Thimbleform is a form builder for lead capture and feedback.
Builder
- Unlimited forms, starter templates (open on Add New when the canvas is empty)
- Drag-and-drop fields, undo, live preview
- Conditional show/hide, file uploads, layout blocks (heading, image, HTML)
- Appearance skins and per-form styling
- Duplicate forms, JSON import/export, import from Contact Form 7 and WPForms
Inbox & mail
- Entries with New / Read / Spam, star, CSV export, printable entry view
- Response summary: totals, fill rate, most chosen / most skipped answers
- Plain-text notifications, CC/BCC, optional autoreply
- Outbound webhooks (HTTPS endpoints you configure per form)
Spam & embed
- Honeypot, time trap, rate limit, optional Akismet
- Google reCAPTCHA v2/v3 via Thimbleform → Integrations
- Gutenberg block and shortcode
[thimbleform id="123"]
Admin
- Dashboard with submission charts
- Light / dark admin theme
Optional Thimbleform Pro is a separate add-on (thimbleform-pro), sold via Freemius and hosted outside the WordPress.org directory. Premium code is not included in this download. It adds multi-step flows, quizzes and surveys, Stripe payments, HubSpot sync, advanced fields, HTML email, PDF attachments, automations, and richer analytics. Compare features under Thimbleform → Pro.
External services
This plugin can connect to optional third-party services configured by the site administrator:
Outbound webhooks (optional)
- Used for: POST JSON to HTTPS endpoints you configure per form (Settings → Webhooks).
- When: after each successful submission, if webhooks are enabled for that form.
- Data sent: form fields, entry metadata, and site URL — only to URLs you enter.
Google reCAPTCHA (optional)
- Used for: spam protection on forms.
- When: after you save site and secret keys under Thimbleform → Integrations.
- Data sent: challenge response tokens and related anti-spam data per Google’s policies.
- Terms: https://policies.google.com/terms
Cloudflare Turnstile (optional)
- Used for: spam protection on forms (alternative captcha provider).
- When: after you choose Turnstile and save site/secret keys under Thimbleform → Integrations.
- Data sent: challenge tokens to Cloudflare per Cloudflare’s policies.
- Terms: https://www.cloudflare.com/website-terms/
hCaptcha (optional)
- Used for: spam protection on forms (alternative captcha provider).
- When: after you choose hCaptcha and save site/secret keys under Thimbleform → Integrations.
- Data sent: challenge tokens to hCaptcha per hCaptcha’s policies.
- Terms: https://www.hcaptcha.com/terms
Akismet (optional)
- Used for: spam scoring of submissions when the Akismet plugin is installed and configured.
- When: after a form is submitted, if Akismet is available on the site.
- Data sent: form field content and comment-check metadata to Automattic’s Akismet service per Akismet’s privacy policy.
- Terms: https://akismet.com/tos/
Stripe (optional — Thimbleform Pro payment fields)
- Used for: accepting card payments on forms that include a Payment field.
- When: after you enable Stripe and save API keys under Thimbleform → Integrations, enable Stripe on the form, and add a Payment field (requires Thimbleform Pro).
- Data sent: payment amounts, currency, and payment intent metadata to Stripe; card details go directly to Stripe (never through Thimbleform servers).
- Terms: https://stripe.com/legal
- Privacy: https://stripe.com/privacy
HubSpot (optional — Thimbleform Pro)
- Used for: creating or updating HubSpot CRM contacts from form submissions.
- When: after you enable HubSpot and save a Private App access token under Thimbleform → Integrations, enable HubSpot on the form, map fields, and Thimbleform Pro is licensed.
- Data sent: mapped contact properties (typically email, name, phone, company) to HubSpot’s CRM API.
- Terms: https://legal.hubspot.com/terms-of-service
- Privacy: https://legal.hubspot.com/privacy-policy
thimbleform.app / Freemius (optional — Pro purchase only)
- Used for: purchasing Thimbleform Pro and managing your Freemius license.
- When: only if you choose to buy Pro (checkout opens Freemius).
- The free plugin does not require a Freemius or thimbleform.app account to run.
Bundled fonts
Admin UI uses self-hosted Plus Jakarta Sans and Sora (SIL Open Font License 1.1). Font files ship under assets/fonts/ with assets/fonts/OFL.txt. No Google Fonts CDN is used.
Bundled flags
The phone country picker uses self-hosted SVG flags from flag-icons (MIT). Files ship under assets/flags/ with assets/flags/LICENSE.txt. No flag CDN is used.