Docs Product page Dashboard
Docs Content Forms

Forms

v1.4.8

A drag-and-drop form builder with branching multi-step flows, conditional logic, file uploads, a searchable entries inbox and built-in spam protection — all from one WPStack panel, with no external form service.

Included in every plan Updated August 2026

Overview

The Forms module builds anything from a quick contact box to a branching, multi-step intake — and keeps every submission in a searchable inbox.

Build a form by dragging in fields, or switch to Flow mode for a multi-step form that branches on the visitor’s answers. Place it with a shortcode or the Elementor widget, and collect submissions in the Entries inbox and by email.

Forms
New form
3
Forms
128
Entries
1
Flows
2
Simple
TitleTypeItemsEntriesShortcode
Get a quote
#3
FLOW5 steps46[stack_form id="3"]
Website intake
#2
SIMPLE12 fields64[stack_form id="2"]
Contact
#1
SIMPLE5 fields18[stack_form id="1"]
The Forms list — simple and flow forms with their type, item counts, entry counts and shortcodes.

What you can do

  • Build simple forms with a drag-and-drop field list — text, email, phone, dropdowns, files and more
  • Build branching flows on a visual canvas of choice and group nodes
  • Add conditional logic to show or hide any field based on another answer
  • Collect submissions in a searchable Entries inbox with CSV export
  • Email a notification to your team and an optional confirmation to the submitter
  • Keep spam out with a honeypot, rate limiting and an auto Blocked IPs list
Simple or Flow — one shortcodeBoth modes render with the same [stack_form id="…"] shortcode. Flip a form between Simple and Flow at any time from the builder tabs.

Requirements & compatibility

Forms runs on any modern WordPress host with no external service.

RequirementMinimumRecommended
WordPress6.06.5 or newer
PHP7.48.1 or newer
ElementorOptionalFor the drag-in form widget
SMTPOptionalFor reliable notification delivery
Works with any theme & page builderForms inherit your theme’s styling and work behind page caching. Place them with the shortcode or the native Elementor widget.

Installation & activation

Forms ships inside WPStack — switch it on per site from the modules panel.

1

Open the WPStack modules panel

In your WordPress admin, go to WPStack → Modules and find Forms.

2

Activate Forms

Flip the Forms toggle to on. A new Forms item appears in the WPStack menu.

3

Create a form

Open WPStack → Forms → New form, name it, and add fields (or switch to Flow mode).

4

Set notifications

Under the form’s Notifications and After submit panels, set the notify email, success message and any confirmation.

5

Place the shortcode

Copy the form’s [stack_form id="…"] shortcode onto any page, or add the Elementor widget.

The field builder

Simple forms are a drag-and-drop list of fields. Click a field to edit it in a popover, drag its edge to set the width, and drag the handle to reorder.

Website intake
Shortcode: [stack_form id="2"]
Simple formFlow (steps & branches)
Fields
NameText50%
EmailEmail50%
PhonePhone50%
ServiceDropdown100%
Reference websitesText100%CONDITIONAL
Do you need hosting?Checkboxes100%CONDITIONAL
Upload a briefFile100%
Text Add Field
The Simple form builder — each field shows its type, width % and (if set) a Conditional badge, with icon Duplicate / Delete controls.

Field types

  • Text, Email, Phone, Textarea, Number
  • Dropdown, Radio, Checkboxes, Single checkbox
  • Date, File upload (with allowed extensions), Hidden
  • Section break to group and title parts of the form

Editing a field

Click a field to open its editor popover — a floating panel that never resizes the tile or pushes the other fields. Set the Field Name (the visible label), an optional Placeholder (a toggle shown only for text-style fields), the Field Key used in entries and emails, the Width, whether it is Required, and any Conditional logic.

Field widths & layout

Every field has a width from 10% to 100%. Pick one from the Width dropdown, or just drag the blue handle on a field’s right edge — fields tile live, so you see the layout as you build.

  • Two 50% fields sit side by side; three 33% share a row
  • A 100% field takes its own row
  • Snap presets: 10, 20, 25, 33, 40, 50, 60, 66, 75, 80, 90, 100%
  • Everything stacks to full width on mobile automatically
Unique field keysEach field’s Field Key is unique within the form — on save, a duplicate is automatically suffixed (email, email_2…) and a blank key is generated from the label, so entries and notification emails stay unambiguous.
Required & reorderToggle Required per field, and drag the ⠿ handle to reorder. Duplicate a field to reuse its settings.

Conditional logic

Every field can show or hide based on another field’s answer — no code, enforced on the front end and re-checked on submit.

Open a field, enable Conditional logic, and add rules: this field will show or hide when all or any of your conditions match.

OperatorMatches when the source field…
equals / not equalsis exactly / is not the value
contains / not containsincludes / does not include the value
is empty / is not emptyhas no value / has any value
Validated twiceHidden fields aren’t required while hidden, and the same rules run again server-side on submit — so the logic can’t be bypassed.

Flow mode (steps & branches)

Flow turns a form into a branching, multi-step experience built on a visual canvas.

Get a quote
Shortcode: [stack_form id="3"]
Simple formFlow (steps & branches)
+ Choice+ GroupDrag a field type onto a group · connect nodes to branch the flow
START
TypeBRANCH
Individual
Business
Business detailsGROUP
CompanyTEXT
Team sizeDROPDOWN
VAT numberTEXT
Personal detailsGROUP
Full nameTEXT
EmailEMAIL
BudgetDROPDOWN
The Flow canvas — a START marker, a branch (choice) node and the group (step) nodes each branch leads to.
  • Choice nodes branch the flow — each option leads to a different next node
  • Group nodes hold the fields for a step; drag field types from the palette
  • The visitor only sees the path their answers lead to
  • A progress bar, Back and Next are built in; only the visited path is submitted
Same shortcodeA flow renders with the same [stack_form id="…"] shortcode as a simple form — switch a form between Simple and Flow from the builder tabs at any time.

Entries inbox

Every submission is stored, searchable and exportable — with source intelligence for each lead.

Entries
All forms
128
Entries
12
Unread
— All forms — 128 entries
Priya N.Get a quoteAug 5, 2026 14:16192.0.2.44
Jordan L.Website intakeAug 5, 2026 14:05203.0.113.19
Sam C.Website intakeAug 5, 2026 13:58198.51.100.7
Alex R.ContactAug 5, 2026 13:22192.0.2.128
Mai T.Website intakeAug 4, 2026 21:06203.0.113.201
The Entries inbox — filter by form, read / unread state, timestamp and source IP, with per-row delete.
  • Filter by form; read / unread state per entry
  • Source intelligence — UTM, referrer, device and IP
  • Export CSV of the entries
  • Per-row delete
Flow entriesA flow submission stores only the fields on the path the visitor actually took, plus the choice they made at each branch — labelled by the step / branch title.

Spam protection & Blocked IPs

Two layers keep junk out with no CAPTCHA: a silent honeypot and per-IP rate limiting.

Blocked IPs
Automatic spam protection
IPs are blocked automatically when a visitor exceeds 15 form submissions per minute.
198.51.100.66Form spam — exceeded 15 submissions/minuteAug 5, 2026 09:41Unblock
203.0.113.201Form spam — exceeded 15 submissions/minuteAug 3, 2026 22:14Unblock
The Blocked IPs panel — addresses that flooded the form are blocked automatically and can be released.
  • A hidden honeypot field silently drops bot submissions
  • Rate limiting — an IP that exceeds 15 submissions a minute is blocked
  • Blocked addresses appear under Blocked IPs, where you can Unblock them
The honeypot is invisible to real visitors and needs no configuration — it’s on for every form.

Notifications & confirmations

Email your team on every submission, and optionally confirm to the person who submitted.

Website intake
Notifications & after submit
Notifications
Notify email
Subject
New form submission
Confirm to submitter
After submit
Button text
Send message
Success message
Thank you! Your message has been sent.
Redirect URL (optional)
https://…
The Notifications and After-submit panels — notify email, subject, submitter confirmation, button text, success message and redirect.
  • Notify email and subject for the team notification (a branded HTML table of the entry)
  • Confirm to submitter — an optional confirmation email sent to the submitted email address
  • Button text and a success message, or a redirect URL after submit
Reliable deliveryPair Forms with the SMTP module so notifications and confirmations are sent through your own mail server and logged.

Shortcode & Elementor

Place a form with a shortcode or the native Elementor widget.

[stack_form]

Render a form (simple or flow) anywhere.

idRequired. The form id, shown in the builder next to “Shortcode”.
texton a page
[stack_form id="2"]
ElementorPrefer a builder? Add the WPStack Form Elementor widget and pick the form from the dropdown — no shortcode needed.

Settings reference

Each form has its own Notifications and After-submit settings.

SettingTypeDefaultWhat it does
Notify emailemailAdmin emailWhere the submission notification is sent. Leave as the site admin or set a team inbox.
SubjecttextNew form submissionSubject line of the notification email.
Confirm to submittertoggleOffSend a confirmation email to the address submitted in the form.
Button texttextSend MessageLabel of the form’s submit button.
Success messagetextThank you! …Shown in place of the form after a successful submission.
Redirect URLurlOptional. Send the visitor to this URL after submit instead of showing the success message.

Webhooks & integrations

Send every submission straight to Make, Zapier, n8n or your own CRM, the moment it arrives.

With the Connect module enabled, each entry can be posted to any address you give it — a row in a spreadsheet, a Slack message, a contact in your mailing list, a deal in your CRM. Set it up under WPStack → App Connect → Integrations: paste the URL your tool generated, pick Forms from the module list, tick the events, and press Send test so your tool can learn the field structure.

Events you can subscribe to

EventSent when
form.submittedA visitor submits any form.
form.entry_deletedAn entry is removed. The full record is included, since it no longer exists afterwards.

What a delivery contains

Alongside the answers, every delivery carries the source of the lead — page_url, referrer, device and the full UTM set (utm_source, utm_medium, utm_campaign, utm_term, utm_content). That is what lets a CRM attribute where the enquiry actually came from.

The answers arrive twice, in two shapes, because the two are useful in different places:

KeyShapeUse it when
fieldsA list of { name, label, value, type }One endpoint receives several forms. The structure is identical for every form, so nothing breaks when a different form comes in.
valuesAn object keyed by field name — values.emailOne endpoint receives one form. Far easier to map, but the keys are whatever that form defines.
One endpoint per form is the safe defaultMake and Zapier learn the field structure from your first test delivery. The envelope keys never change, but values follows the form — so if one endpoint receives a contact form and a quote form, map against fields, or add a filter on form_id in your scenario.
Field names, not labelsvalues is keyed by the field’s name, not its visible label. Renaming “Email” to “Your email address” in the builder will not break a mapping you have already made.
One-way by designData only ever leaves your site. These endpoints give nobody a way to write back into WordPress, and there is no API key for an outsider to hold. Add a signing secret and each delivery carries an X-WPStack-Signature header your receiver can verify.

For developers

Both events are also standard WordPress actions, so you can handle them in a plugin or your theme without Connect — they are fired by the Forms module itself. Note the wpsf_ prefix: it is the module’s own, and predates the wpstack_ naming used by Booking and Events.

HookTypeDescription
wpsf_entry_createdaction$entry_id, $form_id, $data — a form was submitted. $data is [ name => [ label, value, type ] ].
wpsf_entry_deletedaction$entry_id, $entry — fires just before the row is removed, so $entry still holds the record with data and meta decoded.
php
add_action( 'wpsf_entry_created', function ( $entry_id, $form_id, $data ) {
    $email = $data['email']['value'] ?? '';
    if ( ! $email ) {
        return;
    }
    // …add to a mailing list, open a ticket, write to your own table…
}, 10, 3 );
Pass the argument countThe 4th parameter of add_action() is how many arguments your callback receives. Leave it off and WordPress hands you only the first.
Opening an entry is not an eventMarking an entry read happens whenever you view it in the inbox, so it fires nothing — otherwise ordinary browsing would flood your scenario.

FAQ

A simple form is a single flat list of fields. A flow is a branching, multi-step form built on a visual canvas, where each answer leads down its own path. Both render with the same [stack_form] shortcode.

To the Entries inbox — searchable, filterable by form, with CSV export — and to the notify email you set. You can also confirm to the submitter.

A silent honeypot drops bots, and per-IP rate limiting blocks any address that exceeds 15 submissions a minute. Blocked addresses are listed under Blocked IPs, where you can release them.

Yes — every field has conditional-logic rules to show or hide it based on another field, enforced on the front end and re-checked on submit.

Changelog

1.4.0
August 2026
newField widths from 10% to 100% with drag-to-resize — fields tile live for tidy multi-column layouts.
newThe field editor opens in a floating popover that never resizes the tile or pushes other fields.
newOptional Placeholder as a per-field toggle (text fields only).
impField keys are unique per form on save — duplicates get a numeric suffix.
1.3.6
August 2026
impRefined the field-list builder — icon action buttons, clearer rows and a fixed field-list layout.
fixFlow: unique, readable submission keys across the whole flow, and the row chevron now toggles reliably.
1.3.0
August 2026
newFlow mode — branching multi-step forms on a visual choice / group canvas.
newPer-field conditional logic (show / hide on another answer).
1.0.0
July 2026
newDrag-and-drop form builder, entries inbox, notifications, honeypot + rate-limit spam protection, shortcode and Elementor widget.
Was this page helpful?