Streamery Forms is a form builder for the WordPress block editor. You compose a form the same way you compose any other page — by adding blocks — and every submission is stored in an inbox inside your WordPress admin, so nothing depends on an email actually arriving.
Building forms
Handling submissions
Every submission runs through a chain of providers:
Inbox
Spam protection
All of these are enforced on the server. A submission cannot bypass them by talking to the REST endpoint directly.
Privacy
Streamery Forms does not contact any external service on its own. The following are optional and only ever active once you configure them.
Google reCAPTCHA — only when you enable reCAPTCHA and enter your keys under Streamery Forms Settings CAPTCHA. When enabled, the reCAPTCHA script is loaded from Google on pages containing a form, and the visitor’s CAPTCHA response token plus their IP address are sent to Google for verification on submit.
Service: https://www.google.com/recaptcha/
Terms: https://policies.google.com/terms
Privacy policy: https://policies.google.com/privacy
FriendlyCaptcha — only when you enable FriendlyCaptcha and enter your keys under Streamery Forms Settings CAPTCHA. The widget script is bundled with the plugin, not loaded from a third party. On pages with a CAPTCHA block it requests a puzzle from the FriendlyCaptcha API, and on submit the visitor’s solution is sent to the FriendlyCaptcha API for verification.
Service: https://friendlycaptcha.com/
Terms: https://friendlycaptcha.com/legal/terms/
Privacy policy: https://friendlycaptcha.com/legal/privacy/
Webhook provider — only when you add a webhook feed. Submissions of the forms you assign it to are sent to the URL you configure. That endpoint is yours; where the data goes and how it is handled is determined entirely by the address you enter. No default endpoint exists and nothing is sent anywhere unless you set one up.
Some JavaScript and CSS in this plugin is compiled. The complete, human-readable source ships inside the plugin in the src/ folder, together with the build configuration. Every compiled file begins with a comment naming its source folder. The same code is also public and maintained at:
https://github.com/streamery-de/streamery-forms
Compiled file source:
assets/blocks/{block}/index.js, view.js, *.css src/blocks/{block}/ (e.g. assets/blocks/select/view.js src/blocks/select/view.ts), built with @wordpress/scripts (webpack.config.js)assets/blocks/skins/default/ src/skins/default/assets/blocks/{number}.js shared, lazy-loaded chunks of the HTML email editor: currently 3024.js from src/components/email-template-editor/HtmlCodeEditor.tsx and 3468.js with the bundled CodeMirror library (see below)assets/admin/dist/ src/admin/, src/components/, src/lib/, src/hooks/, built with Vite (vite.admin.config.js, tailwind.config.js, postcss.config.js)assets/admin/deactivate.js and assets/admin/deactivate.css are not compiledTo rebuild the compiled files (Node.js 20, Composer):
composer install --no-dev --optimize-autoloadernpm cinpm run build (runs vite build -c vite.admin.config.js and wp-scripts build)Bundled third-party libraries (all MIT or ISC licensed; exact versions in package-lock.json and vendor/composer/installed.json):
libs/assets.php) — https://github.com/kucrut/vite-for-wpvendor/) — https://github.com/prappo/wp-eloquent