Build a secure WordPress form from one sentence
T-Builder 0.9.9 adds a WordPress form builder with spam protection. Describe the form, or take it from a template, and get a widget with a nonce, honeypot, rate limit and stored entries.
Every site needs at least one form, and every form is a door for spam and for sloppy input. Version 0.9.9 of T-Builder turns the form into something the agent builds and secures in one go: a WordPress form builder with spam protection that starts from a sentence.
Three ways to get a form
The new form-save tool takes its definition from any of three sources:
- A description. "A quote request with name, e-mail, company, a choice between three services, a file upload and a message." The agent turns it into typed fields with labels and validation.
- Template HTML. The
<form>from the template you dropped in, with its fields, placeholders and layout read from the markup. - A converted section. When the template converter finds a form inside a section, that form becomes a form definition instead of a dead
<form>tag.
Whichever way it starts, the result is a saved form you can place anywhere.
The Elementor widget and the shortcode
The form is shown by the Elementor T-Builder Form widget, which lists your saved forms and lets you pick one, and by a shortcode for places Elementor does not reach. Both render the same form, with the same protection, and both submit to the site itself.
What "secure" means here
Each form comes with the protection a developer would add by hand, switched on from the start:
- A CSRF nonce on every render, checked on every submit.
- A honeypot field that bots fill in and people never see.
- A rate limit per address, so one visitor cannot send the same form a hundred times.
- Typed validation: e-mail fields must be e-mail addresses, numbers must be numbers, required means required, and the rules are the same on the server as on the page.
- Private uploads: files go to a folder outside the public uploads, reachable only from the entries screen.
Two things are optional, per form: a Turnstile or reCAPTCHA challenge, and an e-mail confirmation code, where the visitor has to enter the code sent to the address before the entry counts. The second one is what stops the "wrong e-mail address" support tickets.
Stored entries
Every submission is stored on the site and listed in wp-admin with its fields, its files and the time. Notifications by e-mail are set per form. Nothing leaves the site unless you say so.
Available now
Update to 0.9.9 from your account and ask the chat for a form. Building it is one conversation step; the pricing page shows what a step costs. Serving the form and storing entries costs nothing.