Description
MIS Webform is a full-featured form builder for WordPress, with no artificial limits on forms,
fields, or submissions in the free version. Build a simple contact form in a minute, or a
multi-page application form with conditional logic, file uploads, and a signature field — all
from one field-type registry of 38+ options, with 8 ready-made templates to start from, and
drag-to-reorder fields in the builder. Submissions are stored securely (uploaded files are never
publicly accessible), exportable to CSV, and integrated with WordPress’s own Export/Erase
Personal Data privacy tools.
Free version features:
- Unlimited forms, fields, and stored submissions – no artificial caps
- 38+ field types: text, email, phone, number, URL, date/time, file uploads (with type-specific
filters), star rating, signature pad, color picker, address, full name, Likert scale, and more - Multi-step / paginated forms with a progress bar and Next/Previous navigation
- Conditional field logic – show or hide a field based on another field’s value
- 8+ pre-built form templates (Contact, Donation, Membership, Education/Course Enrollment, Event
Booking/RSVP, File Upload, Poll, Survey) to start from instead of building from scratch - Submission storage with CSV export
- Honeypot and Google reCAPTCHA spam protection
- Email notifications on new submissions
Need more? MIS Webform Pro adds an AI Form Generator
and webhooks.
External services
This plugin connects to one third-party service, and only when a site owner explicitly enables
it – it is off by default and no data is sent anywhere for this purpose unless you turn it on.
Google reCAPTCHA v2 – used for optional spam protection on a per-form basis, under that
form’s Spam Protection settings.
- What is sent: when a form has reCAPTCHA enabled, the reCAPTCHA widget script is loaded from
Google (https://www.google.com/recaptcha/api.js) on pages where that form appears. When a
visitor submits the form, their reCAPTCHA response token and IP address are sent to Google’s
verification endpoint (https://www.google.com/recaptcha/api/siteverify) to confirm the
submission wasn’t from a bot. - When it is sent: only for forms where you have explicitly turned reCAPTCHA on and entered your
own Google reCAPTCHA site/secret keys. If you never enable it, no data leaves your site for
this purpose, and nothing related to reCAPTCHA loads or runs. - Privacy Policy: https://mistechnolabs.com/privacy-policy/
No other external service is contacted by this plugin. All other assets (CSS, JavaScript,
including the date/time picker library) are bundled with the plugin and served from your own
site. Plugin activation itself does not contact any external server.
Credits
This plugin bundles flatpickr 4.6.13 (MIT license) for its date/time
picker fields.
Installation
- Upload the
mis-webformfolder to the/wp-content/plugins/directory, or install the plugin
through the WordPress plugins screen directly. - Activate the plugin through the “Plugins” screen in WordPress.
- Go to MIS Webform New Form to build your first form.
- Copy the generated
[mis-webform id="X"]shortcode into any page, post, or widget area.
FAQ
-
How do I add a form to a page?
-
Copy the shortcode shown next to your form in the MIS Webform admin screen (for example
[mis-webform id=”1″]) and paste it into a page, post, or any widget/block that supports shortcodes. -
Where are submissions stored?
-
Submissions are stored in your WordPress database and are viewable under
MIS Webform Submissions, where they can also be exported to CSV.Each submission also records the visitor’s IP address and browser user agent string, mainly
useful for spam investigation. These are kept indefinitely along with the submission unless
you delete it yourself – there is currently no automatic expiry. If you’re subject to GDPR or
similar privacy regulations, factor this into your own data retention policy, and delete old
submissions manually via MIS Webform Submissions when they’re no longer needed. -
How are file uploads validated?
-
Each file upload field lets you set allowed file extensions and a maximum size. On submission,
MIS Webform checks both the filename’s extension and the file’s actual content against that
allowlist (using WordPress’s ownwp_check_filetype_and_ext()) – a file renamed to spoof its
extension (e.g. a disguised executable) is rejected even if the filename alone looks fine. This
content-based check is strongest when your host has the PHPfileinfoextension enabled,
which is the default on nearly all WordPress hosting – if your host has disabled it, file-type
validation falls back to WordPress core’s own weaker built-in checks. -
Does this plugin load anything from third-party servers?
-
By default, no – all CSS/JS assets, including the date/time picker library, are bundled with the
plugin and served from your own site.The one exception is Google reCAPTCHA, which is entirely optional and off by default. If you
choose to enable it for a form (under that form’s Spam Protection settings), the plugin will:- Load Google’s reCAPTCHA widget script (
https://www.google.com/recaptcha/api.js) on pages
where that form appears. - Send the visitor’s reCAPTCHA response, together with their IP address, to Google’s
recaptcha/api/siteverify endpoint when the form is submitted, to verify it wasn’t a bot.
This only happens for forms where you’ve explicitly turned reCAPTCHA on and entered your own
Google reCAPTCHA site/secret keys – if you never enable it, no data ever leaves your site for
this purpose. If you do enable it, consider mentioning Google reCAPTCHA in your site’s privacy
policy, as its use is subject to Google’s Privacy Policy
and Terms of Service. - Load Google’s reCAPTCHA widget script (
-
Does MIS Webform include AI features?
-
The free version does not – it’s a complete, standalone form builder with no external account or
service required. An AI Form Generator is available in MIS Webform Pro,
which is documented separately since it involves a connected account and third-party AI service. -
What happens to my data if I uninstall the plugin?
-
Your forms and submissions are kept by default, even if you delete the plugin – deactivating
never touches your data, and deleting it only removes the plugin’s files unless you’ve
explicitly opted in to full cleanup. If you do want your forms and submissions removed when you
delete the plugin, check MIS Webform Settings “Delete all MIS Webform forms and submissions when
uninstalling” before deleting it. This is off by default specifically so you don’t lose
customer/contact data by accident.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“MIS Webform” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “MIS Webform” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.1
- Fixed: the custom database tables used DATETIME DEFAULT CURRENT_TIMESTAMP
(and, on one column, ON UPDATE CURRENT_TIMESTAMP), which isn’t supported
on all MySQL/MariaDB versions.
1.0.0
- Initial release.