{"id":356522,"date":"2026-09-05T21:00:18","date_gmt":"2026-09-05T21:00:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ozy-forms\/"},"modified":"2026-09-05T20:59:55","modified_gmt":"2026-09-05T20:59:55","slug":"ozy-forms","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ozy-forms\/","author":23508772,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.9","stable_tag":"1.0.9","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"OZY Forms","header_author":"Danish Rangaiz","header_description":"Drag-and-drop form builder with conditional logic, multi-step forms, payments, built-in SMTP, AI form generation and one-click migration from every major form plugin.","assets_banners_color":"060709","last_updated":"2026-09-05 20:59:55","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/idanishrangaiz.vercel.app\/","header_author_uri":"https:\/\/ozysolutions.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.9":{"tag":"1.0.9","author":"idanishrangaiz","date":"2026-09-05 20:59:55","revision":3682809}},"upgrade_notice":{"1.0.9":"<p>Fixes three faults that only appear once a form has been used: the Entries screen went blank, email smart tags were delivered as literal text, and successful front-end submissions could report failure. Update before putting a form live.<\/p>","1.0.6":"<p>AI features use the WordPress 7.0 AI Client when a connector is configured. The per-form custom CSS box has been removed; move any rules you had there into the Customizer\u2019s Additional CSS or your theme.<\/p>","1.0.5":"<p>Compatible with WordPress 7.1, where the editor is always iframed and no longer inherits front-end styles. The admin screens also use the full window width.<\/p>","1.0.4":"<p>Most field types could not be configured and the Email &amp; SMTP screen went blank when a provider was chosen. Both are fixed, along with analytics counting nothing but submissions. This release also renames every stored option and table from <code>of_<\/code> to <code>ozyf_<\/code>; existing data is not migrated, so deactivate and reactivate after updating.<\/p>","1.0.3":"<p>Critical fix. Forms could not be displayed at all in 1.0.2 and earlier; every page containing one returned a critical error. Update immediately.<\/p>","1.0.2":"<p>Brand colours applied. Existing forms keep their current design; only new forms use the OZY Default preset.<\/p>","1.0.1":"<p>Fixes admin screens that never finished loading. Clear any page or CDN cache after updating.<\/p>","1.0.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3682808,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3682808,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3682808,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3682808,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":{"ozy-forms\/form":{"$schema":"https:\/\/schemas.wp.org\/trunk\/block.json","apiVersion":3,"name":"ozy-forms\/form","title":"OZY Form","category":"widgets","icon":"feedback","description":"Place a form built with OZY Forms.","keywords":["form","contact","ozy"],"textdomain":"ozy-forms","supports":{"html":false,"align":["wide","full"],"spacing":{"margin":true,"padding":true}},"attributes":{"formId":{"type":"number","default":0},"showTitle":{"type":"boolean","default":false},"showDescription":{"type":"boolean","default":false}},"editorScript":"file:.\/index.js","style":"ozy-forms"}},"tagged_versions":["1.0.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3682808,"resolution":"1","location":"assets","locale":"","width":2880,"height":1800},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3682808,"resolution":"10","location":"assets","locale":"","width":2400,"height":2000},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3682808,"resolution":"2","location":"assets","locale":"","width":2880,"height":1800},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3682808,"resolution":"3","location":"assets","locale":"","width":2400,"height":2000},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3682808,"resolution":"4","location":"assets","locale":"","width":2880,"height":1800},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3682808,"resolution":"5","location":"assets","locale":"","width":2880,"height":1800},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3682808,"resolution":"6","location":"assets","locale":"","width":2880,"height":1800},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3682808,"resolution":"7","location":"assets","locale":"","width":2880,"height":1800},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3682808,"resolution":"8","location":"assets","locale":"","width":2880,"height":1800},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3682808,"resolution":"9","location":"assets","locale":"","width":2880,"height":1800}},"screenshots":{"1":"The form builder: the field library, the canvas, and the settings panel for the selected field.","2":"The forms list, showing each form's storage mode, submission count and shortcode.","3":"A multi-step form on the front end, with the numbered progress indicator.","4":"The AI generator, where a provider is connected before describing the form you want.","5":"The entry list, filtered to one form.","6":"The Data &amp; Privacy tab and the storage consequences dialog.","7":"Email and SMTP setup with delivery diagnostics.","8":"Payment gateway configuration.","9":"The migration screen detecting other form plugins.","10":"A finished form on the front end."}},"plugin_section":[],"plugin_tags":[256804,358,2253,30663,155927],"plugin_category":[],"plugin_contributors":[269519],"plugin_business_model":[],"class_list":["post-356522","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-forms","plugin_tags-contact-form","plugin_tags-form-builder","plugin_tags-multi-step-form","plugin_tags-payment-form","plugin_contributors-idanishrangaiz","plugin_committers-idanishrangaiz"],"banners":{"banner":"https:\/\/ps.w.org\/ozy-forms\/assets\/banner-772x250.png?rev=3682808","banner_2x":"https:\/\/ps.w.org\/ozy-forms\/assets\/banner-1544x500.png?rev=3682808","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ozy-forms\/assets\/icon-128x128.png?rev=3682808","icon_2x":"https:\/\/ps.w.org\/ozy-forms\/assets\/icon-256x256.png?rev=3682808","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-1.png?rev=3682808","caption":"The form builder: the field library, the canvas, and the settings panel for the selected field."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-2.png?rev=3682808","caption":"The forms list, showing each form's storage mode, submission count and shortcode."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-3.png?rev=3682808","caption":"A multi-step form on the front end, with the numbered progress indicator."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-4.png?rev=3682808","caption":"The AI generator, where a provider is connected before describing the form you want."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-5.png?rev=3682808","caption":"The entry list, filtered to one form."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-6.png?rev=3682808","caption":"The Data &amp; Privacy tab and the storage consequences dialog."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-7.png?rev=3682808","caption":"Email and SMTP setup with delivery diagnostics."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-8.png?rev=3682808","caption":"Payment gateway configuration."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-9.png?rev=3682808","caption":"The migration screen detecting other form plugins."},{"src":"https:\/\/ps.w.org\/ozy-forms\/assets\/screenshot-10.png?rev=3682808","caption":"A finished form on the front end."}],"raw_content":"<!--section=description-->\n<p>OZY Forms is a complete form builder for WordPress. Conditional logic, multi-step forms, file uploads, digital signatures, calculations, payments, entry management and integrations are all included \u2014 there is no pro tier, no addon store and no feature locked behind an upgrade prompt.<\/p>\n\n<h4>What it does<\/h4>\n\n<ul>\n<li><strong>Drag and drop builder<\/strong> with 48 field types, from plain text through to signatures, repeaters, calculations and product fields.<\/li>\n<li><strong>Conditional logic<\/strong> with nested AND\/OR groups, 15 operators and 10 actions. Evaluated in the browser for responsiveness and again on the server, which is what actually decides.<\/li>\n<li><strong>Multi-step forms<\/strong> with 8 progress indicator designs, per-step server validation, and Save &amp; Resume.<\/li>\n<li><strong>Calculations<\/strong> using a spreadsheet-style formula language with 14 functions.<\/li>\n<li><strong>Payments<\/strong> through Stripe, PayPal, Razorpay, Square, Mollie or Authorize.Net. Card details are entered into the provider's own iframe and never touch this site.<\/li>\n<li><strong>Built-in SMTP<\/strong> for 11 providers, so a separate mail plugin is not required. Queued delivery, retries with backoff, and a delivery log.<\/li>\n<li><strong>20 email designs<\/strong> plus a template library, autoresponders and conditional routing.<\/li>\n<li><strong>AI features<\/strong> \u2014 generate a form from a description, summarise and tag submissions, find themes across responses, generate email templates. On WordPress 7.0 and later these run through the AI Client in core, so whichever provider you connect once under Settings \u2192 Connectors is the one they use. On older versions, or if no connector is set up, you can save your own key for OpenAI, Anthropic, Groq, Gemini or Mistral instead.<\/li>\n<li><strong>Migration<\/strong> from Gravity Forms, WPForms, Fluent Forms, Formidable, Contact Form 7, Ninja Forms, Forminator and Everest Forms \u2014 read-only, with a preview and a full undo.<\/li>\n<li><strong>30 integrations<\/strong> including Zapier, Make, Mailchimp, HubSpot, Google Sheets, Airtable, Notion, Slack, Discord, Telegram, Twilio, Trello, Asana, ClickUp, monday.com, Salesforce, Zoho, Pipedrive and generic webhooks.<\/li>\n<li><strong>Page builders<\/strong> \u2014 Gutenberg block, Elementor, Divi, WPBakery, Beaver Builder, Oxygen, Bricks, Avada, Brizy, plus a shortcode and a classic widget.<\/li>\n<\/ul>\n\n<h4>You decide what gets stored<\/h4>\n\n<p>Most form plugins save every submission to your database and never mention it. OZY Forms tells you what it keeps, per form, and lets you change it.<\/p>\n\n<p>New forms store submissions, so the entry list, exports, analytics and AI insights all work immediately. Any form can be switched to <strong>email-only<\/strong> or <strong>metadata-only<\/strong> in its Data &amp; Privacy tab \u2014 and before that change is applied, the plugin shows you exactly which features it turns off, which ones keep working, and confirms that existing entries are untouched and the change is reversible.<\/p>\n\n<p>Alongside that, each form controls whether IP addresses are stored at all (off, hashed, or full \u2014 hashed by default), whether browser and referrer details are kept, and whether entries are deleted or anonymised automatically after a set number of days. The plugin also contributes accurate text to your site's privacy policy draft, generated from how your forms are actually configured rather than a fixed claim.<\/p>\n\n<h4>Privacy and external services<\/h4>\n\n<p>Out of the box, OZY Forms contacts nothing. Every external service listed below is opt-in and requires you to supply your own credentials. There is no telemetry, no phone-home and no tracking of any kind.<\/p>\n\n<h3>External Services<\/h3>\n\n<p>OZY Forms contacts nothing on its own. It has no telemetry, no phone-home, no analytics call-back and no tracking of any kind. Every service listed below is optional: it is contacted only after you have entered your own credentials for it and switched it on, and only for the purpose described next to it. If you configure none of them, this plugin makes no outbound requests at all.<\/p>\n\n<h4>AI providers<\/h4>\n\n<p>On WordPress 7.0 and later the AI features prefer the AI Client built into WordPress. In that case this plugin sends the request to core, and core sends it to whichever provider you configured under Settings \u2192 Connectors; the terms and privacy policy of that provider apply, and no credentials are stored by this plugin. The providers below are the fallback, used only when you enable an AI feature and save your own API key for one of them. What is sent: the prompt you type when generating a form or an email template, and the stored field values of the entries you ask it to summarise, tag or analyse. Sent when you press the relevant button in the admin, or on submission if you turn on AI spam checking.<\/p>\n\n<ul>\n<li>OpenAI - api.openai.com - <a href=\"https:\/\/openai.com\/policies\/terms-of-use\/\">Terms<\/a> - <a href=\"https:\/\/openai.com\/policies\/privacy-policy\/\">Privacy<\/a><\/li>\n<li>Anthropic - api.anthropic.com - <a href=\"https:\/\/www.anthropic.com\/legal\/consumer-terms\">Terms<\/a> - <a href=\"https:\/\/www.anthropic.com\/legal\/privacy\">Privacy<\/a><\/li>\n<li>Groq - api.groq.com - <a href=\"https:\/\/groq.com\/terms-of-use\/\">Terms<\/a> - <a href=\"https:\/\/groq.com\/privacy-policy\/\">Privacy<\/a><\/li>\n<li>Google Gemini - generativelanguage.googleapis.com - <a href=\"https:\/\/developers.google.com\/terms\">Terms<\/a> - <a href=\"https:\/\/policies.google.com\/privacy\">Privacy<\/a><\/li>\n<li>Mistral - api.mistral.ai - <a href=\"https:\/\/mistral.ai\/terms\/\">Terms<\/a> - <a href=\"https:\/\/mistral.ai\/terms\/#privacy-policy\">Privacy<\/a><\/li>\n<\/ul>\n\n<h4>Payment gateways<\/h4>\n\n<p>Used only when a form contains a payment field and you have saved that gateway's keys. Card details are entered inside the provider's own iframe or SDK and go straight from the visitor's browser to the provider; this site never receives them. What this site sends: the amount, the currency, the payment token returned by the provider, and the billing name and email if your form collects them. Sent when a form with a payment field is submitted.<\/p>\n\n<ul>\n<li>Stripe - api.stripe.com - <a href=\"https:\/\/stripe.com\/legal\/ssa\">Terms<\/a> - <a href=\"https:\/\/stripe.com\/privacy\">Privacy<\/a><\/li>\n<li>PayPal - api-m.paypal.com - <a href=\"https:\/\/www.paypal.com\/legalhub\/useragreement-full\">Terms<\/a> - <a href=\"https:\/\/www.paypal.com\/legalhub\/privacy-full\">Privacy<\/a><\/li>\n<li>Razorpay - api.razorpay.com - <a href=\"https:\/\/razorpay.com\/terms\/\">Terms<\/a> - <a href=\"https:\/\/razorpay.com\/privacy\/\">Privacy<\/a><\/li>\n<li>Square - connect.squareup.com - <a href=\"https:\/\/squareup.com\/legal\/general\/ua\">Terms<\/a> - <a href=\"https:\/\/squareup.com\/legal\/general\/privacy\">Privacy<\/a><\/li>\n<li>Mollie - api.mollie.com - <a href=\"https:\/\/www.mollie.com\/en\/user-agreement\">Terms<\/a> - <a href=\"https:\/\/www.mollie.com\/en\/privacy\">Privacy<\/a><\/li>\n<li>Authorize.Net - api.authorize.net - <a href=\"https:\/\/www.authorize.net\/about-us\/terms\/\">Terms<\/a> - <a href=\"https:\/\/www.authorize.net\/about-us\/privacy\/\">Privacy<\/a><\/li>\n<\/ul>\n\n<h4>Email delivery (SMTP)<\/h4>\n\n<p>Used only when you switch the built-in SMTP on and pick a provider. What is sent: the notification, autoresponder or test email your site produces, which means the recipient addresses, the subject, the message body and any attachments you have configured, delivered over an authenticated SMTP connection using the credentials you entered. Sent when the plugin sends an email.<\/p>\n\n<ul>\n<li>Gmail \/ Google Workspace - smtp.gmail.com - <a href=\"https:\/\/policies.google.com\/terms\">Terms<\/a> - <a href=\"https:\/\/policies.google.com\/privacy\">Privacy<\/a><\/li>\n<li>Outlook \/ Microsoft 365 - smtp.office365.com - <a href=\"https:\/\/www.microsoft.com\/servicesagreement\">Terms<\/a> - <a href=\"https:\/\/privacy.microsoft.com\/privacystatement\">Privacy<\/a><\/li>\n<li>SendGrid (Twilio) - smtp.sendgrid.net - <a href=\"https:\/\/www.twilio.com\/legal\/tos\">Terms<\/a> - <a href=\"https:\/\/www.twilio.com\/legal\/privacy\">Privacy<\/a><\/li>\n<li>Mailgun - smtp.mailgun.org or smtp.eu.mailgun.org - <a href=\"https:\/\/www.mailgun.com\/legal\/terms\/\">Terms<\/a> - <a href=\"https:\/\/www.mailgun.com\/legal\/privacy-policy\/\">Privacy<\/a><\/li>\n<li>Amazon SES - email-smtp.REGION.amazonaws.com - <a href=\"https:\/\/aws.amazon.com\/service-terms\/\">Terms<\/a> - <a href=\"https:\/\/aws.amazon.com\/privacy\/\">Privacy<\/a><\/li>\n<li>Postmark - smtp.postmarkapp.com - <a href=\"https:\/\/postmarkapp.com\/terms-of-service\">Terms<\/a> - <a href=\"https:\/\/postmarkapp.com\/privacy-policy\">Privacy<\/a><\/li>\n<li>Brevo - smtp-relay.brevo.com - <a href=\"https:\/\/www.brevo.com\/legal\/termsofuse\/\">Terms<\/a> - <a href=\"https:\/\/www.brevo.com\/legal\/privacypolicy\/\">Privacy<\/a><\/li>\n<li>Elastic Email - smtp.elasticemail.com - <a href=\"https:\/\/elasticemail.com\/resources\/usage-policies\/terms-of-use\/\">Terms<\/a> - <a href=\"https:\/\/elasticemail.com\/resources\/usage-policies\/privacy-policy\/\">Privacy<\/a><\/li>\n<li>Mailjet - in-v3.mailjet.com - <a href=\"https:\/\/www.mailjet.com\/legal\/terms\/\">Terms<\/a> - <a href=\"https:\/\/www.mailjet.com\/legal\/privacy-policy\/\">Privacy<\/a><\/li>\n<li>SMTP2GO - mail.smtp2go.com - <a href=\"https:\/\/www.smtp2go.com\/terms\/\">Terms<\/a> - <a href=\"https:\/\/www.smtp2go.com\/privacy\/\">Privacy<\/a><\/li>\n<li>Custom SMTP - the host you enter yourself. The terms and privacy policy of that host's operator apply.<\/li>\n<\/ul>\n\n<h4>Integrations<\/h4>\n\n<p>Used only for a service you connect with your own credentials and then enable on a specific form. What is sent: the submitted field values you map to that service's fields, plus the form name and the submission time. Sent when a submission on that form succeeds.<\/p>\n\n<ul>\n<li>Zapier - hooks.zapier.com, at the Zap webhook URL you paste in - <a href=\"https:\/\/zapier.com\/legal\/terms-of-service\">Terms<\/a> - <a href=\"https:\/\/zapier.com\/privacy\">Privacy<\/a><\/li>\n<li>Make - the Make webhook URL you paste in - <a href=\"https:\/\/www.make.com\/en\/terms-and-conditions\">Terms<\/a> - <a href=\"https:\/\/www.make.com\/en\/privacy-notice\">Privacy<\/a><\/li>\n<li>Mailchimp - your data centre host at api.mailchimp.com - <a href=\"https:\/\/mailchimp.com\/legal\/terms\/\">Terms<\/a> - <a href=\"https:\/\/www.intuit.com\/privacy\/statement\/\">Privacy<\/a><\/li>\n<li>ActiveCampaign - the account API URL you enter - <a href=\"https:\/\/www.activecampaign.com\/legal\/terms-of-service\">Terms<\/a> - <a href=\"https:\/\/www.activecampaign.com\/legal\/privacy-policy\">Privacy<\/a><\/li>\n<li>HubSpot - api.hubapi.com - <a href=\"https:\/\/legal.hubspot.com\/terms-of-service\">Terms<\/a> - <a href=\"https:\/\/legal.hubspot.com\/privacy-policy\">Privacy<\/a><\/li>\n<li>MailerLite - connect.mailerlite.com - <a href=\"https:\/\/www.mailerlite.com\/legal\/terms-of-service\">Terms<\/a> - <a href=\"https:\/\/www.mailerlite.com\/legal\/privacy-policy\">Privacy<\/a><\/li>\n<li>Brevo - api.brevo.com - <a href=\"https:\/\/www.brevo.com\/legal\/termsofuse\/\">Terms<\/a> - <a href=\"https:\/\/www.brevo.com\/legal\/privacypolicy\/\">Privacy<\/a><\/li>\n<li>Constant Contact - api.cc.email - <a href=\"https:\/\/www.constantcontact.com\/legal\/terms\">Terms<\/a> - <a href=\"https:\/\/www.constantcontact.com\/legal\/privacy-notice\">Privacy<\/a><\/li>\n<li>GetResponse - api.getresponse.com - <a href=\"https:\/\/www.getresponse.com\/legal\">Terms<\/a> - <a href=\"https:\/\/www.getresponse.com\/legal\/privacy\">Privacy<\/a><\/li>\n<li>Drip - api.getdrip.com - <a href=\"https:\/\/www.drip.com\/terms\">Terms<\/a> - <a href=\"https:\/\/www.drip.com\/privacy\">Privacy<\/a><\/li>\n<li>Kit (formerly ConvertKit) - api.convertkit.com - <a href=\"https:\/\/kit.com\/terms\">Terms<\/a> - <a href=\"https:\/\/kit.com\/privacy\">Privacy<\/a><\/li>\n<li>Google Sheets - sheets.googleapis.com and oauth2.googleapis.com - <a href=\"https:\/\/policies.google.com\/terms\">Terms<\/a> - <a href=\"https:\/\/policies.google.com\/privacy\">Privacy<\/a><\/li>\n<li>Airtable - api.airtable.com - <a href=\"https:\/\/www.airtable.com\/company\/tos\">Terms<\/a> - <a href=\"https:\/\/www.airtable.com\/company\/privacy\">Privacy<\/a><\/li>\n<li>Notion - api.notion.com - <a href=\"https:\/\/www.notion.com\/terms\">Terms<\/a> - <a href=\"https:\/\/www.notion.so\/notion\/Privacy-Policy-3468d120cf614d4c9014c09f6adc9091\">Privacy<\/a><\/li>\n<li>Slack - the incoming webhook URL you paste in - <a href=\"https:\/\/slack.com\/terms-of-service\">Terms<\/a> - <a href=\"https:\/\/slack.com\/trust\/privacy\/privacy-policy\">Privacy<\/a><\/li>\n<li>Discord - the webhook URL you paste in - <a href=\"https:\/\/discord.com\/terms\">Terms<\/a> - <a href=\"https:\/\/discord.com\/privacy\">Privacy<\/a><\/li>\n<li>Telegram - api.telegram.org - <a href=\"https:\/\/telegram.org\/tos\">Terms<\/a> - <a href=\"https:\/\/telegram.org\/privacy\">Privacy<\/a><\/li>\n<li>Twilio - api.twilio.com - <a href=\"https:\/\/www.twilio.com\/legal\/tos\">Terms<\/a> - <a href=\"https:\/\/www.twilio.com\/legal\/privacy\">Privacy<\/a><\/li>\n<li>MessageBird (Bird) - rest.messagebird.com - <a href=\"https:\/\/www.bird.com\/legal\/terms\">Terms<\/a> - <a href=\"https:\/\/www.bird.com\/legal\/privacy\">Privacy<\/a><\/li>\n<li>Vonage - rest.nexmo.com - <a href=\"https:\/\/www.vonage.com\/legal\/communications-apis\/terms-of-use\/\">Terms<\/a> - <a href=\"https:\/\/www.vonage.com\/legal\/privacy-policy\/\">Privacy<\/a><\/li>\n<li>Trello - api.trello.com - <a href=\"https:\/\/www.atlassian.com\/legal\/cloud-terms-of-service\">Terms<\/a> - <a href=\"https:\/\/www.atlassian.com\/legal\/privacy-policy\">Privacy<\/a><\/li>\n<li>Asana - app.asana.com - <a href=\"https:\/\/asana.com\/terms\">Terms<\/a> - <a href=\"https:\/\/asana.com\/terms#privacy-policy\">Privacy<\/a><\/li>\n<li>ClickUp - api.clickup.com - <a href=\"https:\/\/clickup.com\/terms\">Terms<\/a> - <a href=\"https:\/\/clickup.com\/privacy\">Privacy<\/a><\/li>\n<li>monday.com - api.monday.com - <a href=\"https:\/\/monday.com\/l\/legal\/tos\/\">Terms<\/a> - <a href=\"https:\/\/monday.com\/l\/privacy\/privacy-policy\/\">Privacy<\/a><\/li>\n<li>Salesforce - the instance URL you enter - <a href=\"https:\/\/www.salesforce.com\/company\/legal\/agreements\/\">Terms<\/a> - <a href=\"https:\/\/www.salesforce.com\/company\/privacy\/\">Privacy<\/a><\/li>\n<li>Zoho CRM - the API domain you enter - <a href=\"https:\/\/www.zoho.com\/terms.html\">Terms<\/a> - <a href=\"https:\/\/www.zoho.com\/privacy.html\">Privacy<\/a><\/li>\n<li>Pipedrive - your company subdomain at pipedrive.com - <a href=\"https:\/\/www.pipedrive.com\/en\/terms-of-service\">Terms<\/a> - <a href=\"https:\/\/www.pipedrive.com\/en\/privacy\">Privacy<\/a><\/li>\n<li>Freshsales - the Freshworks domain you enter - <a href=\"https:\/\/www.freshworks.com\/terms\/\">Terms<\/a> - <a href=\"https:\/\/www.freshworks.com\/privacy\/\">Privacy<\/a><\/li>\n<li>Webhook and Custom API - the URL you enter yourself. Nothing is sent anywhere else; the terms and privacy policy of whatever endpoint you point it at apply.<\/li>\n<\/ul>\n\n<h4>Spam protection<\/h4>\n\n<p>Used only after you save that service's keys under OZY Forms \u2192 Settings and a form actually uses it.<\/p>\n\n<p>A CAPTCHA has two halves. The provider's widget script is loaded into the visitor's browser from the provider's own domain, which is how the challenge is drawn and is also a request that tells the provider a page was viewed. The token it produces is then posted from this site to the provider's verification endpoint, together with your secret key, when the form is submitted. Nothing else about the submission is sent.<\/p>\n\n<ul>\n<li>Google reCAPTCHA - script from www.google.com\/recaptcha\/api.js, verified at www.google.com\/recaptcha\/api\/siteverify - <a href=\"https:\/\/policies.google.com\/terms\">Terms<\/a> - <a href=\"https:\/\/policies.google.com\/privacy\">Privacy<\/a><\/li>\n<li>hCaptcha - script from js.hcaptcha.com\/1\/api.js, verified at api.hcaptcha.com\/siteverify - <a href=\"https:\/\/www.hcaptcha.com\/terms\">Terms<\/a> - <a href=\"https:\/\/www.hcaptcha.com\/privacy\">Privacy<\/a><\/li>\n<li>Cloudflare Turnstile - script from challenges.cloudflare.com\/turnstile\/v0\/api.js, verified at challenges.cloudflare.com\/turnstile\/v0\/siteverify - <a href=\"https:\/\/www.cloudflare.com\/website-terms\/\">Terms<\/a> - <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">Privacy<\/a><\/li>\n<\/ul>\n\n<p>Akismet is checked from this site only, with no browser-side component. What is sent: the submitted field values, the visitor's IP address, user agent and referrer, and your site address. Sent when a form is submitted, and once more when you save the key so it can be confirmed.<\/p>\n\n<ul>\n<li>Akismet - rest.akismet.com - <a href=\"https:\/\/automattic.com\/terms\/\">Terms<\/a> - <a href=\"https:\/\/automattic.com\/privacy\/\">Privacy<\/a><\/li>\n<\/ul>\n\n<p>The default anti-spam layer is a honeypot field and a local maths question. Neither contacts anything, and a form falls back to the maths question whenever the chosen CAPTCHA provider has no keys saved.<\/p>\n\n<h4>Scripts loaded into the visitor's browser<\/h4>\n\n<p>Two features need code served by the provider rather than by this site, because the provider will not accept data collected any other way. They load only on a page carrying a form that uses them.<\/p>\n\n<ul>\n<li>Payment gateways load their card entry SDK: js.stripe.com, www.paypal.com\/sdk\/js, checkout.razorpay.com, web.squarecdn.com (sandbox.web.squarecdn.com in test mode) and js.authorize.net (jstest.authorize.net in test mode). The terms and privacy policies are the ones listed under Payment gateways above.<\/li>\n<li>CAPTCHA providers load their widget script, listed under Spam protection above.<\/li>\n<\/ul>\n\n<p>Nothing else in this plugin loads code from anywhere but your own site.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/ozy-forms<\/code>, or install it through Plugins \u2192 Add New.<\/li>\n<li>Activate it.<\/li>\n<li>Go to OZY Forms \u2192 Add New, pick a template or start blank, and save.<\/li>\n<li>Place the form with the block, the <code>[ozy_form id=\"1\"]<\/code> shortcode, or your page builder's OZY Form element.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20separate%20smtp%20plugin%3F\"><h3>Do I need a separate SMTP plugin?<\/h3><\/dt>\n<dd><p>No. Email delivery for 11 providers is built in, under Email &amp; SMTP. If you already run WP Mail SMTP or FluentSMTP, leave OZY Forms' SMTP switched off and your existing setup keeps working \u2014 the plugin will even warn you if it detects a competing mail plugin.<\/p><\/dd>\n<dt id=\"are%20submissions%20saved%20to%20my%20database%3F\"><h3>Are submissions saved to my database?<\/h3><\/dt>\n<dd><p>By default, yes, so the entry list, exports and analytics work straight away. Every form has a Data &amp; Privacy tab where you can switch it to email-only or metadata-only. Before that takes effect you are shown exactly which features stop working.<\/p><\/dd>\n<dt id=\"does%20anything%20get%20sent%20to%20your%20servers%3F\"><h3>Does anything get sent to your servers?<\/h3><\/dt>\n<dd><p>No. There is no telemetry and no phone-home. The only outbound requests are to services you configure yourself, listed above.<\/p><\/dd>\n<dt id=\"can%20i%20move%20away%20later%3F\"><h3>Can I move away later?<\/h3><\/dt>\n<dd><p>Yes. Tools \u2192 Export produces your forms as JSON, and a Contact Form 7 template for the fields that format supports.<\/p><\/dd>\n<dt id=\"are%20card%20details%20stored%20on%20my%20site%3F\"><h3>Are card details stored on my site?<\/h3><\/dt>\n<dd><p>No. Card entry happens inside the payment provider's own iframe or SDK. This plugin only handles the resulting token and stores a transaction reference, amount, currency and status.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>Fixed a crash that blanked the Entries screen. The list rendered each entry's preview, which the search endpoint returns as a set of value rows, as if it were a string; React refused it and took the whole screen down. Any site with at least one stored submission hit this. The preview is now joined into a readable line.<\/li>\n<li>Email smart tags such as {field_3} resolve again. The field lookup they read was built with wp_list_pluck() and a null field, which returns a row of nulls rather than the fields themselves, so every tag fell through and was delivered as literal text. The same call broke CSV entry import, which skipped every mapped column.<\/li>\n<li>Front-end submissions no longer report failure when they have in fact succeeded. The lookup above also emitted PHP warnings, and on a site that displays errors those were printed ahead of the JSON response, so the browser could not parse the reply and showed the validation error instead.<\/li>\n<li>Choice, lookup and product fields no longer pass null to strlen(), deprecated since PHP 8.1. The same pattern was corrected in CSV import and in the conditional logic evaluator.<\/li>\n<li>The Analytics screen no longer requests form_id=0 before the form list has loaded, which answered 404 on every visit.<\/li>\n<li>Removed a stray <code>aria<\/code> prop on number settings that React warned about.<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>Corrected four dead links in the External Services list. Constant Contact's terms moved to \/legal\/terms, GetResponse's terms are served from \/legal, and Notion's terms and privacy policy are now linked at their current addresses. Every link in the readme was checked with a request, not by eye.<\/li>\n<li>The entries shortcode now passes each field value through wp_kses_post() before it is returned, so the value is escaped at the point of output rather than relying on the field type that produced it.<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>CAPTCHA now works end to end. Site and secret keys have a place to be entered, under Settings \u2192 Spam protection keys; the provider's widget script is loaded on pages that render the field; and the token is verified with the provider before a submission is accepted. reCAPTCHA v2 and v3, hCaptcha and Cloudflare Turnstile are supported. Previously the field always fell back to the maths question because there was nowhere to save keys.<\/li>\n<li>The site-wide CAPTCHA choice now matches the values the field understands, so picking a provider on the settings screen has an effect.<\/li>\n<li>Akismet checking is implemented. The key is entered on the same screen and confirmed with Akismet before it is stored, and submissions are checked before they are stored, ahead of the AI classifier.<\/li>\n<li>The readme now names the scripts a page loads from a payment or CAPTCHA provider, separately from the endpoints this site calls itself.<\/li>\n<li>Added a Plugin URI to the plugin header.<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>AI features now go through the AI Client in WordPress 7.0 when a connector is set up, so the provider and its credentials are chosen once at site level and shared by every plugin. Saving a key directly for OpenAI, Anthropic, Groq, Gemini or Mistral still works, and is what older WordPress versions use.<\/li>\n<li>Removed the per-form custom CSS box. WordPress has its own CSS editor in the Customizer and the Site Editor, and the directory no longer allows plugins to store arbitrary CSS.<\/li>\n<li>A form\u2019s generated design CSS is now enqueued through wp_add_inline_style() instead of being printed as a style tag next to the form.<\/li>\n<li>The behaviour metadata a form passes to the front-end script moved from an inline JSON script tag to a data attribute.<\/li>\n<li>Analytics events now carry the form nonce and are rejected without it.<\/li>\n<li>Uploaded file names and MIME types are sanitised as they are read, before anything else looks at them.<\/li>\n<li>Every REST route names its permission callback inline, so what guards each endpoint is readable at the point of registration.<\/li>\n<li>The readme now lists the terms and privacy policy of every external service, one by one.<\/li>\n<li>The author URI points at ozysolutions.com.<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Tested against WordPress 7.1.<\/li>\n<li>The block preview now carries the form stylesheet. WordPress 7.1 always serves the post editor inside an iframe, which no longer inherits front-end styles, so the stylesheet is declared on the block itself.<\/li>\n<li>The AI Generator uses the full screen. On a wide display the composer and the provider keys sit side by side instead of stacking in a narrow column.<\/li>\n<li>The settings screen fills the width, laying the groups out in columns instead of one long strip.<\/li>\n<li>The Email &amp; SMTP screen puts the sending provider and the test message next to each other.<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>Rebuilt the field settings panel. It now renders the settings each field type declares, so the colour picker, image and icon choices, rating, slider, option scale, signature, repeater, field group, hidden, lookup, post, chained dropdowns, calculation, payment, total, product, HTML, heading, section and page break fields all have their own controls instead of the same four generic ones.<\/li>\n<li>Added an options editor that carries per option images, icons, prices and default selections, with the WordPress media library behind the image picker.<\/li>\n<li>Added nested field editing for the repeater and field group, level and dataset editing for chained dropdowns, and a data source picker for hidden fields.<\/li>\n<li>Fixed the white screen on the Email &amp; SMTP screen. Choosing a provider tried to render its setup guidance, which is a structured object, as plain text and took React down with it.<\/li>\n<li>Fixed the choice list appearing on fields that have no choices, such as the option scale and the slider.<\/li>\n<li>Fixed analytics reporting zero views, starts, conversion, completion and abandonment. Views are now recorded when a form is rendered and the page reports starts, field activity, submissions and errors back.<\/li>\n<li>Added the front-end behaviour several fields were rendering markup for but never received: signature drawing, the slider readout, the rating readout, repeater rows, chained dropdown refills, searchable dropdowns, colour swatches, quantity steppers, the password reveal and strength meter, the character counter, input masks and upload drag and drop.<\/li>\n<li>Fixed the colour picker ignoring the required rule. A native colour input always reports a value, so an untouched field now stays genuinely empty.<\/li>\n<li>Added image and logo selection, alternative text, sizing and divider colour to the email template blocks.<\/li>\n<li>Fixed a page break at the end of a form producing an empty final step.<\/li>\n<li>Options, transients, tables and request keys moved from the <code>of_<\/code> prefix to <code>ozyf_<\/code>. <code>of_<\/code> is short enough to belong to something else on the same site. Stored data does not carry over, so deactivate and reactivate after updating.<\/li>\n<li>Translations load through WordPress instead of load_plugin_textdomain(), which fired too early to be useful.<\/li>\n<li>Every directory carries an index.php, so a server with directory listing enabled cannot enumerate the plugin.<\/li>\n<li>The bundled translation template was several releases out of date and now covers every string.<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Fixed the fatal error that broke every page holding a form. Form_Renderer called a method that was never written, so the shortcode, the block, the widget and every page builder element crashed with \"There has been a critical error on this website\".<\/li>\n<li>Wired the shortcode's ajax attribute through to the renderer.<\/li>\n<li>Removed a byte order mark from readme.txt.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Replaced the blue accent throughout the admin screens with the OZY Solutions palette.<\/li>\n<li>Added the \"OZY Default\" colour preset and made it the default for new forms.<\/li>\n<li>Front-end forms now start from the brand palette instead of the old blue.<\/li>\n<li>Rebuilt the settings screen as aligned rows with an explanation under every option, and replaced the checkboxes with toggles.<\/li>\n<li>Fixed the privacy, honeypot and credit-line defaults, which were shown on the settings screen but never applied to new forms.<\/li>\n<li>Removed the \"Analyse entries automatically\" option, which had no implementation behind it.<\/li>\n<li>Added a settings reference to the documentation.<\/li>\n<li>Added AI provider key management, so Groq, Gemini, Mistral, OpenAI and Anthropic keys can be entered, tested and removed from the AI Generator screen.<\/li>\n<li>Added an Email Templates screen exposing the twenty shipped templates with live previews.<\/li>\n<li>Added a block based builder for custom email templates.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Built the entries, templates, AI generator, analytics, email, payments, integrations, migration, settings and help screens.<\/li>\n<li>Added settings, analytics, email, payment and integration REST routes, including credential entry for gateways, services and SMTP providers.<\/li>\n<li>Fixed admin requests losing the ozy-forms\/v1 namespace, which made every screen load forever.<\/li>\n<li>Failed requests now report the reason instead of leaving a screen on \"Loading\".<\/li>\n<li>Scripts and styles are versioned by file modification time so updates are not served from cache.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<\/ul>","raw_excerpt":"Drag and drop form builder with conditional logic, multi-step forms, payments, built-in SMTP, AI form generation and one-click migration.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/356522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=356522"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/idanishrangaiz"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=356522"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=356522"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=356522"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=356522"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=356522"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=356522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}