=== Formsieve – AI Contact Form Spam Filter ===
Contributors: thinking42
Tags: anti-spam, antispam, spam protection, contact form 7, gravity forms
Requires at least: 6.6
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.1.2
License: GPL-2.0-or-later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

AI spam filter for Contact Form 7 and Gravity Forms: free honeypot, timing and list checks, plus an AI check for sales-pitch spam. No CAPTCHA.

== Description ==

Formsieve checks form submissions for spam in two layers. Free local checks run first on your own server. Submissions that pass them get one AI spam check from the Formsieve service, which asks TypeSafe AI's Jev model a fixed set of questions; the plugin turns the answers into a calibrated spam probability and decides. No CAPTCHA.

Contact forms get two kinds of spam: bots, and people who type or paste sales pitches by hand. Honeypots and CAPTCHAs judge the visitor, so a person with a pitch gets through them. The AI check reads the message itself, so SEO offers, link building and other pitches can be caught even when a person sent them.

One plugin covers Gravity Forms and Contact Form 7, on the same site if you use both: it turns on a module for each form plugin that is active, with one key, one settings screen, one dashboard and one decision log.

The plugin and its local checks are free. The AI check is a service you connect with a Formsieve key: a free trial (14 days or 500 AI checks, whichever comes first; no card), then the Free plan (100 AI checks a month for one production site) or a paid plan (as of 2026-09-27; https://formsieve.com/pricing/).

= How it works =

* **Local checks first**, with or without a key: a honeypot, a signed time-to-submit token, a replay cache, a per-IP rate limit, allow and block lists, WordPress's Disallowed Comment Keys, disposable e-mail domains and heuristics. What they stop needs no AI check.
* **One AI check** for what passes them: a spam probability, a category (such as vendor solicitation or scam) and a short reason.
* **Three bands:** allow, review and block, from presets or your own thresholds, per form if you like. Review-band submissions are delivered with a "[Possible spam 62%]" subject tag, so an uncertain lead still reaches you.
* **Explained:** probability, category, model, request ID and latency on each entry, in Flamingo and in the log.
* **Fails open:** by default an outage never blocks a form, and a billing state never does: the submission is delivered with a "not checked" note, or held for review if you prefer.
* **Learns from you:** your spam and not-spam corrections teach it trusted and blocked senders (stored as hashes).

= Gravity Forms =

* Runs after Gravity Forms' own honeypot and sends nothing for an entry it has flagged.
* Per form: mark as spam (default), discard, or refuse with a validation error. Not Spam restores a blocked entry.
* An entry panel with the verdict, Re-check and Mark spam or not spam, a sortable probability column, and entry meta for filters and exports.

= Contact Form 7 and Flamingo =

* Adds a hidden honeypot field and a signed time-to-submit token to each form.
* Uses Contact Form 7's own spam status, spam log and spam message; mail addressed to the visitor is never tagged.
* With Flamingo (recommended), spam is kept in its Spam folder with the explanation, and "Not spam" teaches the sender.
* Per-form settings in a tab of the form editor, and the "formsieve: off" additional setting.

= Also included =

* A Dashboard with your plan and the AI checks used this month; notices at 80% and 100%, on the plugin's own screens only. An optional hourly limit of AI checks per form, against bot waves.
* A privacy kit: a consent screen naming every recipient, the e-mail domain only, sensitive fields left out, phone redaction, privacy-policy text, a one-line notice under forms ("Submissions are screened for spam by an automated AI service.", with no product name or link), on by default once the AI check runs, off under Settings > Privacy or per form, personal-data export and erasure, log retention.
* Test mode, WP-CLI commands and developer hooks.
* Translation-ready: translations come from translate.wordpress.org.

= Requirements =

WordPress 6.6 or later and PHP 7.4 or later, with Gravity Forms 2.9 or later, Contact Form 7 6.0 or later (Flamingo recommended), or both.

= Documentation and support =

* Documentation: https://formsieve.com/docs/
* Questions about the plugin: the support forum here on WordPress.org.
* Questions about your account, plan or invoices: support@formsieve.com (https://formsieve.com/support/). Never post your key in a public forum.

== Installation ==

1. Go to Plugins > Add Plugin (Add New Plugin before WordPress 6.8), search for Formsieve, then Install Now and Activate (or upload the zip). Gravity Forms 2.9 or later or Contact Form 7 6.0 or later must be active.
2. Follow the set-up wizard: enter your key (or start a free trial on formsieve.com), review what is sent and accept, then click Test connection.
3. Describe your site under Settings > Detection, so the AI check can tell a real enquiry from a pitch. Per-form settings are under Forms > (form) > Settings > Formsieve in Gravity Forms, and in a tab of the Contact Form 7 form editor.
4. With Contact Form 7, install Flamingo to keep and review spam.

The local checks run without a key. Test mode (Settings > Advanced) simulates AI verdicts and sends nothing.

== Frequently Asked Questions ==

= Which form plugins does it support? =

Gravity Forms 2.9 or later and Contact Form 7 6.0 or later (Flamingo recommended), on the same site if you use both. The Dashboard's "Form plugins" card shows which ones are checked.

= Do I need an account? =

For the AI check, yes: a Formsieve key from formsieve.com, and nothing else, because the AI is included. The trial needs no card (14 days or 500 AI checks, whichever comes first, as of 2026-09-27). One key covers every form, and its monthly AI checks are shared across your sites.

= Does it work without a key? =

Yes. The local checks run on every enabled form with or without a key; only the AI check needs one. Test mode shows simulated AI verdicts without sending anything.

= What counts as an AI check? =

One submission for which the service returns an AI result. Submissions stopped by the local checks, Test connection, errors and the automatic retry do not count. On the trial and paid plans, staging and development sites use no site slot, but their checks count (as of 2026-09-25). The Free plan covers one production site only; staging and development sites need a paid plan (as of 2026-09-29).

= What happens when my trial ends or my allowance is used? =

Only the AI check stops; forms and local checks keep working. When the trial ends, nothing is charged and the key moves to the Free plan: 100 AI checks a month for one production site (as of 2026-09-27). Paid plans keep checking above the allowance up to a ceiling, with notices at 80% and 100%; from the third month in a row over the allowance, checks pause at 100% until you upgrade (as of 2026-09-27).

While AI checks are paused, submissions that pass the local checks are delivered with the note "Not checked by AI" and the reason, or held for review if you prefer: billing never blocks a form. Checks also pause after unusually high use in one day (until 00:00 UTC), when a key's forms send far more text than typical contact forms (fair use), and when the Free plan's shared capacity is used up for now (as of 2026-09-27).

= Will it slow my forms? =

Page loads are not affected: the plugin works only when a form is submitted. A submission that passes the local checks adds one call to the service, with a 3-second timeout and at most one quick retry. The Dashboard shows the average and 95th-percentile time.

= Does it stop human-typed sales pitches? =

It is built for them. The AI check reads the message and returns a category such as "vendor solicitation", so pitches can be caught even when a person typed them. Describe your site under Settings > Detection to help it tell an enquiry from a pitch. No filter is perfect: borderline messages are delivered with a tag, and blocked ones can be restored.

= What if the service is down or slow? =

It fails open by default: after the timeout and one retry, the submission is delivered with the note "Formsieve: not checked (API unavailable)". You can hold such submissions for review instead, or send them to spam during outages.

= Can a real lead be lost? =

Only confident spam is blocked; borderline submissions are delivered with a tag. Gravity Forms keeps blocked entries in its Spam folder. Contact Form 7 stores nothing by itself, so install Flamingo to keep blocked messages. "Not spam" restores a message and teaches the sender. Visitors never see the probability.

= Does it work with Akismet, reCAPTCHA or Turnstile? =

Yes. Nothing is sent when another check has already flagged a submission: Gravity Forms' honeypot, or Akismet, reCAPTCHA or Turnstile on Contact Form 7. Gravity Forms' built-in Akismet check runs afterwards and sees only allowed submissions, and its reCAPTCHA field stops a failed submission at validation, before any spam check.

= What data is sent? =

Nothing before an administrator enters a key and accepts the notice. Then, for each checked submission: the ordinary fields with their labels (phone numbers redacted by default, sensitive fields left out), the e-mail domain (optional) and a few signals computed on your server, such as the number of links and their host names, the time taken to submit and whether you marked the sender as spam or not spam before. Never the visitor's IP address, user agent or full e-mail address, passwords, payment fields or uploads. See "External services".

= Is Formsieve made by Gravity Forms, Contact Form 7 or TypeSafe? =

No. It is an independent product of Thinking42; see the disclaimer below.

== Screenshots ==

1. The decision log: verdict, spam probability, category and reason, with Mark spam and Mark not spam. Demo data from a test site.
2. Every decision explained: a Contact Form 7 message in Flamingo and a Gravity Forms entry. Demo data from a test site.
3. The set-up wizard: paste a key or start a free trial, see what is sent, test the connection.
4. Per-form settings for Contact Form 7, in a tab of the form editor.
5. Per-form settings for Gravity Forms, under Form Settings.
6. The free local checks: honeypot, timing, replay cache, rate limit, lists and disposable e-mail domains.
7. The Dashboard: AI checks used this month against your plan, the form plugins found and the verdicts. Demo data from a test site.
8. Test mode: simulated verdicts, nothing sent.

== Changelog ==

= 1.1.2 (2026-10-09) =
* Fixed: Formsieve's look on Contact Form 7 6.2's screens. Its styles did not load there, so the Formsieve tab of the form editor showed no Formsieve mark and a plain status pill.
* Fixed: the note at the bottom of Forms > Settings > Formsieve in Gravity Forms now names the "Delete all Formsieve data when the plugin is deleted" option as it is labelled.
* Tested with Gravity Forms 3.1.3 and Contact Form 7 6.2.1.

= 1.1.1 (2026-09-30) =
* First version published on WordPress.org. Translations come from translate.wordpress.org; the Spanish (Spain) files that 1.1.0 bundled are no longer in the plugin.
* The Formsieve entry in the WordPress admin menu shows the Formsieve mark instead of a generic filter icon, in the colours of your admin colour scheme. The Formsieve tab in Gravity Forms' settings shows the mark too.
* The notice about an incomplete installation shows only on the Plugins and Updates screens.
* A key whose plan is not active no longer also shows "This site is not on your Formsieve plan".

= 1.1.0 (2026-09-29) =
* One plugin with a module for Gravity Forms and one for Contact Form 7 (with Flamingo).
* Free local checks on every enabled form, with or without a key.
* One AI check per submission that passes them, through the Formsieve service with a Formsieve key (free 14-day trial): spam probability, category and reason; allow, review and block bands; presets, thresholds and per-form overrides.
* Set-up wizard, Dashboard with your plan and usage, decision log, feedback loop, privacy kit, Test mode, WP-CLI and a Spanish (Spain) translation.
* Fails open: outages and billing states never block a form by default.
* Asks once, on its own Dashboard only, for an honest review after 14 days and 25 stopped spam submissions. "Maybe later" and "Don't ask again" are kept.

Full changelog: https://formsieve.com/docs/changelog/

== External services ==

Formsieve uses one external service, for its AI check: the Formsieve spam-check service at https://api.formsieve.com, run by Thinking42, Inc. (USA). It needs a key (a free trial, the Free plan or a paid plan: https://formsieve.com/pricing/). The local checks need no service.

When: never before an administrator enters a key and accepts the notice in the set-up wizard or on the settings screen. Then: once for each submission that passes the local checks (each form can be switched off); when you save a key (to verify it) or click Test connection (a sample, no form data); when you open the Dashboard (plan and usage, at most every 15 minutes); once a day (key, plan, usage and this site's slot); and when you disconnect the key or delete the plugin (to free this site's slot). Test mode sends nothing.

What each check sends: the site name, the form name, the site and form descriptions you write, the site languages, the label, type and value of the submission's ordinary fields (phone numbers redacted by default; passwords, payment, identity-document and health fields excluded automatically; any field can be excluded; values capped), the sender's e-mail domain (optional), signals computed on your server (the number of links and their host names, whether a phone number is present, the time taken to submit, the number of submissions from the same IP address in the last hour, the writing systems used, the message length, and whether you marked the sender as spam or not spam before), your key, this site's address and environment (production, staging or development), and which form plugin handled the submission (for example "gf" or "cf7"). The key calls send your key, this site's address and environment and which form plugins are active, and no form data. Every call carries the plugin, WordPress and PHP versions. Never sent: the visitor's IP address, user agent or full e-mail address, passwords, uploads, payment fields or the plugin's own hidden fields.

Where it goes: Thinking42 runs the service on Amazon Web Services, Inc., behind Cloudflare, Inc. It sends the content, with fixed questions, to TypeSafe AI, Inc.'s Jev model through OpenRouter, Inc. (all US companies; Cloudflare runs a global network, and OpenRouter does not promise to handle a request only in the USA, as of 2026-10-08) and returns the answers; the plugin computes the spam probability on your server. Thinking42 does not store the content of submissions; it keeps request records without the content (such as the time, key and site identifiers, status, timing and the spam band of the result) for 30 days (as of 2026-09-25).

* Formsieve (Thinking42, Inc.): https://formsieve.com - Terms: https://formsieve.com/terms/ - Privacy policy: https://formsieve.com/privacy-policy/ - Data Processing Agreement: https://formsieve.com/dpa/ - Sub-processors: https://formsieve.com/subprocessors/
* OpenRouter, Inc.: Terms: https://openrouter.ai/terms - Privacy policy: https://openrouter.ai/privacy
* TypeSafe AI, Inc.: Terms: https://typesafe.ai/legal/terms - Master customer agreement: https://typesafe.ai/legal/mca - Privacy policy: https://typesafe.ai/legal/privacy-policy

== Credits ==

* Admin fonts in assets/fonts/, under the SIL Open Font License 1.1, so no font is loaded from another site: Unbounded (Copyright 2022 The Unbounded Project Authors), DM Sans (Copyright 2014 The DM Sans Project Authors) and IBM Plex Mono (Copyright 2017 IBM Corp., with Reserved Font Name "Plex"). Sources: assets/fonts/README.txt.
* Disposable e-mail domain list: https://github.com/disposable-email-domains/disposable-email-domains (CC0 1.0), copied 2026-09-22.
* Composer class loader (MIT licence).

== Disclaimer ==

Formsieve is an independent product of Thinking42. It is not affiliated with, endorsed by, or sponsored by TypeSafe AI, Inc., Rocketgenius, Inc., or Rock Lobster Inc. TypeSafe and Jev are trademarks of TypeSafe AI, Inc. Gravity Forms is a registered trademark of Rocketgenius, Inc. Contact Form 7 is a registered trademark of Rock Lobster Inc. WordPress is a registered trademark of the WordPress Foundation. All other names are used only to identify compatibility.
