. The limit applies on screen as well as on the server, so somebody typing runs out of room rather than being told off after submitting. Oversized and absurdly nested requests are now turned away before they are even read.
- The minimum fill time – how quickly after a form loads a submission is treated as automated – is now a setting rather than something only a developer could change, under Forms > Settings > Security. Raise it for a long form; set it to 0 to accept any speed while keeping the rest of the browser check.
- Forms you built somewhere else can be brought over instead of typed again. A new Forms > Import screen reads the forms Contact Form 7 and WPForms have on this site – neither plugin needs to still be active, because their forms stay in the database after they are switched off, which is exactly the moment you want them – and rebuilds a Google Form from the share link you paste in. The questions come across with their wording, their type, their options and which ones are required; Contact Form 7 keeps its field names, so a webhook built against the old form goes on receiving the same keys. Everything lands as a draft with a page of its own and a report saying plainly what could not be brought across – a file upload question, a Google Forms grid, a Name field that had to become one question instead of two – so you correct it before anyone can fill it in rather than afterwards. Responses already collected are not touched and do not come across; they stay in the plugin that took them. Importing a Google Form is the only time LocalForm fetches anything from the internet, it only happens when you press the button, only Google’s own form addresses are ever fetched, and pasting the page source instead skips the request altogether.
- Forms and their response counts are now read through WordPress’s object cache. On a site running a persistent cache – Redis, Memcached, or what most managed hosts switch on by default – the query behind every page that shows a form is answered from memory instead of the database, and a form with a capacity limit stops counting its responses afresh on every visit. Sites without one still save the repeated lookups a single page load was making. Nothing is cached across a change: saving a form, deleting one, flipping Accepting responses, or a new response arriving all take effect on the very next page view, as before.
- Getting started is now a guided path rather than an empty screen. Activating the plugin takes you straight to Forms, and its row on the Plugins screen has a “Create a form” link. A site with no forms yet is greeted with the starter templates as the screen itself, instead of an empty six-column table under a collapsed panel you had to find and open. And the first form you save now tells you what to do with it: its public link and its shortcode, each with a copy button, plus a prompt to send yourself a test email while it still matters – a form that emails you on every response is worth checking before the first one arrives, because plenty of hosts send no mail at all and nothing says so until somebody’s answer goes missing. All of it appears once, on this plugin’s own screens.
- Screen readers can now make sense of every question on a form. A question built from several inputs – a set of tick boxes or radio buttons, a star rating, a date range – carried a label pointing at an element that did not exist, so the question itself was never read out: somebody on a screen reader heard the options with nothing saying what was being asked. Those questions now name themselves properly, a date range says which box is the start and which is the end, and a consent tick box is read as the statement you are agreeing to rather than that statement run together with the field’s label. Every field is also tied to its own error message, so a question that comes back rejected is read out with the reason attached instead of leaving the visitor to hunt for it, and a failed submission announces itself as an error rather than as a passing status update. Nothing about how a form looks or behaves otherwise has changed.
- The form editor can now be cut down to the features your site actually uses. Forms > Settings > General > Form Builder lists what the editor is able to show – tags, event details, access, registration limits, per-form spam settings, quiz, email notifications and custom fields – and unticking one takes it out of every form editor on the site. It is for the common case where the person setting the site up is not the person building the forms: a colleague who only ever collects sign-ups should not have to read past a quiz answer key and a webhook payload to find the question they came for. Everything starts ticked, so nothing changes until you decide it should. Hiding is not clearing, exactly as with light mode – a form set up while a feature was on keeps everything it stored and goes on working, a registration cap still applies and a confirmation email still goes out, and ticking the feature again brings its settings back untouched. Switching off the per-form spam settings hides only that override; the site-wide protection under Settings > Security keeps running for every form.
- The Access card in the form builder is drawn as the set of choices it is again. Its role tick boxes were stretched to the full width of the card and bordered like text boxes, with each role’s name set underneath as a small bold caption, and the three access modes above them had lost their layout the same way. Settings cards now leave tick boxes and radio buttons their own size, so any card can hold a choice without restating it.
- The pointer to the paid add-on on the forms list now answers the need the site has actually shown, instead of appearing purely because two forms exist. A site with an event date or a price on a form is told that Pro can take the payment along with the registration; a site with a form long enough that conditional fields would shorten it is told about those. Sites with neither signal see the line they saw before, at the same point they saw it before, so nobody is shown more of this than they were – it is the same one notice, on the same one screen, with the same permanent dismissal, saying something the reader has a reason to care about.
- LocalForm Pro can now be tried for 14 days without a card, and the Pro page says so above the link to the price.
- The launch discount is 70% off the first year, and the offer now says so. It previously read as coming off every renewal for the life of the subscription, which was never how the coupon was meant to work.
- The pointer to the paid add-on now recognises three more things a site has already done, so the one sentence it shows is more often the one worth reading: a form nearly at its maximum is told a waiting list exists, a form with a newsletter tick box on it is told about mailing lists, and somebody who has exported responses by hand three times is told those can be emailed out on a schedule instead. All of it is read off your own forms at the moment the notice is considered – nothing is profiled and nothing is reported anywhere – and it is still the same single notice, on the same two screens, with the same permanent “Don’t show this again”.
- The Pro page now shows where the line between free and paid actually falls, job by job, alongside what the add-on adds – including what the free plugin already does about each one, written to be read rather than to look thin. It also answers the four questions people ask before buying, and the launch offer now says how many days of it are left rather than only the date it closes.
- An import that has to leave a question behind now says whether the add-on happens to have it. A Contact Form 7 or WPForms form with a file upload or a payment field has always been reported honestly as something LocalForm cannot ask for; the report now adds one sentence at the end naming where that question does exist. It is a footnote to the report and nothing else – nothing on the Import screen is disabled, the imported form is finished and usable either way, and questions Pro has no answer for either (a signature, a Google Forms grid) are not mentioned at all.
- You can now credit LocalForm under your forms, if you want to. Settings > General > Credit LocalForm under my forms adds a small “Powered by LocalForm” line below every form, linking to localform.dev. It is off unless you switch it on, nothing about the form changes either way, and the link carries nothing about your site – no identifier, no campaign parameter, and nobody who follows it is reported back to you or to us.
2.6.1
- Fixed: saving a form in the editor looked like it had done nothing. The “Form saved.” notice was there, but WordPress moves every admin notice to just below the first heading on the screen, and the only heading the editor has is the one on the diagram panel – which is hidden until you open the diagram. So the confirmation was moved out of sight, and it turned up later on the diagram instead. The editor now says where its notices belong, and the confirmation appears at the top of the page where you saved.
2.6.0
- Fixed: on a site that had never saved its settings before, the first save of Settings > General > Access recorded the roles you ticked but did not actually grant them. The screen came back looking right, yet the permissions themselves were only written the second time you pressed Save – so a colleague you had just given View responses to could still be turned away from the responses screen. The first save now takes effect like any other.
- The developer reference – every hook and filter LocalForm offers an add-on – is now published at docs.localform.dev under Developer, alongside the REST API and MCP pages. It used to live only in the source repository, which nobody outside the team can open, so the pages that pointed at it were pointing at a file the reader could not reach. Nothing in the plugin changed.
- Forms can be restricted to the people who should be filling them in. A new Access card on the form’s Settings tab offers three choices – anyone with the link, anyone signed in to the site, or only the roles you tick – with your own message for whoever is turned away. Somebody who is merely signed out gets a sign-in button that brings them back to the form; somebody signed in with the wrong role does not, since it would only return them to the same page. The refusal is enforced on the server rather than merely hidden in the page, and the shortcode, the block and the form’s own page are all covered, because the check sits in the same place the closing dates and the capacity limit do. A restricted form is kept out of page caches, so a cache cannot serve it to the wrong person, and its description and event card are held back along with the questions – only the title is shown, so a members-only form does not publish what it is about to everyone with the link. Anyone who can manage forms is let through any restriction, so a form can be previewed without keeping a test account, with a notice above it saying plainly that everybody else is being turned away. The forms list marks restricted forms, and the editor warns you if a form is limited to a role that no longer exists – which would otherwise stop it collecting anything without saying so.
- Responses now record which account left them, whenever somebody was signed in. A “Submitted by” column appears in the responses list, in the Excel and CSV exports and on the printout – but only on a form that actually has one, so nothing changes for a public form, and switching a login gate off later does not hide the names already collected. It is a name to read and nothing more: no permission anywhere is decided by it. The webhook payload carries the account’s ID as
user_id(null when nobody was signed in), Tools > Export Personal Data and Tools > Erase Personal Data find responses by the account as well as by an address written in an answer – which is the only way to reach a response to a form that never asked for one – and an AI assistant connected over MCP can set all three settings, asaccess,access_rolesandaccess_message. - Fixed: the FAQ in this readme still said LocalForm could not do scored or graded quizzes, and sent anyone who wanted one elsewhere. Quiz mode has been in the plugin since it was described three sections further up; the answer was simply never rewritten.
- Fixed: the section menu down the side of a form’s Settings tab highlighted the wrong entry. Custom Fields is hidden while a form is in light mode, and a hidden card measures as sitting above everything on the page, so the menu marked a section nobody could see as the one being read – and left it marked however far you scrolled. Hidden sections are now left out of the menu altogether, the entry you land on at the bottom of the page is the one that lights up, and flipping the light mode switch updates the menu straight away.
- Fixed: the Stop accepting link on the forms list read its parameter from the URL without unslashing it first. Harmless in practice – the value is compared against “1” and the action is nonce-checked – but it is the kind of shortcut that stops being harmless when the code around it changes.
- Roles and permissions. Until now every LocalForm screen required a site administrator, so the colleague who reads the registrations had to be given the run of the whole site to do it. LocalForm now has two permissions of its own – View responses, and Manage forms – and Settings > General > Access gives either to any role. Someone with View responses gets the responses screen in full (filters, summary, exports, printouts) and a read-only forms list to reach it by; they cannot build, delete or configure anything. Managing forms includes viewing responses. They are ordinary WordPress capabilities, so Members, User Role Editor and the like list them too. Nothing changes for existing sites: anyone who could administer the site keeps both.
- The admin menu now carries a count of the responses that arrived since you last looked, the way WordPress counts pending comments, and the forms list marks which form they came in on. Opening a form’s responses clears its share of the count. It is per person rather than per site, and it starts from zero on an existing site: installing this does not report ten years of history as new.
- An Accepting responses switch per form, under Registration Limits and as a Stop accepting link on the forms list. It closes the form on the spot – visitors see the closed message – whatever its opening and closing dates say, and switching it back on picks up where you left off. Nothing already collected is touched. An AI assistant connected over MCP can set it too.
- Email now has a delivery log, the way webhooks always have. Every notification and confirmation LocalForm sends is recorded under Settings > Email > Delivery log with the recipient, the subject and whether the mailer accepted it – and the mailer’s own error when it did not. There is a Send test email button beside it, and the first time a message fails, LocalForm says so on its own screens instead of letting a site that silently drops mail look like a site nobody is registering for. Message bodies are never stored, and entries are deleted after 30 days (adjustable under Settings > Data).
- Quiz mode. Any form can now be marked: switch on Quiz under the form’s Settings, tick the correct option on each question – or type the answers you accept – and every response is scored. Set what each question is worth, a pass mark, and a sentence of explanation to show with the answer. The person who submitted sees their score, which questions they got right, and the correct answer where they did not; you see a Score column in the responses list, score columns in every export and on the printout, and a Quiz results block in the summary that says how the group did and which question everybody got wrong. Scores are worked out from the answer key each time they are read rather than stored, so correcting a key you got wrong re-marks every response you have already collected – and switching grading on for the first time scores the answers a form collected before it was a quiz. There is a Quiz starter template, and an AI assistant connected over MCP can write the whole quiz, answer key included.
- The LocalForm block now shows the real form while you are editing, instead of a grey placeholder that told you nothing about how the form would sit in the page. The form can also be swapped from a Form panel in the sidebar once one is picked, and the block understands wide and full width plus the usual margin and padding controls.
- New QR Code block. Drop a scannable code for any form onto a page – the poster you are laying out, the last slide of a talk, a flyer you print from the browser. Pick the form, set how big the code should be, and optionally print the form’s title underneath. As with the Share button’s QR code, it is drawn on your own site: the form’s address is never sent to an outside QR service.
- LocalForm’s blocks now sit together in a LocalForm category in the block inserter rather than being scattered through Widgets.
- Fixed: the block’s own wording in the editor now follows the site’s language. The strings were prepared for translation but never handed to WordPress, so the block appeared in English whatever the site was set to.
- Settings now opens on General rather than Webhooks. General is where the settings most people came for sit; webhooks are for the handful of sites that wire LocalForm into something else, and they had no reason to be the first thing everybody saw.
- The LocalForm menu now ends with a Documentation entry, which opens the manual at docs.localform.dev in a new tab so you do not lose the screen you were on. Anyone who can read responses gets it, not only administrators. It is an ordinary link and nothing more – nothing is fetched from that site, and no visit to your admin is reported anywhere, unless you click it.
