Description
BlogCutter Magic Form Builder is a complete visual form builder for WordPress. Build contact forms, registration forms, surveys, applications, support requests, quote forms, and more without writing code.
Everything included in the plugin is free to use. There is no Pro edition, premium upgrade, subscription, usage limit, locked field, or payment required to access its features.
Create forms with the drag-and-drop builder, apply conditional logic, split long forms into multiple steps, accept file uploads, protect submissions from spam, send email notifications, manage entries in WordPress, and export submission data to CSV.
100% free—all included features unlocked
- No paid plan or Pro version
- No premium-only fields
- No locked templates
- No form or submission limits imposed by the plugin
- No subscription or recurring payment
- No upgrade prompts required to unlock features
- Use the complete included feature set on any WordPress site where you install the plugin
- GPL-licensed open-source software
Your hosting provider may still impose normal server, email, storage, upload, or traffic limits. Optional Google reCAPTCHA is operated under Google’s own terms.
Modern visual form builder
- Drag and drop fields into the form canvas
- Click any field type to add it instantly
- Searchable and categorized field palette
- Live field previews in the admin builder
- Move fields up or down and reorder them by dragging
- Duplicate and delete fields
- Full-width and half-width field layouts
- Field, Logic, and Advanced property tabs
- Keyboard-friendly field selection and reordering
- Stable field IDs for reliable saved data and conditional rules
- Form revision checks to help prevent stale editor saves
- Automatic asset cache busting after plugin updates
Ready-made form templates
Choose a template to automatically set the form title and add a complete group of relevant fields:
- Contact Form
- Registration Form
- Customer Feedback Form
- Login Support Form
- Newsletter Signup Form
- Appointment Booking Form
- Customer Survey Form
- Job Application Form
- Request a Quote Form
- Customer Support Request
Every template is fully editable after it is added.
21 field and layout types
- Short Text
- Full Name
- Phone
- Website URL
- Number
- Long Text
- Dropdown
- Radio Buttons
- Checkboxes
- Consent Checkbox
- Date
- Time
- Address
- File Upload
- Color Picker
- Hidden Field
- Section Heading
- Divider
- HTML Content
- Page Break
Full Name and composite fields
- Full Name includes first and last name inputs
- Optional middle-name input
- Browser autocomplete support
- Address field stores structured address details
- Composite values are formatted clearly in entries, emails, and CSV exports
Flexible field settings
Depending on field type, configure:
- Label and placeholder
- Help text
- Required or optional status
- Default value
- Full or half width
- Number minimum and maximum
- Text minimum and maximum length
- Editable dropdown, radio, and checkbox choices
- Consent statement
- Allowed file extensions
- Maximum upload size
- Optional middle name
Conditional logic
Create dynamic forms that react to visitor answers:
- Show or hide a field
- Match all rules or any rule
- Reference eligible fields placed earlier in the form
- Operators include is, is not, contains, does not contain, is empty, is not empty, greater than, and less than
- Type-aware operators and choice values
- Conditional visibility updates in the browser
- Rules are independently re-evaluated on the server
- Hidden values are not stored
- Hidden required fields do not block submission
Multi-step forms
- Add Page Break fields to create steps
- Automatic Back and Next controls
- Optional progress bar
- Per-step validation
- Step titles
- Responsive navigation
- Only currently relevant conditional steps and fields are shown
Frontend experience
- Responsive form layout
- Accessible labels and controls
- Required-field indicators
- Clear validation messages
- Invalid-field highlighting
- Submit button state based on required inputs
- Custom submit-button label
- Success message after submission
- Optional redirect after submission
- Shortcode embedding in posts, pages, widgets, and shortcode-compatible page builders
- Only published forms render and accept submissions
Entries and submission management
- Store submissions in the WordPress admin
- Unread, Read, and Spam statuses
- Filter entries by form and status
- Entry detail screen with structured values
- Form name, field count, visitor IP, and email-delivery information
- Printable entry view
- Uploaded files linked to entries
- Forms list shows shortcode, field count, and entry count
- One-click shortcode copy button
- Entry-count links open submissions filtered to the selected form
CSV export
- Export all entries or the currently filtered form/status set
- Streaming, batched export for better memory use
- Dynamic columns based on current and historical form fields
- UTF-8 BOM for Excel compatibility
- Protection against spreadsheet formula injection
Email notifications
- Send submission notifications to one or multiple email addresses
- Custom notification subject
{form_title}placeholder in the subject- Choose an Email field as the Reply-To address
- Email delivery status recorded with each entry
- Submitted values formatted for readable notification emails
Layered spam and abuse protection
- Invisible honeypot field
- Signed, expiring form token
- Minimum form-completion time
- Per-IP rate limiting
- Duplicate-submission suppression
- Built-in math CAPTCHA
- Optional Google reCAPTCHA v2
- Form-bound CAPTCHA verification
- Published-form verification before accepting a submission
Validation and secure uploads
- Server-side required-field validation
- Email-address validation
- Safe URL validation
- Number and range validation
- Date and time validation
- Choice membership validation to reject tampered values
- Text length validation
- Consent validation
- Conditional logic enforced again on the server
- File extension, MIME type, and size checks
- Successful uploads become WordPress Media Library attachments
- Uploaded files are rolled back if the entry cannot be saved
- WordPress nonces, capability checks, sanitization, and escaping
Data ownership and privacy
- Forms and entries are stored in your own WordPress database
- No submission data is sent to Blog Cutter
- Form data remains on your site by default when the plugin is uninstalled
- Optional complete data removal on uninstall
- Visitor IP and user agent are stored with entries for moderation and troubleshooting
- Proxy headers are not trusted unless explicitly enabled with the
blogmafo_trust_proxy_headersfilter
Backward compatibility
Forms and entries created with version 1.x continue to work. Version 2 reads the legacy format directly, normalizes it safely in memory, and creates the versioned definition when the form is saved. Legacy form metadata is updated in parallel to preserve downgrade compatibility.
External services
This plugin can connect to the following third-party service only when the related optional feature is configured.
Google reCAPTCHA
When reCAPTCHA v2 site and secret keys are entered under Magic Forms Settings, the plugin loads Google’s reCAPTCHA JavaScript on pages displaying a protected form. Upon submission, the visitor’s reCAPTCHA response token is sent to Google’s verification API.
- What is sent: reCAPTCHA response token, your secret key from the server, visitor IP address, and standard request metadata required by Google
- When it is sent: when reCAPTCHA is configured and a visitor submits a protected form
- Why it is sent: to verify that a submission appears to come from a human
- Service provider: Google LLC
- Terms of Service: https://policies.google.com/terms
- Privacy Policy: https://policies.google.com/privacy
Screenshots












Installation
- Upload the
blogcutter-magic-form-builderfolder to/wp-content/plugins/, or install it through the WordPress Plugins screen. - Activate BlogCutter Magic Form Builder.
- Go to Magic Forms Add New Form.
- Start from a template or add fields from the palette.
- Configure field properties, conditional logic, notifications, and submission behavior.
- Publish the form.
- Copy its shortcode from the form editor or Magic Forms list.
- Paste the shortcode into a page, post, widget, or shortcode-compatible page builder.
- Optionally configure CAPTCHA and data settings under Magic Forms Settings.
FAQ
-
Is every included feature really free?
-
Yes. All functionality included in BlogCutter Magic Form Builder is available without a payment, license key, subscription, Pro plan, or premium upgrade. There are no plugin-imposed limits on the number of forms or entries.
-
Do I need to create an account or enter a license key?
-
No. Install and activate the plugin, then begin building forms. Optional Google reCAPTCHA requires keys obtained separately from Google.
-
How do I display a form?
-
Publish the form and copy its shortcode, for example
[blogmafo_form id="12"]. Paste it into a post, page, widget, or shortcode block. Only published forms display and accept submissions. -
How do form templates work?
-
On an empty form canvas, click a template such as Contact Form, Registration, Survey, or Job Application. The builder automatically changes the form title and adds the template fields. You can then edit, reorder, duplicate, or delete any field.
-
How do I create a multi-step form?
-
Add a Page Break field wherever the next step should begin. The plugin creates Back and Next buttons automatically. Enable or disable the progress bar in Form Settings.
-
How does conditional logic work?
-
Select a field, open the Logic tab, enable conditional logic, and choose whether to show or hide it when all or any rules match. Rules reference eligible fields above the selected field. Conditions are enforced both in the browser and on the server.
-
Can I accept file uploads?
-
Yes. Add a File Upload field and configure allowed extensions and maximum size. The plugin verifies extension, MIME type, and file size. Accepted files become Media Library attachments linked to the entry. Standard WordPress media URLs may be publicly accessible, so do not request highly sensitive files without additional site-level access controls.
-
Where are submissions stored?
-
Go to Magic Forms Entries. Entries include submitted values, status, source form, IP address, user agent, uploads, and email-delivery status.
-
Can I export entries?
-
Yes. Filter entries by form or status if needed, then click Export CSV. The CSV includes current and historical fields and protects cells that could otherwise be interpreted as spreadsheet formulas.
-
Can notification emails go to multiple people?
-
Yes. Enter multiple notification recipients in Form Settings. You can customize the subject and use a visitor Email field as Reply-To.
-
Can I redirect visitors after submission?
-
Yes. Each form can show a custom success message or redirect to a configured URL.
-
How does spam protection work?
-
The plugin combines a honeypot, signed form token, minimum completion time, rate limiting, duplicate suppression, built-in math CAPTCHA, and optional reCAPTCHA v2.
-
Does it work with page builders?
-
Yes. Any page builder that executes WordPress shortcodes can display the form.
-
What happens when I uninstall the plugin?
-
Forms, entries, settings, and uploaded files are preserved by default. To remove plugin data during uninstall, first enable Delete Data on Uninstall under Magic Forms Settings. This action is permanent.
-
What visitor data is stored?
-
The plugin stores submitted field values, visitor IP address, and browser user agent. Data remains in your WordPress database and is not sent to Blog Cutter. If reCAPTCHA is enabled, relevant verification data is sent to Google as described below.
-
Is there a submission or form limit?
-
The plugin does not impose one. Practical limits depend on your WordPress hosting plan, database size, storage, PHP configuration, and email service.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“BlogCutter Magic Form Builder” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “BlogCutter Magic Form Builder” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
2.0.0
- Added 10 complete templates that automatically populate the title and fields: Contact, Registration, Feedback, Login Support, Newsletter, Appointment, Survey, Job Application, Quote Request, and Support Request
- Added forms-list columns for shortcode, field count, and entry count, including one-click shortcode copying
- Added Full Name with first, optional middle, and last name inputs
- Added Website URL, Address, Consent, Hidden, HTML Content, and Page Break fields
- Added conditional show/hide logic with all/any matching and type-aware operators
- Added multi-step forms with progress bar and Back/Next navigation
- Modernized the builder with search, click-to-add, live previews, duplicate/reorder controls, keyboard support, and tabbed properties
- Added default values, field widths, text limits, numeric ranges, upload extension controls, and upload size controls
- Added unread/read/spam entry statuses, filters, email-delivery status, printable views, and streaming CSV export
- Added multiple notification recipients, custom subjects,
{form_title}, and visitor Reply-To support - Added type-aware server validation and hardened uploads with rollback
- Added honeypot, signed token, timing checks, rate limiting, duplicate suppression, math CAPTCHA, and optional reCAPTCHA v2
- Added versioned form definitions with safe version 1 compatibility and dual writes
- Added configurable uninstall data retention
- Added Contact Us support links on plugin admin screens
- Added automatic asset cache busting
1.0.4
- Prefixed plugin hooks, options, and registrations for WordPress.org compliance
- Isolated math CAPTCHA hashing from WordPress salts
- Moved printable-entry CSS and JavaScript to enqueued assets
- Documented Google reCAPTCHA and stored visitor metadata
1.0.3
- Added visitor IP address and user-agent details to entries
- Improved Plugin Check and coding standards compliance
- Added WordPress 7.0 compatibility metadata
1.0.2
- Added a modern entry view
- Changed entry actions from Edit to View
- Added form-name and field-count entry columns
1.0.1
- Kept submit disabled until required fields and math CAPTCHA are complete
- Added server-side required-field validation
- Improved frontend invalid-field highlighting
1.0.0
- Initial release
- Visual admin builder and responsive frontend forms
- Math CAPTCHA and optional Google reCAPTCHA v2
- Entry management and email notifications
