{"id":363053,"date":"2026-09-16T18:36:48","date_gmt":"2026-09-16T18:36:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/arvelos-form-monitor\/"},"modified":"2026-09-16T18:36:40","modified_gmt":"2026-09-16T18:36:40","slug":"arvelos-form-monitor","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/arvelos-form-monitor\/","author":23557212,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.0","stable_tag":"0.1.0","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Arvelos Form Monitor","header_author":"Arvelos Software","header_description":"Companion plugin for Arvelos synthetic monitoring of Contact Form 7 forms. Authorizes a single-use synthetic test submission and routes its notification to the Arvelos verification address. Does not circumvent CAPTCHAs and does not contact real recipients for a synthetic run.","assets_banners_color":"","last_updated":"2026-09-16 18:36:40","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/clickarvelos.com\/products\/wordpress-form-monitoring\/","header_author_uri":"https:\/\/clickarvelos.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":75,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.0":{"tag":"0.1.0","author":"arvelos","date":"2026-09-16 18:36:40","revision":3699123}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[5445,1152,601,5603,29148],"plugin_category":[42,54],"plugin_contributors":[281119],"plugin_business_model":[],"class_list":["post-363053","plugin","type-plugin","status-publish","hentry","plugin_tags-cf7","plugin_tags-contact-form-7","plugin_tags-forms","plugin_tags-monitoring","plugin_tags-uptime","plugin_category-contact-forms","plugin_category-security-and-spam-protection","plugin_contributors-arvelos","plugin_committers-arvelos"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/arvelos-form-monitor.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Arvelos Form Monitor is the companion plugin for <strong>Arvelos Form Monitor<\/strong>, a\nhosted service that periodically runs a <strong>controlled synthetic test<\/strong> through\nyour live Contact Form 7 forms and checks that the submission completes. When a\ncheck starts failing you get an email; you get another when it recovers. When\neverything is fine, you hear nothing.<\/p>\n\n<p>This plugin is the small piece that runs on your site. On its own it does not\nmonitor anything \u2014 it authorizes and routes the service's synthetic test so the\ntest never reaches your real recipients and never bypasses your spam\nprotection. Using it requires an Arvelos account to pair with (see <em>External\nservices<\/em> below).<\/p>\n\n<p><strong>What a passing status means:<\/strong> a controlled synthetic test submission was\naccepted by your form and its notification reached a mailbox Arvelos controls\nfor the test.<\/p>\n\n<p><strong>What it does not mean:<\/strong> it does not verify your real inbox and does not\nguarantee delivery of real visitor enquiries. It is a signal from a synthetic\ntest, not a delivery guarantee.<\/p>\n\n<p><strong>Boundaries this plugin respects:<\/strong><\/p>\n\n<ul>\n<li>It only authorizes a submission that carries a valid, unexpired, single-use,\nsite-scoped token issued by the Arvelos service. It never mints tokens itself\nand never authorizes an ordinary visitor submission.<\/li>\n<li>It never circumvents a CAPTCHA (reCAPTCHA, hCaptcha, Turnstile). A form\nprotected by one is reported as unsupported and is not monitored.<\/li>\n<li>A synthetic run's notification is routed to the Arvelos verification address\n(an Arvelos-controlled mailbox) and is never delivered to your real recipients\nas if it were a real enquiry.<\/li>\n<li>It transmits nothing to Arvelos until you pair the site by entering your\nSite ID and secret.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to <strong>Arvelos Form Monitor<\/strong>, a hosted service operated\nby Arvelos Software, so the service can run and confirm the synthetic tests\ndescribed above. The service is what makes the plugin useful; without pairing,\nthe plugin sends nothing.<\/p>\n\n<p>Service endpoint: <code>https:\/\/forms.clickarvelos.com<\/code><\/p>\n\n<p><strong>What is sent to Arvelos, and when \u2014 only after you pair the site:<\/strong><\/p>\n\n<ul>\n<li>When you save your pairing settings, the plugin asks the service to verify\ncontrol of this site. The request contains your <strong>Site ID<\/strong>. The service then\nfetches a public, read-only proof route on your site (below) to confirm the\nplugin is installed here and holds the paired secret.<\/li>\n<li>When you rotate your secret, the plugin sends a signed rotation request\ncontaining your <strong>Site ID<\/strong> and a timestamp.<\/li>\n<li>After a plugin, theme, or WordPress core update completes, the plugin sends a\nsingle debounced, signed \"site updated\" event containing your <strong>Site ID<\/strong> and\na timestamp, so the service can re-test promptly instead of waiting for its\nnext scheduled check.<\/li>\n<\/ul>\n\n<p>The rotation and \"site updated\" requests above are signed with your per-site\nsecret; the initial pairing request is not signed \u2014 instead Arvelos confirms\ncontrol by fetching the public proof route below, which is derived from your\nsecret. The plugin does <strong>not<\/strong> send your form submissions, your visitors' data, or your\nreal recipient addresses to the service. The Arvelos verification address that a\nsynthetic notification is routed to is built into the plugin \u2014 you never enter,\nstore, or manage it, and run correlation uses a per-run single-use code, not the\naddress itself.<\/p>\n\n<p><strong>Public route this plugin exposes:<\/strong> once paired, the plugin serves a read-only\nREST route, <code>GET \/wp-json\/orion-fm\/v1\/pairing<\/code>, that returns a fixed\nproof-of-control value derived from your secret. It exposes no submission data\nand is a 404 until the site is paired.<\/p>\n\n<p>This plugin connects your site to Arvelos Form Monitor, a paid hosted\nservice operated by Arvelos Software. Your use of that service, and the\ndata it handles, are governed by the Arvelos Terms of Service and Privacy\nPolicy, which cover Arvelos Form Monitor specifically:<\/p>\n\n<ul>\n<li>Terms of Service: https:\/\/clickarvelos.com\/terms\/<\/li>\n<li>Privacy Policy: https:\/\/clickarvelos.com\/privacy\/<\/li>\n<\/ul>\n\n<p>The Privacy Policy describes what the service stores (your account email,\nconnected site and form identifiers, alert recipient, billing identifiers\nvia Stripe, and monitoring results) and confirms that your real visitors'\nsubmissions are never sent to or stored by the service.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>This plugin stores your Arvelos pairing details (Site ID, per-site secret) in\nyour site's options table. The secret is never\nexposed to the front end. See <em>External services<\/em> above for exactly what the\nplugin transmits to Arvelos and when, and the linked Privacy Policy for how the\nArvelos service handles data.<\/p>\n\n<h3>Support<\/h3>\n\n<p>Support is by email through Arvelos: https:\/\/clickarvelos.com\/support\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate <strong>Contact Form 7<\/strong> (required).<\/li>\n<li>Install and activate <strong>Arvelos Form Monitor<\/strong>.<\/li>\n<li>Go to <strong>Settings \u2192 Arvelos Form Monitor<\/strong> and enter the pairing details from\nyour Arvelos account: your Site ID and your per-site secret. The Arvelos\nendpoint and the verification address are built in and need no configuration.<\/li>\n<li>Save. The plugin proves control of your site to Arvelos; monitoring stays\noff until that verification succeeds.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20contact%20form%207%20installation%3F\"><h3>Do I need a Contact Form 7 installation?<\/h3><\/dt>\n<dd><p>Yes. Contact Form 7 is required; the plugin will not run without it and will\nshow a notice asking you to install and activate it.<\/p><\/dd>\n<dt id=\"do%20i%20need%20an%20arvelos%20account%3F\"><h3>Do I need an Arvelos account?<\/h3><\/dt>\n<dd><p>Yes. This plugin is the companion to the hosted Arvelos Form Monitor\nservice. You pair it with an Arvelos account; on its own it does not monitor\nyour forms.<\/p><\/dd>\n<dt id=\"will%20my%20real%20visitors%20be%20affected%3F\"><h3>Will my real visitors be affected?<\/h3><\/dt>\n<dd><p>No. The plugin only ever changes behaviour for a single request that carries a\nvalid, single-use Arvelos token, and only to let that one synthetic test\nthrough supported spam checks on a CAPTCHA-free form. Ordinary visitor\nsubmissions are untouched.<\/p><\/dd>\n<dt id=\"will%20the%20synthetic%20test%20email%20my%20real%20recipients%3F\"><h3>Will the synthetic test email my real recipients?<\/h3><\/dt>\n<dd><p>No. A synthetic run's notification is redirected to the Arvelos verification\naddress (an Arvelos-controlled mailbox) and clearly marked as a test. Your\nconfigured recipients are not contacted for a synthetic run.<\/p><\/dd>\n<dt id=\"what%20about%20forms%20protected%20by%20a%20captcha%3F\"><h3>What about forms protected by a CAPTCHA?<\/h3><\/dt>\n<dd><p>The plugin never circumvents a CAPTCHA. A form protected by reCAPTCHA,\nhCaptcha, or Turnstile is reported as unsupported and is not monitored.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20send%20any%20data%20before%20i%20set%20it%20up%3F\"><h3>Does the plugin send any data before I set it up?<\/h3><\/dt>\n<dd><p>No. Nothing is sent to Arvelos until you pair the site by entering your Site ID\nand secret.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release: synthetic-test authorization, single-use token verification,\nCAPTCHA-aware unsupported detection, synthetic notification routing to the\nArvelos verification address, a proof-of-control pairing route, secret\nrotation, and a debounced post-update re-test signal.<\/li>\n<\/ul>","raw_excerpt":"Companion plugin for the Arvelos service that runs a controlled synthetic test of your Contact Form 7 forms and confirms it completes.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/363053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=363053"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/arvelos"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=363053"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=363053"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=363053"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=363053"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=363053"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=363053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}