=== Pigeon Form ===
Contributors: clickwebstudio
Tags: contact form, forms, form builder, lightweight, privacy
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 0.1.8
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Contact forms that make no outbound requests, load nothing on pages without a form, and keep every entry in your own database.

== Description ==

Most form plugins arrive with a page builder's worth of JavaScript, a dashboard
that calls home, and fonts fetched from someone else's CDN. Pigeon Form is the
opposite bargain: a working contact form in about a minute, and nothing on your
site that you did not ask for.

**What makes it different**

* **It makes no outbound network requests. None.** No licence pings, no usage
  statistics, no fonts from a CDN, no remote assets. Search the source for
  `wp_remote_get`, `wp_remote_post` or `curl_exec` and you will find nothing.
* **Nothing loads on pages without a form.** The stylesheet and script are
  registered up front but enqueued only when a form actually renders.
* **Entries stay in your database.** They are yours, on your server, and
  deletable. IP addresses are anonymised unless you turn that off.
* **No page builder, no framework, no block library.** The editor is the
  WordPress admin, and the front end is plain HTML and one small script.
* **Your data is kept until you say otherwise.** Deleting the plugin leaves
  your forms and entries in place, so removing it by mistake loses nothing.
  Turn on "Delete all Pigeon Form data when the plugin is deleted" in the
  settings and deleting it removes its tables, options and entries instead.

**Building forms**

* Unlimited forms and fields
* Drag fields in from the palette and drag them into order
* Text, email, paragraph, dropdown, multiple choice, checkboxes, number, phone,
  URL, consent and hidden fields
* Shortcode and block embedding

**Entries and notifications**

* Every submission saved to your site, with a searchable Entries screen
* Admin notification emails and an optional autoresponder
* Smart tags — `{all_fields}`, `{form_title}`, `{site_name}` and any field id

**Spam, without a CAPTCHA**

* A honeypot field, a timing check and a rate limiter, all on by default
* No third-party captcha service, so no visitor data leaves your site and
  nobody has to identify traffic lights to contact you

**Accessibility**

Real labels tied to their inputs, `aria-invalid` on fields that fail
validation, focus moved to the first error, and a form you can complete with a
keyboard alone.

**Pigeon Form Premium**

The free plugin is not a trial and nothing in it is switched off. Premium is a
separate plugin that adds capabilities this one does not contain: a visual
builder with live preview, conditional logic, multi-page forms, file uploads,
advanced field types, captcha integrations, CSV export and third-party
integrations.

== Installation ==

1. Upload the `pigeon-form` folder to `/wp-content/plugins/`, or install through Plugins → Add New.
2. Activate the plugin.
3. Go to **Pigeon Form → Add New Form** to build your first form.
4. Copy the shortcode, or add the **Pigeon Form Form** block to any page.

== Frequently Asked Questions ==

= Where are my submissions stored? =

In two custom database tables, `wp_pigeon_forms_entries` and `wp_pigeon_forms_entry_meta`.
You can browse them under Pigeon Form → Entries, or turn storage off entirely in the
settings if you only want the notification email.

= Does it work without JavaScript? =

Yes. Forms submit normally and are re-rendered server-side with inline errors.
JavaScript only upgrades that to an in-place submit.

= Will it slow my site down? =

The stylesheet and script are only enqueued on pages that actually render a form,
and neither depends on jQuery.

= How do I remove all data on uninstall? =

Enable "Delete all Pigeon Form data when the plugin is deleted" in the settings first.
Without that, deleting the plugin leaves your forms and entries intact.

== Screenshots ==

1. The form editor.
2. The Entries screen.
3. A form on the front end.

== Third-party resources ==

The admin screens use two bundled typefaces. Both are served from this plugin —
nothing is requested from a font host, so no visitor or administrator data
leaves your site.

* Plus Jakarta Sans — SIL Open Font License 1.1, https://github.com/tokotype/PlusJakartaSans
  (assets/fonts/plus-jakarta-sans-*.woff2, licence in assets/fonts/LICENSE-PlusJakartaSans.txt)
* JetBrains Mono — SIL Open Font License 1.1, https://github.com/JetBrains/JetBrainsMono
  (assets/fonts/jetbrains-mono-*.woff2, licence in assets/fonts/LICENSE-JetBrainsMono.txt)

Licence text for both: https://scripts.sil.org/OFL

== Changelog ==

= 0.1.8 =
* The Pigeon plugins sit together in the admin menu, one below another, instead of wherever their menu positions landed among other plugins' items.

= 0.1.7 =
* The admin menu uses the Pigeon family mark: the Pigeon SEO pigeon with a small form badge, so the plugins read as one family and stay easy to tell apart.

= 0.1.6 =
* Security: every value taken from a request is sanitized before it is stored or handed to a hook. Form fields keep only the settings their type declares, each cleaned for what it holds; unknown keys are dropped. Form settings keep only the settings the plugin defines. Submissions and the settings screen sanitize every key and value on arrival.
* Security: the preview endpoint sanitizes the unsaved schema and settings it is sent, the same way a save does.
* Copy buttons are checked with wp_kses() where they are printed.

= 0.1.5 =
* The submit button is set up on the canvas: select it to edit its text, the label shown while sending, its alignment and whether it spans the form. Those four controls have left the Settings tab, which was describing something on the previous screen.
* Full width is a toggle above alignment, and alignment is hidden while it is on rather than shown and ignored.
* The redirect URL only appears when "Submit without reloading the page" is off — with it on the visitor never leaves the page.
* Fix: Edit, Duplicate and Trash on the forms list showed no pointer and did not respond. The faded "edited ... ago" note is an inline box and paints above the actions, so an invisible timestamp was taking the hover and the click.

= 0.1.4 =
* Fix: choosing a label position or a confirmation behaviour left the highlight on the previously saved option. The radio moved but the styling did not, so the control looked broken and a change made without saving was easy to lose.
* The submit button can be aligned left, centre or right, or made full width — and it is selectable in the editor canvas, where its text, sending label, alignment and width are edited in the inspector like any field.
* Fix: the copy button beside a shortcode drew as a full-size admin button and sat above the chip's midline.
* Segmented choices now show a focus ring, so a keyboard can tell which option it is on.

= 0.1.3 =
* Forms load their stylesheet again. It had been registered under a filename that did not exist, so forms rendered with unstyled browser controls.
* Dropdowns, date and time fields, file inputs, checkboxes and sliders have been restyled to match the rest of the form.
* The field row actions are proper icons instead of text arrows, in one shape rather than four different colours.
* Fields can be dragged to reorder them, using the handle at the left of each row. The arrow buttons still work, for trackpads and keyboards.
* Every row action now has a tooltip, and reads correctly in a screen reader.

= 0.1.2 =
* Fixed the plugin homepage and upgrade links pointing at a domain that no longer exists.

= 0.1.0 =
* Initial release.
