Title: Quarivo Form Shield
Author: 菅原隆志
Published: <strong>August 12, 2026</strong>
Last modified: August 12, 2026

---

Search plugins

![](https://ps.w.org/quarivo-form-shield/assets/banner-772x250.png?rev=3642921)

![](https://ps.w.org/quarivo-form-shield/assets/icon-256x256.png?rev=3642921)

# Quarivo Form Shield

 By [菅原隆志](https://profiles.wordpress.org/taka235345/)

[Download](https://downloads.wordpress.org/plugin/quarivo-form-shield.1.0.1.zip)

 * [Details](https://wordpress.org/plugins/quarivo-form-shield/#description)
 * [Reviews](https://wordpress.org/plugins/quarivo-form-shield/#reviews)
 *  [Installation](https://wordpress.org/plugins/quarivo-form-shield/#installation)
 * [Development](https://wordpress.org/plugins/quarivo-form-shield/#developers)

 [Support](https://wordpress.org/support/plugin/quarivo-form-shield/)

## Description

Quarivo Form Shield adds an independent, local inbox for Contact Form 7. It stores
a reviewable record before Contact Form 7 attempts email, so a local mail error 
does not make the original inquiry disappear.

#### The important distinction

WordPress can report that its mail method processed a request without an error. 
That is not a mailbox delivery receipt. Quarivo Form Shield therefore shows **Mail
handoff accepted — delivery not verified** separately from a mail error, skipped
spam mail, and mail that was not attempted.

#### Conservative spam handling

 * Balanced mode is the default and treats every language equally.
 * Japanese-site enhanced and Strict Japanese modes are explicit administrator choices.
 * One URL, one foreign-language message, missing JavaScript, or a public email 
   address does not cause automatic quarantine by itself.
 * Compound signals include URL/link structure, a honeypot, browser-observed timing,
   local rate evidence, repeated promotion structure, executable markup, and bounded
   local moderator feedback.
 * Only high-confidence Quarivo results are quietly quarantined. Lower evidence 
   stays visible as **Needs review** and ordinary mail remains available.
 * Akismet, reCAPTCHA, Cloudflare Turnstile, Flamingo, and other Contact Form 7 
   decisions are not disabled or overwritten. An existing spam result remains spam.
 * No message is automatically deleted.

#### Local inbox

The responsive WordPress administration inbox provides:

 * All, unread, read, important, normal, needs review, auto-quarantined, spam, mail-
   error, and invalid counts.
 * Search, form filtering, 25/50/100-row pagination, and bounded per-page bulk actions.
 * Full submitted fields, source form/page, sender information, score/reasons, Contact
   Form 7 status, and mail-processing status.
 * Reversible normal/review/spam decisions and local learning from explicit moderator
   choices.
 * A deliberate plain-text resend to the validated site administrator address. Submitted
   data is never reused as an email header and attachments are not automatically
   resent.
 * Private JSON and formula-safe CSV export.

#### Failure-safe storage

The first database insert occurs before validation, spam handling, upload processing,
and email. Later Contact Form 7 hooks enrich the same unique row, preventing duplicate
records from one request.

If a database write fails, Quarivo retries before mail, writes an authenticated-
encrypted local recovery record, shows an administrator health warning, and processes
a small recovery batch when the database becomes available. The original mail path
is left available. A simultaneous database, private-filesystem, and mail outage 
cannot be made loss-free by an in-process plugin; Quarivo reports that failure instead
of silently claiming success.

#### Protected attachments

Validated Contact Form 7 temporary uploads are copied before Contact Form 7 removes
them. Quarivo enforces a 25 MB default storage limit and stores each file as AES-
256-GCM authenticated ciphertext under a random opaque name in a protected plugin
directory inside the site’s configured WordPress uploads directory. It does not 
create a public attachment URL. A capability and nonce checked administrator request
verifies and decrypts a download. If authenticated encryption or private storage
is unavailable, Quarivo does not retain the attachment and displays a storage warning.

#### Privacy and retention

 * No API key, CAPTCHA, remote request, telemetry, external font, or third-party
   asset is required by Quarivo Form Shield.
 * Password, token, API-key, PIN, CVV, and card-number-like field names are redacted
   automatically. Administrators can add exact excluded field names.
 * Contact Form 7 do-not-store and storage-consent metadata is respected: operational
   metadata may remain, but submitted field values are not copied when the form 
   prohibits storage.
 * Visible IP storage defaults to anonymized. Full IP display is opt-in; a keyed
   local hash supports rate checks.
 * Read, non-important entries and encrypted attachments have separate retention
   controls. Unread and important entries are not removed by scheduled entry retention.
 * WordPress personal-data export and erasure tools include exact sender-email matches.
 * Plugin deletion retains data by default. Permanent removal must first be selected
   in settings and confirmed by typing DELETE.

#### Contact Form 7 dependency

Contact Form 7 is not bundled. If it is absent or inactive, Quarivo Form Shield 
does not cause a fatal error. The existing inbox remains available and a clear administrator
notice explains that new capture is paused.

## Installation

 1. Install and activate Contact Form 7.
 2. Upload the `quarivo-form-shield` folder to `/wp-content/plugins/`, or install its
    ZIP from **Plugins > Add New > Upload Plugin**.
 3. Activate **Quarivo Form Shield**.
 4. Open **Form Shield > Inbox**. Balanced protection and local capture require no 
    API key or external account.
 5. Review **Form Shield > Settings** for retention, field exclusions, and your privacy
    notice.

## FAQ

### Does “mail handoff accepted” mean the inquiry reached the recipient?

No. It means the local WordPress mail method processed the request without reporting
an error. A downstream mail server can still reject, quarantine, delay, or misroute
it. The saved inbox record is the reliable local copy.

### Does the plugin require Flamingo?

No. Quarivo Form Shield has its own tables and inbox. If Flamingo is active, Quarivo
does not change or delete Flamingo records.

### Does it send inquiry data to an AI or external API?

No. Scoring, storage, learning, and review stay on the WordPress site.

### Can I restore a false positive?

Yes. Mark it Normal or Needs review in the inbox. The record is never automatically
deleted, and explicit Normal feedback can slightly reduce matching soft structural
evidence in the future.

### What happens to data when I delete the plugin?

It is retained by default. To remove Quarivo tables, settings, encrypted attachments,
fail-safe files, and learning data during plugin deletion, first open **Form Shield
> Settings**, select permanent deletion, type DELETE, and save. Contact Form 7 forms
and Flamingo data are never deleted by this option.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Quarivo Form Shield” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ 菅原隆志 ](https://profiles.wordpress.org/taka235345/)

[Translate “Quarivo Form Shield” into your language.](https://translate.wordpress.org/projects/wp-plugins/quarivo-form-shield)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/quarivo-form-shield/),
check out the [SVN repository](https://plugins.svn.wordpress.org/quarivo-form-shield/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/quarivo-form-shield/)
by [RSS](https://plugins.trac.wordpress.org/log/quarivo-form-shield/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.1

 * Uses the configured WordPress uploads directory for encrypted private storage
   and fail-safe recovery files.
 * Uses WordPress.org language packs instead of bundled translation files.
 * Limits activation and operational notices to the Plugins screen and Quarivo Form
   Shield screens.

#### 1.0.0

 * First public-review candidate focused on deep Contact Form 7 capture.
 * Adds server-bound request identity, bounded hostile-input processing, guarded
   private-storage roots, attachment memory checks, resend throttling, and concurrency-
   safe fail-safe recovery.
 * Passes the official Plugin Check with no reported errors or warnings.

#### 0.1.0

 * Initial private local-test build.
 * Adds pre-mail inbox persistence, final mail-result tracking, conservative compound
   scoring, protected attachments, encrypted database-failure recovery, privacy 
   tools, retention, review, resend, export, and explicit uninstall controls.

## Meta

 *  Version **1.0.1**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.7 or higher **
 *  Tested up to **7.0.4**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [contact form](https://wordpress.org/plugins/tags/contact-form/)[contact form 7](https://wordpress.org/plugins/tags/contact-form-7/)
   [email](https://wordpress.org/plugins/tags/email/)[inbox](https://wordpress.org/plugins/tags/inbox/)
   [spam](https://wordpress.org/plugins/tags/spam/)
 *  [Advanced View](https://wordpress.org/plugins/quarivo-form-shield/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/quarivo-form-shield/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/quarivo-form-shield/reviews/)

## Contributors

 *   [ 菅原隆志 ](https://profiles.wordpress.org/taka235345/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/quarivo-form-shield/)