{"id":372822,"date":"2026-10-01T16:34:18","date_gmt":"2026-10-01T16:34:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/mis-webform\/"},"modified":"2026-10-01T16:34:01","modified_gmt":"2026-10-01T16:34:01","slug":"mis-webform","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/mis-webform\/","author":23506731,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.1.2","requires":"5.8","requires_php":"7.1","requires_plugins":null,"header_name":"MIS Webform","header_author":"MIS Technolabs","header_description":"Full-featured form builder with 38+ field types, multi-step forms, conditional logic, file uploads, and email notifications, with 8 predefined templates.","assets_banners_color":"","last_updated":"2026-10-01 16:34:01","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/mistechnolabs.com\/mis-webform","header_author_uri":"https:\/\/mistechnolabs.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":65,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"mistechnolabs","date":"2026-10-01 16:34:01","revision":3723491}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[130308,358,5887,2253,30663],"plugin_category":[],"plugin_contributors":[275573],"plugin_business_model":[],"class_list":["post-372822","plugin","type-plugin","status-publish","hentry","plugin_tags-conditional-logic","plugin_tags-contact-form","plugin_tags-file-upload","plugin_tags-form-builder","plugin_tags-multi-step-form","plugin_contributors-mistechnolabs","plugin_committers-mistechnolabs"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/mis-webform.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>MIS Webform is a full-featured form builder for WordPress, with no artificial limits on forms,\nfields, or submissions in the free version. Build a simple contact form in a minute, or a\nmulti-page application form with conditional logic, file uploads, and a signature field \u2014 all\nfrom one field-type registry of 38+ options, with 8 ready-made templates to start from, and\ndrag-to-reorder fields in the builder. Submissions are stored securely (uploaded files are never\npublicly accessible), exportable to CSV, and integrated with WordPress's own Export\/Erase\nPersonal Data privacy tools.<\/p>\n\n<p>Free version features:<\/p>\n\n<ul>\n<li>Unlimited forms, fields, and stored submissions - no artificial caps<\/li>\n<li>38+ field types: text, email, phone, number, URL, date\/time, file uploads (with type-specific\nfilters), star rating, signature pad, color picker, address, full name, Likert scale, and more<\/li>\n<li>Multi-step \/ paginated forms with a progress bar and Next\/Previous navigation<\/li>\n<li>Conditional field logic - show or hide a field based on another field's value<\/li>\n<li>8+ pre-built form templates (Contact, Donation, Membership, Education\/Course Enrollment, Event\nBooking\/RSVP, File Upload, Poll, Survey) to start from instead of building from scratch<\/li>\n<li>Submission storage with CSV export<\/li>\n<li>Honeypot and Google reCAPTCHA spam protection<\/li>\n<li>Email notifications on new submissions<\/li>\n<\/ul>\n\n<p>Need more? <a href=\"https:\/\/mistechnolabs.com\/mis-webform-pro\">MIS Webform Pro<\/a> adds an AI Form Generator\nand webhooks.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to one third-party service, and only when a site owner explicitly enables\nit - it is off by default and no data is sent anywhere for this purpose unless you turn it on.<\/p>\n\n<p><strong>Google reCAPTCHA v2<\/strong> - used for optional spam protection on a per-form basis, under that\nform's Spam Protection settings.<\/p>\n\n<ul>\n<li>What is sent: when a form has reCAPTCHA enabled, the reCAPTCHA widget script is loaded from\nGoogle (<code>https:\/\/www.google.com\/recaptcha\/api.js<\/code>) on pages where that form appears. When a\nvisitor submits the form, their reCAPTCHA response token and IP address are sent to Google's\nverification endpoint (<code>https:\/\/www.google.com\/recaptcha\/api\/siteverify<\/code>) to confirm the\nsubmission wasn't from a bot.<\/li>\n<li>When it is sent: only for forms where you have explicitly turned reCAPTCHA on and entered your\nown Google reCAPTCHA site\/secret keys. If you never enable it, no data leaves your site for\nthis purpose, and nothing related to reCAPTCHA loads or runs.<\/li>\n<li>Privacy Policy: https:\/\/mistechnolabs.com\/privacy-policy\/<\/li>\n<\/ul>\n\n<p>No other external service is contacted by this plugin. All other assets (CSS, JavaScript,\nincluding the date\/time picker library) are bundled with the plugin and served from your own\nsite. Plugin activation itself does not contact any external server.<\/p>\n\n<h3>Credits<\/h3>\n\n<p>This plugin bundles <a href=\"https:\/\/flatpickr.js.org\/\">flatpickr<\/a> 4.6.13 (MIT license) for its date\/time\npicker fields.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>mis-webform<\/code> folder to the <code>\/wp-content\/plugins\/<\/code> directory, or install the plugin\nthrough the WordPress plugins screen directly.<\/li>\n<li>Activate the plugin through the \"Plugins\" screen in WordPress.<\/li>\n<li>Go to <strong>MIS Webform \u2192 New Form<\/strong> to build your first form.<\/li>\n<li>Copy the generated <code>[mis-webform id=\"X\"]<\/code> shortcode into any page, post, or widget area.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20add%20a%20form%20to%20a%20page%3F\"><h3>How do I add a form to a page?<\/h3><\/dt>\n<dd><p>Copy the shortcode shown next to your form in the <strong>MIS Webform<\/strong> admin screen (for example\n    [mis-webform id=\"1\"]) and paste it into a page, post, or any widget\/block that supports shortcodes.<\/p><\/dd>\n<dt id=\"where%20are%20submissions%20stored%3F\"><h3>Where are submissions stored?<\/h3><\/dt>\n<dd><p>Submissions are stored in your WordPress database and are viewable under\n<strong>MIS Webform \u2192 Submissions<\/strong>, where they can also be exported to CSV.<\/p>\n\n<p>Each submission also records the visitor's IP address and browser user agent string, mainly\nuseful for spam investigation. These are kept indefinitely along with the submission unless\nyou delete it yourself - there is currently no automatic expiry. If you're subject to GDPR or\nsimilar privacy regulations, factor this into your own data retention policy, and delete old\nsubmissions manually via <strong>MIS Webform \u2192 Submissions<\/strong> when they're no longer needed.<\/p><\/dd>\n<dt id=\"how%20are%20file%20uploads%20validated%3F\"><h3>How are file uploads validated?<\/h3><\/dt>\n<dd><p>Each file upload field lets you set allowed file extensions and a maximum size. On submission,\nMIS Webform checks both the filename's extension <em>and<\/em> the file's actual content against that\nallowlist (using WordPress's own <code>wp_check_filetype_and_ext()<\/code>) - a file renamed to spoof its\nextension (e.g. a disguised executable) is rejected even if the filename alone looks fine. This\ncontent-based check is strongest when your host has the PHP <code>fileinfo<\/code> extension enabled,\nwhich is the default on nearly all WordPress hosting - if your host has disabled it, file-type\nvalidation falls back to WordPress core's own weaker built-in checks.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20load%20anything%20from%20third-party%20servers%3F\"><h3>Does this plugin load anything from third-party servers?<\/h3><\/dt>\n<dd><p>By default, no - all CSS\/JS assets, including the date\/time picker library, are bundled with the\nplugin and served from your own site.<\/p>\n\n<p>The one exception is Google reCAPTCHA, which is entirely optional and off by default. If you\nchoose to enable it for a form (under that form's Spam Protection settings), the plugin will:<\/p>\n\n<ul>\n<li>Load Google's reCAPTCHA widget script (<code>https:\/\/www.google.com\/recaptcha\/api.js<\/code>) on pages\nwhere that form appears.<\/li>\n<li>Send the visitor's reCAPTCHA response, together with their IP address, to Google's\n  recaptcha\/api\/siteverify endpoint when the form is submitted, to verify it wasn't a bot.<\/li>\n<\/ul>\n\n<p>This only happens for forms where you've explicitly turned reCAPTCHA on and entered your own\nGoogle reCAPTCHA site\/secret keys - if you never enable it, no data ever leaves your site for\nthis purpose. If you do enable it, consider mentioning Google reCAPTCHA in your site's privacy\npolicy, as its use is subject to <a href=\"https:\/\/mistechnolabs.com\/privacy-policy\">Google's Privacy Policy<\/a>\nand <a href=\"https:\/\/mistechnolabs.com\/terms\">Terms of Service<\/a>.<\/p><\/dd>\n<dt id=\"does%20mis%20webform%20include%20ai%20features%3F\"><h3>Does MIS Webform include AI features?<\/h3><\/dt>\n<dd><p>The free version does not - it's a complete, standalone form builder with no external account or\nservice required. An AI Form Generator is available in <a href=\"https:\/\/mistechnolabs.com\/mis-webform-pro\">MIS Webform Pro<\/a>,\nwhich is documented separately since it involves a connected account and third-party AI service.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20data%20if%20i%20uninstall%20the%20plugin%3F\"><h3>What happens to my data if I uninstall the plugin?<\/h3><\/dt>\n<dd><p>Your forms and submissions are kept by default, even if you delete the plugin - deactivating\nnever touches your data, and deleting it only removes the plugin's files unless you've\nexplicitly opted in to full cleanup. If you do want your forms and submissions removed when you\ndelete the plugin, check <strong>MIS Webform \u2192 Settings \u2192 \"Delete all MIS Webform forms and submissions when\nuninstalling\"<\/strong> before deleting it. This is off by default specifically so you don't lose\ncustomer\/contact data by accident.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fixed: the custom database tables used DATETIME DEFAULT CURRENT_TIMESTAMP\n(and, on one column, ON UPDATE CURRENT_TIMESTAMP), which isn't supported\non all MySQL\/MariaDB versions.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Full-featured form builder with 38+ field types, multi-step forms, conditional logic, and file uploads.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/372822","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=372822"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/mistechnolabs"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=372822"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=372822"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=372822"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=372822"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=372822"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=372822"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}