Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

SentientMail Form Builder

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

SentientMail Form Builder

By sentientmail
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

SentientMail Form Builder connects your WordPress site to SentientMail, so every newsletter signup and form submission lands in your email audience automatically, ready for journeys, campaigns, and transactional email.

Newsletter signups in two minutes

  1. Install and activate the plugin
  2. Paste your SentientMail Events API key on the Get Started screen
  3. Add the ready-made Newsletter Signup form to any page, as a block or a shortcode

Everything else a small site needs from forms

  • Contact, application, and custom forms with 23 field types (including file uploads, address, rating, consent, calculations, signature, matrix and repeatable groups)
  • Save and resume, so a long form can be finished later, plus optional capture of forms people abandon
  • Conditional logic: show or hide fields based on earlier answers, enforced on the server as well as in the browser
  • Multi-page forms with a progress indicator and per-page validation
  • Eight starter templates, so you never begin with an empty form
  • Privacy controls: optional IP logging, an entry retention window, and support for WordPress export and erasure requests
  • Every submission saved as an entry, with CSV export
  • Per-form analytics: views, submissions, the conversion rate between them, and which field people were on when they gave up. Aggregate counters only, kept in your own database, with no third-party service and no charting library
  • Email notifications with smart tags ({all_fields}, {field_id="2"}, …)
  • Show-a-message or redirect confirmations
  • Invisible anti-spam (honeypot + time trap) out of the box; optional Cloudflare Turnstile
  • A keyword blocklist you control, plus optional Akismet if you already use it. Suspected spam is held for review, not thrown away
  • Trigger a SentientMail transactional email to the submitter (welcome emails, promo codes)
  • Add subscribers to a Mailchimp audience, with your own field-to-merge-field mapping. Double opt-in by default, and a consent checkbox on the form is honoured
  • Post each submission to a Slack channel, using the same smart tags as your notification emails
  • Outgoing webhooks with HMAC signatures for anything else (Zapier, Make, custom apps)
  • One-click import of WPForms forms and entries if you’re switching

The plugin works without a SentientMail account too. Forms, entries, and notifications are fully functional standalone. Connect an account when you’re ready to grow your list.

External services

This plugin can connect to five named external services, and it can send
submissions to a webhook address you choose. All of it is optional: with none of
it configured, forms, entries and email notifications work entirely on your own
site and no data leaves it. The keyword blocklist is not one of them; it is
matched on your own server and sends nothing anywhere.

SentientMail

SentientMail is a hosted email marketing and transactional email platform, operated
by us. It is what the plugin syncs your form submissions into, so that signups
become contacts you can send campaigns and journeys to.

It is used only after you paste a SentientMail Events API key on the Get Started
screen. Nothing is sent before that.

What is sent, and when:

  • When you verify your API key on the Get Started screen: your site’s address and
    the plugin version, plus your WordPress administrator email address, as a single
    connection event.
  • When a visitor submits a form that has audience sync enabled: the values that
    form collected (typically name and email address), the form’s name, and whether
    the visitor gave marketing consent.
  • When a form is configured to send a welcome or transactional email: the
    recipient’s email address and the merge values that email needs.

Requests go to https://app.sentientmail.com over HTTPS and are authenticated with
the key you supplied. Forms without audience sync enabled send nothing.

Terms of service: https://sentientmail.com/terms.html
Privacy policy: https://sentientmail.com/privacy.html

Mailchimp

Mailchimp is a hosted email marketing platform operated by Intuit. It is used
only if you enter your own Mailchimp API key under Settings AND switch Mailchimp
on for a particular form, where you also choose which audience to add people to.
It is off by default. With no key entered, no form makes any request to
Mailchimp.

Your Mailchimp API key ends in a dash and a short datacenter code, such as
-us21. The plugin reads that code out of the key to work out which Mailchimp
server your account is on, so there is no server address for you to enter. A key
without that suffix is refused, and nothing is sent.

What is sent, and when:

  • When a visitor submits a form that has Mailchimp enabled: their email address,
    the audience ID you chose, and the values you mapped to Mailchimp merge fields,
    which by default are their first and last name. Uploaded files and signature
    images are never sent. Nothing else from the submission is sent unless you map
    it to a merge field yourself.
  • Nothing is sent at any other time. There is no background sync, and the plugin
    never reads your audiences or your Mailchimp account back.

If the form contains a consent checkbox, nothing is sent to Mailchimp at all
unless the visitor ticked it.

New subscribers are added as “pending” by default, which is Mailchimp’s double
opt-in: Mailchimp emails a confirmation link and nobody joins the audience until
they click it. You can choose single opt-in per form instead, which adds the
address immediately.

Requests go from your server to https://.api.mailchimp.com over
HTTPS, authenticated with the API key you supplied. The key is sent in an
Authorization header, is never written into a URL, is never shown again after you
save it, and is removed from any error message the plugin records.

Terms of service: https://mailchimp.com/legal/terms/
Privacy policy: https://mailchimp.com/legal/privacy/

Slack

Slack is a team messaging service operated by Salesforce. It is used only if you
create an incoming webhook in your own Slack workspace, paste its URL into a
form’s Integrations tab and switch Slack on for that form. It is off by default.
With no webhook URL saved, no form makes any request to Slack.

The URL must be an https://hooks.slack.com/ address; anything else is refused
rather than saved, so the field cannot be pointed at some other server.

What is sent, and when:

  • When a visitor submits a form that has Slack enabled: the message you composed
    for that form, which by default is the form’s name followed by the answers.
    Uploaded files and signature images are never posted to Slack; the message
    says how many files were attached and links to the entry in your own
    dashboard instead. The message is posted as plain text, so nothing a visitor
    typed can become a link or a channel mention.
  • Nothing is sent at any other time, and the plugin never reads anything back
    out of Slack.

Requests go from your server to https://hooks.slack.com over HTTPS. The webhook
URL is the credential: it is never displayed again after you save it, and it is
removed from any error message the plugin records.

Terms of service: https://slack.com/terms-of-service
Privacy policy: https://slack.com/trust/privacy/privacy-policy

Cloudflare Turnstile

Turnstile is Cloudflare’s privacy-preserving CAPTCHA alternative. It is used only
if you enable it and enter your own Turnstile site key and secret key under
Settings. It is off by default.

What is sent, and when:

  • On any page displaying a form: the visitor’s browser loads Turnstile’s widget
    script from challenges.cloudflare.com. Cloudflare receives the visitor’s IP
    address and browser information as part of that request.
  • When a visitor submits the form: the challenge token their browser produced,
    together with your secret key, is sent from your server to Cloudflare for
    verification.

Terms of service: https://www.cloudflare.com/website-terms/
Privacy policy: https://www.cloudflare.com/privacypolicy/

Akismet

Akismet is a spam-filtering service operated by Automattic. It is used only if
the Akismet plugin is installed and already set up with its own API key, AND you
tick “Akismet” in a form’s anti-spam settings. It is off by default. This plugin
never asks you for an Akismet key of its own and never stores one: it uses the
key Akismet already holds. With no key present, no request is made.

What is sent, and when:

  • When a visitor submits a form that has Akismet enabled: the text values that
    form collected, together with the submitter’s IP address, browser user agent,
    and the address of the page the form was on. Uploaded files and signature
    images are never included. Alongside the submission, the request carries the
    fields the Akismet API defines for a spam check: your site’s address, its
    language and its character set.

Requests go from your server to https://rest.akismet.com over HTTPS, addressed
with your Akismet API key, which is how Akismet identifies the account making
the check. Nothing is sent from the visitor’s browser, and no Akismet script is
loaded on your pages.

If Akismet cannot be reached, or answers with anything other than a verdict, the
submission is accepted. A submission Akismet does call spam is kept as a spam
entry you can review and restore, not deleted.

Terms of service: https://akismet.com/tos/
Privacy policy: https://akismet.com/privacy/

Outgoing webhooks

Not a third-party service, but it does send data off your site, so it is
documented here with the rest.

A form can be given a webhook address under its Integrations tab. There is no
default and no address is built in: it goes wherever you type. When somebody
submits that form, this plugin sends that address a JSON request containing your
site address, the form’s ID and title, the entry ID, the time of submission, the
page the form was on, and the values the visitor entered. If you set a signing
secret, the request is also signed so the receiver can verify it came from you.

Requests go over HTTPS only, and cannot be aimed at addresses inside your own
server’s network. Whoever operates the address you enter decides what happens to
the data once it arrives, under their own terms and privacy policy. Remove the
address to stop the sending.

Blocks

This plugin provides 1 block.

  • SentientMail Form

Installation

  1. Upload the plugin ZIP under Plugins → Add New → Upload Plugin, then activate it.
  2. You’ll land on the Get Started screen. Paste your Events API key from SentientMail (Settings → API Keys).
  3. Add the Newsletter Signup form to a page: add a block and search “SentientMail Form”, or paste the shortcode shown on the Get Started screen.

FAQ

Do I need a SentientMail account?

No. Forms, entries, and email notifications work standalone. A free SentientMail account adds audience sync, journeys, and transactional email.

Where do submissions go?

Three places: the Entries screen in your dashboard, your notification email(s), and, if connected, your SentientMail audience.

Does it work with my page builder?

The [sentientmail_form id=123] shortcode works anywhere shortcodes are supported, and the block works in the standard editor.

What data does the plugin send to SentientMail?

Only what a form collects, and only when you’ve connected an API key and enabled sync for that form.

A submission can also reach the other services listed under “External services” below, each of which you switch on yourself: a webhook address you enter, Mailchimp, Slack, Akismet, or Cloudflare Turnstile. With none of them configured and no API key entered, nothing leaves your site.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“SentientMail Form Builder” is open source software. The following people have contributed to this plugin.

Contributors
  • sentientmail

Translate “SentientMail Form Builder” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.7.1

  • Fixed: choosing which role a form may create could raise an error if the value arrived in an unexpected shape. It is now reduced to a plain value and checked against the allowed list before use.
  • Fixed: the block editor’s form list used a data name left over from an earlier version of the plugin.

1.7.0

  • Fixed: correcting one field could destroy an upload on another. Files were moved out of temporary storage while the rest of the form was still being checked, so an error anywhere left the upload unusable and a required file field impossible to satisfy. Uploads are now taken only once the whole submission is accepted.
  • Fixed: a mistyped field could lock a visitor out of the form. A Cloudflare Turnstile check is good for one use, and it was spent before the form was checked, so every retry failed until the page was reloaded. The check now runs last, and the widget is reset after any failure.
  • Fixed: a submission that could not be saved told the visitor it had gone through, and still sent the notifications. It now reports the failure and tells the site owner what was lost.
  • Fixed: two things processing the queue at the same time could send the same webhook, Slack message or Mailchimp update twice.
  • Security: the file upload endpoints accepted requests from anyone who knew a form’s ID. They now require the signed token every form carries, and limit how much one visitor can have in progress.
  • Security: uploaded chunks are written under a lock, so simultaneous requests can no longer push a file past the size limit it declared.
  • Security: webhooks are sent over HTTPS only, and can no longer be pointed at addresses inside the server’s own network.
  • Fixed: values submitted through a form are neutralised before they are written to a CSV export, so a spreadsheet cannot treat them as formulas.
  • Fixed: an entry’s resume link only works on the form it belongs to.
  • Fixed: reinstalling over an older version no longer skips the upgrade and comes up empty.
  • Fixed: an array-typed query variable could reach a string-typed method and produce a fatal error on a public page. All request values are now type-checked before use.
  • Changed: every internal name now uses a longer prefix, as the plugin directory requires. Existing forms, entries, settings and uploads are migrated automatically on upgrade.
  • Changed: the admin menu, the Settings screen and the setup wizard are translatable.

1.6.0

  • Renamed to SentientMail Form Builder.

1.5.1

  • Renamed to SentientMail Form Builder.
  • Added: Mailchimp. Enter your API key once under Settings, then per form choose an audience and map form fields to merge fields. Subscribers are added with double opt-in unless you choose otherwise, and if the form has a consent checkbox, nobody is subscribed without ticking it. An address already on the audience is not treated as an error, and someone who previously unsubscribed is never put back on.
  • Added: Slack. Paste an incoming webhook URL into a form and each submission is posted to your channel, using the same smart tags as notification emails. Uploaded files and signatures are never posted; the message links to the entry instead, and it is posted as plain text so nothing a visitor typed can become a link or a channel mention.
  • Security: only an https://hooks.slack.com/ address can be saved as a Slack webhook, so the field cannot be aimed at another server.
  • Security: the Mailchimp API key and the Slack webhook URL are never shown again after saving, and are removed from any error recorded on the Integration Queue screen.
  • Fixed: one integration job throwing an error ended the whole queue run, so a single broken destination could stall every other integration on the site. A failure now stays with the job that caused it.
  • Fixed: the per-form “marketing consent” checkbox was not being read when a form was saved, so ticking it had no effect.
  • Added: a keyword blocklist. Enter words or phrases in Settings and a submission containing any of them is held as a spam entry for review. Matching ignores case and spacing, and every entry is matched as the literal text you typed, so a line reading .* blocks those two characters rather than every submission.
  • Added: optional Akismet checking, per form, using the key the Akismet plugin already has. Off by default, and inert with no key. If Akismet is unreachable the submission is accepted rather than lost, and a submission it flags is quarantined for review, never discarded.
  • Security: notification sender name, from address and reply-to are now stripped of line breaks before they reach a mail header.
  • Security: a form can no longer be configured to grant a role that can write posts. Only roles with read-only capabilities are offered.
  • Security: the submission rate limiter only trusts a proxy-supplied client IP when the request arrived from a local reverse proxy, so a direct visitor cannot forge one to bypass the limit, and a site behind a proxy does not put every visitor in the same bucket. Override with the sentfobu_trust_proxy_ip filter.
  • Fixed: the custom post type is now prefixed. Existing forms are migrated automatically on upgrade.
  • Fixed: the editor’s configuration is attached with wp_add_inline_script instead of a hand-written script tag.
  • Fixed: the Plugin URI pointed at a page that returned 404.
  • Added: an External services section in the readme documenting exactly what is sent to SentientMail and to Cloudflare Turnstile, with links to both services’ terms and privacy policies.

1.3.1

  • Verified against WordPress 7.1. The compatibility notice on this plugin was three major releases out of date.

1.3.0

  • Added: update notices for the edition downloaded from our own site. The version published on WordPress.org is updated by WordPress.org like any other plugin and contains no update-checking code.

1.2.1

  • Added: a per-form “marketing consent” option, for forms where the visitor is clearly opting in. It marks the contact as eligible for consent-gated journeys.
  • Fixed: a welcome email could be sent twice if the delivery queue retried a job. Messages are now keyed so a retry cannot duplicate a send.
  • Fixed: the file upload area could pick up a theme’s button styling and render as a small coloured block instead of a drop zone.
  • Fixed: a form whose stored settings had been damaged by another plugin or script rendered as nothing at all, with no error. Recoverable damage is now repaired automatically and reported in the error log.

1.2.0

  • Added: calculation fields. Build a running total from other fields with a simple formula. The total is recalculated on the server, so it cannot be tampered with in the browser.
  • Added: save and resume. Visitors can pick up a long form where they left off, from a link.
  • Added: abandoned entry capture. See what people filled in before they gave up, so you can shorten the form or follow up. Off by default, and partial entries expire on their own.
  • Added: create a WordPress user from a submission. Only roles that cannot manage the site can be granted, and the account gets a set-password email rather than a password typed into a form.
  • Added: create a post from a submission, as a draft unless you choose otherwise.

1.1.0

  • Added: conditional logic. Show or hide any field based on what was answered earlier, with all/any matching and ten comparisons. Enforced on the server as well as in the browser, so a field nobody saw can neither block a submission nor be smuggled into one.
  • Added: multi-page forms with a progress indicator, per-page validation, and Next/Previous buttons you can label.
  • Added: address, rating, consent and section-divider fields.
  • Added: eight starter templates. “Add New” now opens a gallery instead of an empty form.
  • Added: entry search, date filtering, spam/received tabs, bulk actions, resend notification, and CSV export that respects the current filter.
  • Added: privacy controls per form. Turn IP logging off, set a retention window, and answer export or erasure requests through the normal WordPress personal-data tools.
  • Added: an Integration Queue screen showing webhook and sync jobs, with retry.
  • Added: full translation support. The plugin is now translatable and ships a .pot file.
  • Changed: a submission caught by the honeypot is kept as a reviewable spam entry rather than being discarded. A browser autofill could previously destroy a genuine message with no record it ever arrived.
  • Fixed: accessibility. Groups of choices now use fieldset and legend, errors are announced and tied to their field, and required fields are marked for screen readers.
  • Fixed: importing from WPForms no longer drops page breaks, GDPR checkboxes, address or rating fields, and it now carries conditional logic across.

1.0.3

  • Added: a notification that fails without raising an error is now logged and recorded from the submission handler too, closing the last path where a failed email could pass unnoticed.

1.0.2

  • Added: failed notification emails are now recorded and surfaced as a dashboard warning. Previously a rejected email was invisible, so a submitter saw “received”, the entry saved, and nobody was told an email never arrived.

1.0.1

  • Fixed: audience sync and the Get Started key check sent an outdated authentication header, so connecting an account failed and contact sync never reached SentientMail. Both now send X-Event-API-Key.

1.0.0

  • Initial release: newsletter signups, form builder, entries, notifications, confirmations, chunked file uploads, SentientMail audience sync + transactional sends, signed webhooks, Turnstile, WPForms import.

Meta

  • Version 1.7.1
  • Last updated 16 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.0 or higher
  • Tested up to 7.1
  • PHP version 7.4 or higher
  • Tags
    contact formEmail Marketingformsnewslettersignup
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • sentientmail

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org
  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry
The WordPress® trademark is the intellectual property of the WordPress Foundation.