Kontelio connects a flexible WordPress contact form to email, Telegram and the WhatsApp Cloud API. Enable any combination of channels, or send private notifications that link to an encrypted local inbox.
Hosting, email providers and Meta may charge. WhatsApp needs business onboarding, a Cloud API number, token and approved template, not a personal account. No affiliation with Telegram, WhatsApp or Meta; no legal-compliance guarantee.
Enable Extended privacy per channel. It sends only a generic notice, site name and admin link: no visitor name, email, phone, subject or answers. Email omits visitor Reply-To. Provider credentials and routing metadata remain necessary. Channels with this mode off still receive full content.
If an active channel uses extended privacy, validated details are stored in this site’s database using AES-256-GCM before delivery. OpenSSL is required. Storage failure blocks ALL channels; there is no plaintext fallback. Successful storage counts as acceptance even if notifications fail. Check the inbox and diagnostics; there is no retry queue.
Links contain an ID, not an access token. Access requires WordPress login and manage_options. No public/search/REST exposure. Admins can delete inquiries; WordPress personal-data export/erasure matches email fields.
Retention: 30 days by default, 1–36500 whole days or 0 permanently. Unsupported timestamp ranges are rejected. Changes affect NEW inquiries only. Expired items become unreadable and receive bounded hourly/admin cleanup. WP-Cron needs visits or server cron. Permanent items remain until deletion/uninstall; backups may retain copies.
Encryption uses WordPress security salts. Losing/changing keys makes existing inquiries unreadable; securely back them up. Database plus keys permit decryption. Use HTTPS; protect accounts, hosting and backups. Disabling privacy leaves existing inquiries.
Use text, email, telephone, textarea, select or checkbox fields. Set labels, placeholders, requirements, widths and up to 20 options. Original fields are removable; consent stays separate. Editing needs JavaScript; submissions do not. Unknown/removed fields are ignored; at least one answer is required.
Full-content email/Telegram include ordered labelled answers; the first completed valid email supplies Reply-To only for full-content email. Limits: 12,000 combined characters, plus field limits; full-content Telegram 4,000 UTF-16 units; full-content WhatsApp 500 labelled characters and 900 across five parameters. Provider content limits exclude privacy notifications. Oversized submissions are rejected, not truncated.
Use [kontelio]. Existing [contact_bridge] shortcodes from earlier development builds remain supported; use [kontelio] for new content. Override an instance with theme="light|dark|auto", shape="rounded|square", heading="Your heading" or embedded="true|false".
Seamless embedding removes the outer card, keeping fields/maximum width. Match colors to your theme. Preview never saves/sends; tests send notifications. Presets preserve content and privacy settings.
Set the consent link’s label, URL and tab behavior. {privacy_link} positions it; otherwise it is appended. Without a URL it is text. Executable HTML/URL schemes are rejected.
New installations follow the WordPress language; English is the source and fallback language. Existing saved language choices and custom text are preserved. A complete German translation is maintained separately in the repository translations/ directory and a separate language-pack ZIP. Translation catalogs are not included in the installable plugin ZIP. Until a WordPress.org German language pack is available, copy kontelio-de_DE.mo to wp-content/languages/plugins/ and choose German or a German WordPress locale. Without an installed matching language pack, the plugin displays English. German language packs are distributed through WordPress.org once the translations are approved.
Providers are contacted for enabled deliveries, requested tests and Telegram confirmation, never form/preview views. They see the server connection and routing/account data; notifications omit visitor IPs. Tests use sample data or a privacy notification with an inbox overview link, never the administrator’s email as sample content.
Use WordPress mail or your provider’s SMTP host. Sender/recipient are separate. SMTP supports STARTTLS/implicit TLS and password/app-password login with certificate verification. No OAuth client is included. Settings affect this plugin only; existing mail integrations may take over. Full content includes labelled answers and optional visitor Reply-To; privacy sends notice, site name and admin URL. Provider/recipient retention applies. Acceptance does not prove arrival.
Telegram Bot API
Uses https://api.telegram.org/bot<TOKEN>/sendMessage: token, chat ID and full content or privacy notification. Link previews are disabled. Requested getUpdates confirmation saves a private chat only after matching the admin’s temporary code. Chat members can read messages; bot chats are not Secret Chats.
WhatsApp Business Platform / Meta Cloud API
Uses https://graph.facebook.com/<API_VERSION>/<PHONE_NUMBER_ID>/messages: Bearer token, sender ID, operator number, template name/language and parameters. Full content uses five body parameters: name, email, subject, labelled details, site name. Privacy requires a SEPARATE approved template with two: site name, admin URL. Meta/recipient process this data; the recipient must agree to notifications. Meta determines approval, availability and charges.
Full-content-only setups create no inquiry archive. Keyed IP/request hashes enforce five attempts/ten minutes; done status lasts one hour, locks two minutes, health 24 hours and Telegram codes ten minutes. No raw IP is stored. Optional email logs: up to 50 events/seven days, containing time, method, context, result and safe error category. No addresses, subjects, bodies, passwords or raw server replies. Admins can clear/disable logs. Hosting/software may keep other records.
SMTP passwords use salt-based encryption or TSCB_SMTP_PASSWORD; changed salts require re-entry. Messenger tokens are unencrypted, non-autoloading options, or use TSCB_TELEGRAM_TOKEN / TSCB_WHATSAPP_TOKEN in wp-config.php. Protect backups. Uninstall removes inquiries, database runtime data and logs; settings/credentials only if enabled. External-cache keys expire. Provider messages, backups and wp-config constants need separate handling.