{"id":375216,"date":"2026-10-06T15:11:18","date_gmt":"2026-10-06T15:11:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/nestform\/"},"modified":"2026-10-06T15:10:59","modified_gmt":"2026-10-06T15:10:59","slug":"thimbleform","status":"publish","type":"plugin","link":"https:\/\/bal.wordpress.org\/plugins\/thimbleform\/","author":23557844,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.3.3","stable_tag":"2.3.3","tested":"7.1.3","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Thimbleform","header_author":"Thimbleform","header_description":"Build lead and contact forms with an entries inbox, email alerts, spam protection, and webhooks.","assets_banners_color":"979da6","last_updated":"2026-10-06 15:10:59","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/thimbleform.app","header_author_uri":"","rating":5,"author_block_rating":0,"active_installs":0,"downloads":131,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.3.3":{"tag":"2.3.3","author":"nestform","date":"2026-10-06 15:10:59","revision":3731102}},"upgrade_notice":{"2.3.3":"<p>Security hardening for form output and entry status changes.<\/p>","2.3.2":"<p>Entries hub kind filters for Recruiting (All \/ Forms \/ Jobs), sharper dashboard charts, and directory screenshots of the free plugin.<\/p>","2.3.1":"<p>Addon access hooks for Thimbleform HR and similar recruiting\/ownership add-ons.<\/p>","2.3.0":"<p>Clearer dashboard: one inbox pulse, cleaner chart and Top forms, WordPress 7.1 tested.<\/p>","2.2.1":"<p>Print layout, templates on empty forms, and a clearer response summary.<\/p>","2.2.0":"<p>Free plugin with unlimited forms. Thimbleform Pro is a separate add-on purchased via Freemius.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3731102,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3731102,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3731102,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3731102,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.3.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3731102,"resolution":"1","location":"assets","locale":"","width":1440,"height":1088},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3731102,"resolution":"2","location":"assets","locale":"","width":1440,"height":1088},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3731102,"resolution":"3","location":"assets","locale":"","width":1440,"height":948},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3731102,"resolution":"4","location":"assets","locale":"","width":1440,"height":948},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3731102,"resolution":"5","location":"assets","locale":"","width":1425,"height":707}},"screenshots":{"1":"Dashboard \u2014 Work pulse, activity chart, and quick actions.","2":"Forms list \u2014 search, status, and shortcode copy.","3":"Form builder \u2014 drag-and-drop fields on the canvas.","4":"Entries inbox \u2014 submissions with status filters.","5":"Front-end form \u2014 embedded Thimbleform on a page."}},"plugin_section":[],"plugin_tags":[358,267,2253,601,337],"plugin_category":[41,42],"plugin_contributors":[284729],"plugin_business_model":[],"class_list":["post-375216","plugin","type-plugin","status-publish","hentry","plugin_tags-contact-form","plugin_tags-email","plugin_tags-form-builder","plugin_tags-forms","plugin_tags-lead-generation","plugin_category-communication","plugin_category-contact-forms","plugin_contributors-nestform","plugin_committers-nestform"],"banners":{"banner":"https:\/\/ps.w.org\/thimbleform\/assets\/banner-772x250.png?rev=3731102","banner_2x":"https:\/\/ps.w.org\/thimbleform\/assets\/banner-1544x500.png?rev=3731102","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/thimbleform\/assets\/icon-128x128.png?rev=3731102","icon_2x":"https:\/\/ps.w.org\/thimbleform\/assets\/icon-256x256.png?rev=3731102","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/thimbleform\/assets\/screenshot-1.png?rev=3731102","caption":"Dashboard \u2014 Work pulse, activity chart, and quick actions."},{"src":"https:\/\/ps.w.org\/thimbleform\/assets\/screenshot-2.png?rev=3731102","caption":"Forms list \u2014 search, status, and shortcode copy."},{"src":"https:\/\/ps.w.org\/thimbleform\/assets\/screenshot-3.png?rev=3731102","caption":"Form builder \u2014 drag-and-drop fields on the canvas."},{"src":"https:\/\/ps.w.org\/thimbleform\/assets\/screenshot-4.png?rev=3731102","caption":"Entries inbox \u2014 submissions with status filters."},{"src":"https:\/\/ps.w.org\/thimbleform\/assets\/screenshot-5.png?rev=3731102","caption":"Front-end form \u2014 embedded Thimbleform on a page."}],"raw_content":"<!--section=description-->\n<p>Thimbleform is a form builder for lead capture and feedback.<\/p>\n\n<p><strong>Builder<\/strong><\/p>\n\n<ul>\n<li>Unlimited forms, starter templates (open on Add New when the canvas is empty)<\/li>\n<li>Drag-and-drop fields, undo, live preview<\/li>\n<li>Conditional show\/hide, file uploads, layout blocks (heading, image, HTML)<\/li>\n<li>Appearance skins and per-form styling<\/li>\n<li>Duplicate forms, JSON import\/export, import from Contact Form 7 and WPForms<\/li>\n<\/ul>\n\n<p><strong>Inbox &amp; mail<\/strong><\/p>\n\n<ul>\n<li>Entries with New \/ Read \/ Spam, star, CSV export, printable entry view<\/li>\n<li>Response summary: totals, fill rate, most chosen \/ most skipped answers<\/li>\n<li>Plain-text notifications, CC\/BCC, optional autoreply<\/li>\n<li>Outbound webhooks (HTTPS endpoints you configure per form)<\/li>\n<\/ul>\n\n<p><strong>Spam &amp; embed<\/strong><\/p>\n\n<ul>\n<li>Honeypot, time trap, rate limit, optional Akismet<\/li>\n<li>Google reCAPTCHA v2\/v3 via <strong>Thimbleform \u2192 Integrations<\/strong><\/li>\n<li>Gutenberg block and shortcode <code>[thimbleform id=\"123\"]<\/code><\/li>\n<\/ul>\n\n<p><strong>Admin<\/strong><\/p>\n\n<ul>\n<li>Dashboard with submission charts<\/li>\n<li>Light \/ dark admin theme<\/li>\n<\/ul>\n\n<p><strong>Optional Thimbleform Pro<\/strong> is a <strong>separate add-on<\/strong> (<code>thimbleform-pro<\/code>), sold via Freemius and hosted outside the WordPress.org directory. Premium code is not included in this download. It adds multi-step flows, quizzes and surveys, Stripe payments, HubSpot sync, advanced fields, HTML email, PDF attachments, automations, and richer analytics. Compare features under <strong>Thimbleform \u2192 Pro<\/strong>.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin can connect to optional third-party services configured by the site administrator:<\/p>\n\n<p><strong>Outbound webhooks<\/strong> (optional)<\/p>\n\n<ul>\n<li>Used for: POST JSON to HTTPS endpoints you configure per form (Settings \u2192 Webhooks).<\/li>\n<li>When: after each successful submission, if webhooks are enabled for that form.<\/li>\n<li>Data sent: form fields, entry metadata, and site URL \u2014 only to URLs you enter.<\/li>\n<\/ul>\n\n<p><strong>Google reCAPTCHA<\/strong> (optional)<\/p>\n\n<ul>\n<li>Used for: spam protection on forms.<\/li>\n<li>When: after you save site and secret keys under <strong>Thimbleform \u2192 Integrations<\/strong>.<\/li>\n<li>Data sent: challenge response tokens and related anti-spam data per <a href=\"https:\/\/policies.google.com\/privacy\">Google's policies<\/a>.<\/li>\n<li>Terms: https:\/\/policies.google.com\/terms<\/li>\n<\/ul>\n\n<p><strong>Cloudflare Turnstile<\/strong> (optional)<\/p>\n\n<ul>\n<li>Used for: spam protection on forms (alternative captcha provider).<\/li>\n<li>When: after you choose Turnstile and save site\/secret keys under <strong>Thimbleform \u2192 Integrations<\/strong>.<\/li>\n<li>Data sent: challenge tokens to Cloudflare per <a href=\"https:\/\/www.cloudflare.com\/privacypolicy\/\">Cloudflare's policies<\/a>.<\/li>\n<li>Terms: https:\/\/www.cloudflare.com\/website-terms\/<\/li>\n<\/ul>\n\n<p><strong>hCaptcha<\/strong> (optional)<\/p>\n\n<ul>\n<li>Used for: spam protection on forms (alternative captcha provider).<\/li>\n<li>When: after you choose hCaptcha and save site\/secret keys under <strong>Thimbleform \u2192 Integrations<\/strong>.<\/li>\n<li>Data sent: challenge tokens to hCaptcha per <a href=\"https:\/\/www.hcaptcha.com\/privacy\">hCaptcha's policies<\/a>.<\/li>\n<li>Terms: https:\/\/www.hcaptcha.com\/terms<\/li>\n<\/ul>\n\n<p><strong>Akismet<\/strong> (optional)<\/p>\n\n<ul>\n<li>Used for: spam scoring of submissions when the Akismet plugin is installed and configured.<\/li>\n<li>When: after a form is submitted, if Akismet is available on the site.<\/li>\n<li>Data sent: form field content and comment-check metadata to Automattic\u2019s Akismet service per <a href=\"https:\/\/akismet.com\/privacy\/\">Akismet's privacy policy<\/a>.<\/li>\n<li>Terms: https:\/\/akismet.com\/tos\/<\/li>\n<\/ul>\n\n<p><strong>Stripe<\/strong> (optional \u2014 Thimbleform Pro payment fields)<\/p>\n\n<ul>\n<li>Used for: accepting card payments on forms that include a Payment field.<\/li>\n<li>When: after you enable Stripe and save API keys under <strong>Thimbleform \u2192 Integrations<\/strong>, enable Stripe on the form, and add a Payment field (requires Thimbleform Pro).<\/li>\n<li>Data sent: payment amounts, currency, and payment intent metadata to Stripe; card details go directly to Stripe (never through Thimbleform servers).<\/li>\n<li>Terms: https:\/\/stripe.com\/legal<\/li>\n<li>Privacy: https:\/\/stripe.com\/privacy<\/li>\n<\/ul>\n\n<p><strong>HubSpot<\/strong> (optional \u2014 Thimbleform Pro)<\/p>\n\n<ul>\n<li>Used for: creating or updating HubSpot CRM contacts from form submissions.<\/li>\n<li>When: after you enable HubSpot and save a Private App access token under <strong>Thimbleform \u2192 Integrations<\/strong>, enable HubSpot on the form, map fields, and Thimbleform Pro is licensed.<\/li>\n<li>Data sent: mapped contact properties (typically email, name, phone, company) to HubSpot\u2019s CRM API.<\/li>\n<li>Terms: https:\/\/legal.hubspot.com\/terms-of-service<\/li>\n<li>Privacy: https:\/\/legal.hubspot.com\/privacy-policy<\/li>\n<\/ul>\n\n<p><strong>thimbleform.app \/ Freemius<\/strong> (optional \u2014 Pro purchase only)<\/p>\n\n<ul>\n<li>Used for: purchasing Thimbleform Pro and managing your Freemius license.<\/li>\n<li>When: only if you choose to buy Pro (checkout opens Freemius).<\/li>\n<li>The free plugin does not require a Freemius or thimbleform.app account to run.<\/li>\n<\/ul>\n\n<h3>Bundled fonts<\/h3>\n\n<p>Admin UI uses self-hosted <strong>Plus Jakarta Sans<\/strong> and <strong>Sora<\/strong> (SIL Open Font License 1.1). Font files ship under <code>assets\/fonts\/<\/code> with <code>assets\/fonts\/OFL.txt<\/code>. No Google Fonts CDN is used.<\/p>\n\n<h3>Bundled flags<\/h3>\n\n<p>The phone country picker uses self-hosted SVG flags from <a href=\"https:\/\/github.com\/lipis\/flag-icons\">flag-icons<\/a> (MIT). Files ship under <code>assets\/flags\/<\/code> with <code>assets\/flags\/LICENSE.txt<\/code>. No flag CDN is used.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/thimbleform\/<\/code> or install from the WordPress plugins screen.<\/li>\n<li>Activate <strong>Thimbleform<\/strong> through the <strong>Plugins<\/strong> menu.<\/li>\n<li>Open <strong>Thimbleform<\/strong> in the admin menu to create your first form.<\/li>\n<li>Embed with the Gutenberg block or shortcode <code>[thimbleform id=\"123\"]<\/code>.<\/li>\n<li>Documentation and hooks: <a href=\"https:\/\/thimbleform.app\/docs\">thimbleform.app\/docs<\/a>.<\/li>\n<\/ol>\n\n<p>For Pro features, install the <code>thimbleform-pro<\/code> add-on from Freemius checkout \/ your purchase email, then activate the license under <strong>Thimbleform \u2192 Account<\/strong> or <strong>Thimbleform \u2192 License<\/strong>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20thimbleform%20pro%20included%20in%20this%20download%3F\"><h3>Is Thimbleform Pro included in this download?<\/h3><\/dt>\n<dd><p>No. This is the free plugin. Thimbleform Pro is a separate add-on purchased via Freemius and installed as its own plugin.<\/p><\/dd>\n<dt id=\"how%20do%20i%20activate%20pro%20after%20purchase%3F\"><h3>How do I activate Pro after purchase?<\/h3><\/dt>\n<dd><p>Install <strong>Thimbleform Pro<\/strong>, then open <strong>Thimbleform \u2192 Account<\/strong> (or <strong>Thimbleform \u2192 License<\/strong>) and activate your Freemius license on this site.<\/p><\/dd>\n<dt id=\"how%20many%20forms%20can%20i%20create%3F\"><h3>How many forms can I create?<\/h3><\/dt>\n<dd><p>Unlimited on the free plugin. Pro adds builder features (multi-step, quizzes, advanced fields, and more), not extra form slots.<\/p><\/dd>\n<dt id=\"does%20thimbleform%20store%20submissions%3F\"><h3>Does Thimbleform store submissions?<\/h3><\/dt>\n<dd><p>Yes. Submissions appear under <strong>Thimbleform \u2192 Entries<\/strong>. You can export CSV and print a single entry.<\/p><\/dd>\n<dt id=\"does%20thimbleform%20add%20branding%20to%20my%20public%20site%3F\"><h3>Does Thimbleform add branding to my public site?<\/h3><\/dt>\n<dd><p>No. A \u201cPowered by Thimbleform\u201d link stays off unless you turn it on under <strong>Thimbleform \u2192 Settings<\/strong>.<\/p><\/dd>\n<dt id=\"where%20can%20i%20read%20the%20source%3F\"><h3>Where can I read the source?<\/h3><\/dt>\n<dd><p>The PHP in this download is the source. CSS and JavaScript are built from the files on GitHub: <a href=\"https:\/\/github.com\/NestForm\/thimbleform-free\">github.com\/NestForm\/thimbleform-free<\/a>. From that project, <code>npm run build<\/code> rebuilds the assets.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.3.3<\/h4>\n\n<ul>\n<li>Escape form and admin markup when it is printed, including shortcode output and filtered HTML.<\/li>\n<li>Marking an entry as read now requires a nonce. Opening the entry screen no longer changes status from a bare GET request.<\/li>\n<li>File uploads no longer load wp-admin\/includes\/media.php.<\/li>\n<li>The dashboard chart library ships in the plugin package.<\/li>\n<li>Privacy settings: Save is below the section cards, with the usual space between them.<\/li>\n<\/ul>\n\n<h4>2.3.2<\/h4>\n\n<ul>\n<li>Public name is Thimbleform. The plugin directory slug is <code>thimbleform<\/code>.<\/li>\n<li>Entries hub: optional All \/ Forms \/ Jobs kind filters via <code>thimbleform_entries_kind_filters<\/code> and <code>thimbleform_entries_hub_query_args<\/code> (form_ids \/ exclude_form_ids).<\/li>\n<li>Sharper dashboard charts (no forced canvas stretch on retina).<\/li>\n<li>Clearer description and screenshots of the free plugin.<\/li>\n<\/ul>\n\n<h4>2.3.1<\/h4>\n\n<ul>\n<li>Addon hooks: <code>thimbleform_accessible_form_ids<\/code>, <code>thimbleform_user_can_manage_form_entries<\/code>, <code>thimbleform_templates<\/code>, <code>thimbleform_template_applied<\/code>, <code>thimbleform_entry_meta_after<\/code>.<\/li>\n<li>Forms hub respects the same entry access allow-list (needed for Thimbleform HR and similar add-ons).<\/li>\n<\/ul>\n\n<h4>2.3.0<\/h4>\n\n<ul>\n<li>Dashboard redesign: Work pulse (New \/ Read \/ Spam), quieter KPIs, Activity chart without duplicate status footers.<\/li>\n<li>Top forms rail replaces Status mix; Recent activity uses a normal panel frame.<\/li>\n<li>Quick actions are visible secondary buttons (New form, Forms\/Export, Integrations).<\/li>\n<li>Developers docs: <code>thimbleform_dashboard_work_pulse_extra<\/code> filter.<\/li>\n<li>Tested up to WordPress 7.1. Turnstile, hCaptcha, and Akismet are described under External services.<\/li>\n<li>Smoke checks via <code>npm test<\/code>.<\/li>\n<\/ul>\n\n<h4>2.2.1<\/h4>\n\n<ul>\n<li>Printable entries: two-column label\/value layout so answers line up.<\/li>\n<li>Empty Add New forms open the templates gallery; starter cards stay on the canvas.<\/li>\n<li>Response summary: KPIs, most chosen \/ most skipped, richer field cards.<\/li>\n<li>Unread counts use a ripple; New status uses a quiet border pulse.<\/li>\n<li>Phone country flags are bundled as local SVGs (no flagcdn.com).<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Free plugin: unlimited forms, no Freemius SDK in the free zip; Pro sold via Freemius.<\/li>\n<li>Pro add-on: Freemius license activation.<\/li>\n<li>Admin preview submits no longer create entries.<\/li>\n<li>In-app <strong>Pro<\/strong> page and <strong>Developers<\/strong> reference.<\/li>\n<li>Thimbleform Pro is a separate add-on and is not part of this download.<\/li>\n<\/ul>","raw_excerpt":"Build lead and contact forms with an entries inbox, email alerts, spam protection, and webhooks.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/375216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=375216"}],"author":[{"embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/nestform"}],"wp:attachment":[{"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=375216"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=375216"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=375216"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=375216"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=375216"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/bal.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=375216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}