=== MIS Webform ===
Contributors: mistechnolabs
Tags: form builder, contact form, multi-step form, file upload, conditional logic
Requires at least: 5.8
Tested up to: 7.1
Requires PHP: 7.1
Stable tag: 1.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Full-featured form builder with 38+ field types, multi-step forms, conditional logic, and file uploads.

== Description ==

MIS Webform is a full-featured form builder for WordPress, with no artificial limits on forms,
fields, or submissions in the free version. Build a simple contact form in a minute, or a
multi-page application form with conditional logic, file uploads, and a signature field — all
from one field-type registry of 38+ options, with 8 ready-made templates to start from, and
drag-to-reorder fields in the builder. Submissions are stored securely (uploaded files are never
publicly accessible), exportable to CSV, and integrated with WordPress's own Export/Erase
Personal Data privacy tools.

Free version features:

* Unlimited forms, fields, and stored submissions - no artificial caps
* 38+ field types: text, email, phone, number, URL, date/time, file uploads (with type-specific
  filters), star rating, signature pad, color picker, address, full name, Likert scale, and more
* Multi-step / paginated forms with a progress bar and Next/Previous navigation
* Conditional field logic - show or hide a field based on another field's value
* 8+ pre-built form templates (Contact, Donation, Membership, Education/Course Enrollment, Event
  Booking/RSVP, File Upload, Poll, Survey) to start from instead of building from scratch
* Submission storage with CSV export
* Honeypot and Google reCAPTCHA spam protection
* Email notifications on new submissions

Need more? [MIS Webform Pro](https://mistechnolabs.com/mis-webform-pro) adds an AI Form Generator
and webhooks.

== External services ==

This plugin connects to one third-party service, and only when a site owner explicitly enables
it - it is off by default and no data is sent anywhere for this purpose unless you turn it on.

**Google reCAPTCHA v2** - used for optional spam protection on a per-form basis, under that
form's Spam Protection settings.

* What is sent: when a form has reCAPTCHA enabled, the reCAPTCHA widget script is loaded from
  Google (`https://www.google.com/recaptcha/api.js`) on pages where that form appears. When a
  visitor submits the form, their reCAPTCHA response token and IP address are sent to Google's
  verification endpoint (`https://www.google.com/recaptcha/api/siteverify`) to confirm the
  submission wasn't from a bot.
* When it is sent: only for forms where you have explicitly turned reCAPTCHA on and entered your
  own Google reCAPTCHA site/secret keys. If you never enable it, no data leaves your site for
  this purpose, and nothing related to reCAPTCHA loads or runs.
* Privacy Policy: https://mistechnolabs.com/privacy-policy/

No other external service is contacted by this plugin. All other assets (CSS, JavaScript,
including the date/time picker library) are bundled with the plugin and served from your own
site. Plugin activation itself does not contact any external server.

== Installation ==

1. Upload the `mis-webform` folder to the `/wp-content/plugins/` directory, or install the plugin
   through the WordPress plugins screen directly.
2. Activate the plugin through the "Plugins" screen in WordPress.
3. Go to **MIS Webform → New Form** to build your first form.
4. Copy the generated `[mis-webform id="X"]` shortcode into any page, post, or widget area.

== Frequently Asked Questions ==

= How do I add a form to a page? =

Copy the shortcode shown next to your form in the **MIS Webform** admin screen (for example
`[mis-webform id="1"]`) and paste it into a page, post, or any widget/block that supports shortcodes.

= Where are submissions stored? =

Submissions are stored in your WordPress database and are viewable under
**MIS Webform → Submissions**, where they can also be exported to CSV.

Each submission also records the visitor's IP address and browser user agent string, mainly
useful for spam investigation. These are kept indefinitely along with the submission unless
you delete it yourself - there is currently no automatic expiry. If you're subject to GDPR or
similar privacy regulations, factor this into your own data retention policy, and delete old
submissions manually via **MIS Webform → Submissions** when they're no longer needed.

= How are file uploads validated? =

Each file upload field lets you set allowed file extensions and a maximum size. On submission,
MIS Webform checks both the filename's extension *and* the file's actual content against that
allowlist (using WordPress's own `wp_check_filetype_and_ext()`) - a file renamed to spoof its
extension (e.g. a disguised executable) is rejected even if the filename alone looks fine. This
content-based check is strongest when your host has the PHP `fileinfo` extension enabled,
which is the default on nearly all WordPress hosting - if your host has disabled it, file-type
validation falls back to WordPress core's own weaker built-in checks.

= Does this plugin load anything from third-party servers? =

By default, no - all CSS/JS assets, including the date/time picker library, are bundled with the
plugin and served from your own site.

The one exception is Google reCAPTCHA, which is entirely optional and off by default. If you
choose to enable it for a form (under that form's Spam Protection settings), the plugin will:

* Load Google's reCAPTCHA widget script (`https://www.google.com/recaptcha/api.js`) on pages
  where that form appears.
* Send the visitor's reCAPTCHA response, together with their IP address, to Google's
  `recaptcha/api/siteverify` endpoint when the form is submitted, to verify it wasn't a bot.

This only happens for forms where you've explicitly turned reCAPTCHA on and entered your own
Google reCAPTCHA site/secret keys - if you never enable it, no data ever leaves your site for
this purpose. If you do enable it, consider mentioning Google reCAPTCHA in your site's privacy
policy, as its use is subject to [Google's Privacy Policy](https://mistechnolabs.com/privacy-policy)
and [Terms of Service](https://mistechnolabs.com/terms).

= Does MIS Webform include AI features? =

The free version does not - it's a complete, standalone form builder with no external account or
service required. An AI Form Generator is available in [MIS Webform Pro](https://mistechnolabs.com/mis-webform-pro),
which is documented separately since it involves a connected account and third-party AI service.

= What happens to my data if I uninstall the plugin? =

Your forms and submissions are kept by default, even if you delete the plugin - deactivating
never touches your data, and deleting it only removes the plugin's files unless you've
explicitly opted in to full cleanup. If you do want your forms and submissions removed when you
delete the plugin, check **MIS Webform → Settings → "Delete all MIS Webform forms and submissions when
uninstalling"** before deleting it. This is off by default specifically so you don't lose
customer/contact data by accident.

== Credits ==

This plugin bundles [flatpickr](https://flatpickr.js.org/) 4.6.13 (MIT license) for its date/time
picker fields.

== Changelog ==

= 1.0.1 =
* Fixed: the custom database tables used DATETIME DEFAULT CURRENT_TIMESTAMP
  (and, on one column, ON UPDATE CURRENT_TIMESTAMP), which isn't supported
  on all MySQL/MariaDB versions.

= 1.0.0 =
* Initial release.