=== GB Forms DB ===
Contributors: gb-plugins
Tags: contact form 7, leads, form submissions, elementor forms, csv export
Requires at least: 5.6
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 2.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

One lead collector to rule them all. Every form on your site saves into one list you can search, filter and export.

== Description ==

GB Forms DB saves every lead from every form on your site in one place — even when the site runs several form plugins, and even for forms built by hand.

Each lead keeps what was submitted, the form it came from, the page it was sent from, the date and time, and the technical details the form plugin reported (IP address, browser, hidden fields).

= Supported forms =

* Contact Form 7 — saved even when the notification email fails to send
* Elementor Pro forms
* Gravity Forms
* Ninja Forms
* Pojo Forms
* **All forms** — any form submitted on the site, including hand-built forms and forms that submit with Ajax
* **Form by selector** — only the forms that match a CSS selector

Password and payment-card fields are never saved. Login, registration, search, cart and checkout forms are left alone.

= Managing leads =

* Search every field at once, or search inside one field
* Filter by form and by date, with quick ranges (7 days, 30 days, 3 months, a year)
* Pick a form and its fields appear as columns
* New / read status, with the unread count in the admin menu
* Trash, restore, delete permanently, and bulk actions
* Export to CSV — the whole list or just what is filtered. The file opens in Excel with Hebrew and other languages intact.
* Personal data export and erase through WordPress's privacy tools

= For developers =

Send leads on to a CRM, a mailing list or anything else with an action hook:

`
add_action( 'gbfdb_after_save_6', function ( $data, $lead_id ) {
	// $data['fields'] — what was submitted, e.g. $data['fields']['your-email']
	// $data['meta']   — form_id, type, url, remote_ip, user_agent...
}, 10, 2 );
`

The number after `gbfdb_after_save_` is the form ID. Forms saved by "All forms" or "Form by selector" use `gbfdb_after_save_forms-{id}`, where the ID is the form's `id` attribute — their hook is kept apart because anyone can post to it. `gbfdb_after_save` fires for every form (third argument: the lead type), and `after_save_lead` receives the lead ID.

Filters: `gbfdb_before_save_lead` (change or skip a lead before it is saved), `gbfdb_exclude_field`, `gbfdb_client_ip` (the visitor's real address behind a proxy or CDN), `gbfdb_supported_plugins`, `gbfdb_forms_settings`, `gbfdb_capability`, `gbfdb_page_url`, `gbfdb_lead_order`, `gbfdb_field_output_data`, `gbfdb-before-admin-save`, `gbfdb-admin-save`.

Actions: `gbfdb_admin_page_add_fieldset` and `gbfdb_admin_page_add_fieldset_fields` add a tab to the settings screen; `before_gbfdb_field_output` and `after_gbfdb_field_output` add markup around a field on the lead screen.

= Docs and support =

[gb-plugins.com](https://www.gb-plugins.com/documents/gb-forms-db/)

== Installation ==

1. Upload the `gb-forms-db` folder to `/wp-content/plugins/`, or install it from Plugins > Add New.
2. Activate the plugin.
3. Go to GB Forms DB > Settings. The form plugins found on your site are already switched on — check the list and press Save.

== Frequently Asked Questions ==

= Where are the leads stored? =

In your own WordPress database, as a private post type. Nothing is sent anywhere unless you hook into `gbfdb_after_save`.

= Does it save forms that submit with Ajax? =

Yes. The form plugins in the list are saved through their own hooks. For other forms, "All forms" and "Form by selector" catch the submission in the browser, whether the form reloads the page or not.

= Is anything left out? =

Password fields, payment-card fields, nonces and captcha responses are never saved, and login, registration, search, cart and checkout forms are skipped. Use the `gbfdb_exclude_field` filter to leave out more.

= Who can see the leads? =

Administrators (the `manage_options` capability). Change it with the `gbfdb_capability` filter. Other roles cannot reach leads through any WordPress screen or API.

= What happens to leads in the trash? =

WordPress empties the trash after 30 days, as it does for posts.

= My site is behind Cloudflare or a proxy =

Return the visitor's real IP from the `gbfdb_client_ip` filter. Otherwise every visitor looks like the proxy, and the limit on submissions from one address (30 in 10 minutes) applies to all of them together.

== Screenshots ==

1. All your leads in one list: search, filter by form and date, unread leads highlighted.
2. A single lead with everything that was submitted and where it came from.
3. Settings: the form plugins found on your site, plus "All forms" and "Form by selector".
4. Pick a form and its fields become columns. Export exactly what you see to CSV.
5. Fully translated and right-to-left ready (Hebrew shown).

== Changelog ==

= 2.0.0 =
Rebuilt from the ground up.

* Leads are saved the moment the form is submitted. 1.x held them in the options table, loaded on every page of the site, until an hourly job moved them.
* Contact Form 7 leads are kept when the notification email fails to send.
* "All forms" now works; in 1.x a script error stopped it from saving anything. It also catches forms that submit with Ajax, and never saves passwords or card numbers.
* New leads screen: server-side search, field search, form and date filters, pages, sorting, bulk actions, trash.
* CSV export runs on the server, covers the current filter, and opens correctly in Excel.
* New lead screen and settings screen.
* Privacy tools: export and erase a person's leads by email address.
* Removed a debug log that 1.x wrote inside the plugin folder on every admin page load.
* Removed a site-wide change to WordPress's output buffering.
* Leads can only be reached by administrators (filter `gbfdb_capability`). In 1.x, editors could read and delete them through XML-RPC.
* Existing leads and settings are carried over automatically, including leads 1.x had not moved yet.
* Now requires WordPress 5.6 and PHP 7.4.

= 1.0.4 =
* Last 1.x release.

= 1.0.1 =
* Fixed CSS issues.

== Upgrade Notice ==

= 2.0.0 =
A complete rebuild. Your leads and settings are carried over automatically. If you customised the look of the 1.x leads screen with CSS, those styles no longer apply.
