Contact Form Builder, Lead Capture & Inbox CRM – ContactIn
ContactIn helps teams move from “message received” to “message handled” with less manual work and better visibility. Every submission lands in one inbox, contacts are updated automatically, and intent is classified with keyword rules tailored to your industry profile. If you need a contact form plugin that stores submissions in your WordPress database, ContactIn combines form builder, lead capture, inbox workflow, and delivery reliability in one system. Instead of splitting traffic across multiple forms, you can run one smart form for sales, support, and general inquiries, then triage quickly inside a single workflow. If your goal is to capture more leads, respond faster, and keep operations organized as volume grows, ContactIn is built for that. You get one workflow for capture, triage, response, and reporting: Form builder with shortcode, Gutenberg block, and Elementor widget Unified inbox with fail-safe capture flow — search, filters, status pipeline, and notes Intent classification: keyword-based patterns across 19 industry-specific profiles Real-time analytics: submissions, trends, response performance, and delivery visibility Email deliverability toolkit: SMTP, SPF/DKIM/DMARC checks, HTML templates, TLS/SSL, queue with retries Multi-layer spam protection: reCAPTCHA v3, honeypot, rate limiting Queue reliability engine: deduplication (30-day window), dead-letter queue support, and automatic stuck-item recovery Consent capture support for compliance-oriented form workflows Automatic contact capture and profile updates (phone normalization, deduplication, CSV/JSON export) Safe lifecycle handling for activation, deactivation, and uninstall operations Why Teams Choose ContactIn Faster first-response handling with clear inbox status, filters, and notes Cleaner lead pipeline with auto-captured contacts and deduplication support Better operational confidence with queue visibility, retries, and diagnostics Lower manual overhead by combining capture, routing, and reporting in one plugin Flexible deployment for agencies and multi-team workflows across many industries The Problem We Solve When businesses receive contact form submissions, they often hit the same growth blockers: Messages scattered across email, spreadsheets, and internal chat No consistent way to prioritize sales vs support vs spam Slow response times and missed high-intent leads Manual data entry and inconsistent follow-up Limited visibility into which forms and campaigns perform best ContactIn addresses these blockers by centralizing submissions, improving triage speed, maintaining contact records, and giving your team clearer analytics and delivery visibility. How It Works Capture leads from your form (shortcode, block, or Elementor widget). Classify intent automatically using industry-specific keyword profiles. Route and manage submissions in a unified inbox with filters, status, and notes. Measure performance with analytics and delivery logs. Monitor queue health and maintain your submission pipeline. Who It’s For ContactIn is designed for teams that need faster response and clearer message routing: SaaS and software teams E-commerce and retail stores Service and consulting firms Healthcare and medical clinics Education and training providers Hospitality and travel businesses Banking and financial services Insurance teams Legal services and law firms Real estate teams Construction and home services Automotive and dealerships Logistics and courier services Telecom and ISP providers Supermarkets and grocery Travel agencies and tours Embassy and high commission services Quality agencies and certification bodies Agencies and multi-client operations Features Form Builder & Frontend Integration * Shortcode: [contactin_form] * Native Gutenberg block * Elementor widget * Configurable fields and validation * Responsive form UI * Per-profile settings (labels, messages, optional fields, consent) Unified Inbox & Contact Management * Centralized submission inbox with fail-safe capture (no lost messages) * Search and filtering * Bulk actions * Status pipeline (unread, read, archived, spam) * Threading and internal notes * Automatic contact creation and updates (including phone changes) * Phone number normalization and validation * Duplicate submission detection and cleanup tools * CSV/JSON exports * Contact timeline context to support faster follow-up and cleaner handoff Intent Classification (Keyword-Based) * Categories: Sales, Support, Feedback, Complaints, Questions * Keyword-based classification with custom rule support * Business-type profiles to improve relevance by industry * 19 industry profiles: Generic, SaaS, E-commerce, Service, Healthcare, Education, Hospitality, Banking, Insurance, Embassy, Quality Agency, Travel Agency, Supermarket, Legal, Logistics, Telecom, Automotive, Construction, Real Estate Analytics & Reporting * Submission volume tracking * Conversion and response metrics * Geographic and device-level insights * Performance monitoring * Delivery and queue observability * Dashboard widgets for daily operational visibility Deliverability & Reliability * SMTP support (Gmail, SendGrid, Mailgun, AWS SES, Outlook, custom) * Anti-spam headers and sender-domain checks * SPF/DKIM/DMARC mismatch warnings * Professional HTML email templates and TLS/SSL encryption * Delivery queue with retries and delivery logs * Async queue with retries, deduplication, dead-letter handling * Queue maintenance tools and diagnostics * Queue health monitoring for stalled processors/locks * Circuit-breaker and retry behavior designed to prevent silent message loss Queue Reliability & Deduplication * Idempotent queue engine: deduplication window extended to 30 days for maintenance operations * Automatic recovery for stuck “processing” items (older than 10 minutes reset to pending) * Dead-letter queue (DLQ) with per-item and bulk retry, idempotent retry button (safe to click multiple times) * Before/after statistics and last retry timestamp displayed in Maintenance panel Operations, Logs & Maintenance * Email, cron, and queue log tables for troubleshooting * Background cleanup of stale logs, orphaned entries, and old records to keep the system tidy * Safe activation/deactivation lifecycle handling * Safe uninstall path with cleanup controls Security & Compliance * Google reCAPTCHA v3 * Honeypot and rate limiting * Duplicate submission safeguards * Consent checkbox/capture support for compliance-oriented forms What’s Included This version includes a complete contact management solution: Multiple form profiles (unlimited — label, fields, messages, consent, reCAPTCHA override) Unified inbox + search/filter + bulk actions Keyword-based intent classification with 19 industry profiles Industry-specific business-type profiles Analytics dashboard (core metrics) Core spam protection (reCAPTCHA + honeypot + baseline throttling) SMTP + deliverability checks + queue reliability Consent capture support for compliance-oriented forms Automatic data capture from every submission to continuously grow your contact list Contact auto-capture and profile updates with phone normalization ContactIn Pro ContactIn Pro is available for teams that need extended automation and deeper reporting. Both Free and Pro versions capture every submission and help grow your contact list automatically. For current Pro capabilities and support, visit: https://contactinbox.app/ Source Code and Build Assets Public source snapshots and release packages for this plugin are available at: https://github.com/bizjaved/contactin-release https://github.com/bizjaved/contactin-release/releases This plugin includes human-readable source for distributed minified assets. Distributed assets: dist/js/ dist/css/ Readable source directories available in the public repository: assets/src/js/ (source for dist/js/*.min.js) assets/src/css/ (source for dist/css/*.min.css) Custom JavaScript minified -> source mapping: dist/js/admin-email-log.min.js -> assets/src/js/admin-email-log.js dist/js/admin-global.min.js -> assets/src/js/admin-global.js dist/js/admin-inbox.min.js -> assets/src/js/admin-inbox.js dist/js/admin-settings.min.js -> assets/src/js/admin-settings.js dist/js/attachment-cleanup.min.js -> assets/src/js/attachment-cleanup.js dist/js/confetti.min.js -> assets/src/js/confetti.js dist/js/dashboard-analytics.min.js -> assets/src/js/dashboard-analytics.js dist/js/dashboard-chart-renderer.min.js -> assets/src/js/dashboard-chart-renderer.js dist/js/dashboard-date-utils.min.js -> assets/src/js/dashboard-date-utils.js dist/js/dashboard-render-helpers.min.js -> assets/src/js/dashboard-render-helpers.js dist/js/dashboard-sparkline.min.js -> assets/src/js/dashboard-sparkline.js dist/js/dashboard-tabs.min.js -> assets/src/js/dashboard-tabs.js dist/js/dashboard-widgets-live.min.js -> assets/src/js/dashboard-widgets-live.js dist/js/elementor-editor.min.js -> assets/src/js/elementor-editor.js dist/js/frontend.min.js -> assets/src/js/frontend.js dist/js/gutenberg-block.min.js -> assets/src/js/gutenberg-block.js dist/js/maintenance.min.js -> assets/src/js/maintenance.js dist/js/sf-attachment-settings.min.js -> assets/src/js/sf-attachment-settings.js Custom CSS minified -> source mapping: dist/css/admin-global.min.css -> assets/src/css/admin-global.css dist/css/admin-inbox.min.css -> assets/src/css/admin-inbox.css dist/css/admin-inbox-old.min.css -> assets/src/css/admin-inbox-old.css dist/css/admin-settings.min.css -> assets/src/css/admin-settings.css dist/css/attachment-cleanup.min.css -> assets/src/css/attachment-cleanup.css dist/css/contact-detail.min.css -> assets/src/css/contact-detail.css dist/css/contact-detail-tabs.min.css -> assets/src/css/contact-detail-tabs.css dist/css/contact-edit-modal.min.css -> assets/src/css/contact-edit-modal.css dist/css/crm-log.min.css -> assets/src/css/crm-log.css dist/css/dashboard-analytics.min.css -> assets/src/css/dashboard-analytics.css dist/css/dashboard-widgets.min.css -> assets/src/css/dashboard-widgets.css dist/css/elementor-editor.min.css -> assets/src/css/elementor-editor.css dist/css/frontend.min.css -> assets/src/css/frontend.css dist/css/gutenberg-editor.min.css -> assets/src/css/gutenberg-editor.css dist/css/inbox-consolidated.min.css -> assets/src/css/inbox-consolidated.css dist/css/logs.min.css -> assets/src/css/logs.css dist/css/maintenance.min.css -> assets/src/css/maintenance.css dist/css/sf-attachment-settings.min.css -> assets/src/css/sf-attachment-settings.css dist/css/tests.min.css -> assets/src/css/tests.css Third-party bundled libraries and public sources: Chart.js v4.5.1 (bundled as dist/js/vendor/chart.min.js) Source: https://github.com/chartjs/Chart.js License: MIT Select2 v4.1.0-rc.0 (bundled as dist/js/vendor/select2.min.js and dist/css/vendor/select2.min.css) Source: https://github.com/select2/select2 License: MIT Additional distributed JS/CSS that are already human-readable (not minified/compressed): dist/js/admin-settings-attachment-restapi.js dist/js/admin-settings-autosave.js dist/js/contactin-profile-core.js dist/js/contact-deletion.js dist/js/contact-detail-tabs.js dist/js/contact-edit-modal.js dist/js/gdpr-frontend.js dist/js/gdpr.js dist/css/form-error-modal.css dist/css/gdpr-frontend.css dist/css/get-started.css dist/css/intent-classification.css How to rebuild generated/minified assets (from plugin root): Install build tools (if needed): npm install –no-save terser clean-css-cli Rebuild JavaScript minified assets from source: for f in assets/src/js/*.js; do \ npx terser “$f” -c -m -o “dist/js/$(basename “${f%.js}”).min.js”; \ done Rebuild CSS minified assets from source: for f in assets/src/css/*.css; do \ npx cleancss -o “dist/css/$(basename “${f%.css}”).min.css” “$f”; \ done Rebuild one specific file examples: JS: npx terser assets/src/js/dashboard-widgets-live.js -c -m -o dist/js/dashboard-widgets-live.min.js CSS: npx cleancss -o dist/css/dashboard-analytics.min.css assets/src/css/dashboard-analytics.css Build prerequisites: Node.js + npm (for terser / clean-css-cli) Composer for PHP autoload/dependency management (see composer.json) Public source code locations (required for review/forking): Main repository (public): https://github.com/bizjaved/contactin-release Tagged releases: https://github.com/bizjaved/contactin-release/releases JavaScript source tree: https://github.com/bizjaved/contactin-release/tree/main/assets/src/js CSS source tree: https://github.com/bizjaved/contactin-release/tree/main/assets/src/css Review note for WordPress.org: every compressed asset in dist/js/.min.js and dist/css/.min.css is generated from files in assets/src/js and assets/src/css, and those source files are publicly accessible in the repository links above. All plugin PHP source is included in this package under includes/ and templates/. Quick Start Install and activate ContactIn. Add [contactin_form] to a page/post (or use block/widget). Configure email delivery in Settings > Email (SMTP recommended). Configure spam protection in Settings > Security. Start capturing and organizing contact submissions. External Services This plugin may connect to the following external services depending on your configuration. No data is sent to any service without your explicit setup. 1. SMTP provider (user-configured, optional) This plugin can send notification emails via an external SMTP server that you configure. Supported providers include Gmail, SendGrid, Mailgun, AWS SES, Outlook, and any custom SMTP server. Data sent is limited to the email content (sender, recipient, subject, body). This only activates if you enable and configure SMTP in Settings → Email. Consult your chosen provider’s own privacy and terms documentation. 2. Google reCAPTCHA (optional) Used for: Spam protection on the contact form front-end. Data sent: Browser/device fingerprint data transmitted to Google servers. Conditions: Only active when reCAPTCHA is enabled in Settings. Privacy Policy: https://policies.google.com/privacy Terms: https://www.google.com/recaptcha/about/ 3. Salesforce CRM (optional) Used for: Sending contact, case/task, and related attachment sync requests when Salesforce CRM integration is configured. Data sent: Contact form fields you map into Salesforce, message metadata needed for sync status, and optional attachment content when file sync is enabled. Conditions: Only active when a site administrator configures Salesforce CRM integration and enables CRM sync features. Privacy Policy: https://www.salesforce.com/company/privacy/ Terms: https://www.salesforce.com/company/legal/agreements/ Privacy & Data Collection Data collected: * Form submission fields entered by users * IP/user agent data for anti-spam and security operations * Submission timestamps and routing metadata Data storage: * Stored in your WordPress database * Sent externally only to services you configure (e.g., reCAPTCHA, SMTP, Salesforce CRM) Optional external services: * Google reCAPTCHA * Your SMTP provider * Salesforce CRM reCAPTCHA policy links: * Privacy Policy: https://policies.google.com/privacy * Terms of Service: https://policies.google.com/terms Documentation Website: https://contactinbox.app/ Docs: https://contactinbox.app/ Support: https://contactinbox.app/ Credits Developed by Javed Ahsan.
Top keywords
- js114×5.35%
- css108×5.07%
- dist62×2.91%
- assets53×2.49%
- min48×2.25%
- assets src47×2.21%
- src47×2.21%
- dist js33×1.55%
- dist css29×1.36%
- js dist26×1.22%
- assets src css24×1.13%
- js dist js24×1.13%
Kitgenix CAPTCHA for Cloudflare Turnstile
Kitgenix CAPTCHA for Cloudflare Turnstile adds Cloudflare Turnstile CAPTCHA and anti-spam protection to WordPress, WooCommerce and a wide range of form, membership, community and ecommerce plugins. Challenges are not treated as a client-side decoration: submitted Turnstile tokens are verified server-side with Cloudflare before a protected action is accepted. The plugin is designed for site owners who want to reduce automated login attempts, fake registrations, comment spam, bot-driven checkout abuse and unwanted form submissions while using Cloudflare’s privacy-oriented Turnstile challenge rather than a traditional image CAPTCHA. Configuration, integration controls, diagnostics and local verification metrics are managed inside WordPress. The only service required for CAPTCHA functionality is Cloudflare Turnstile itself; no Kitgenix verification proxy is used. Learn more about Kitgenix WordPress plugins at Kitgenix. Supported WordPress and Plugin Integrations The codebase contains dedicated integrations for: WordPress login. WordPress registration. Lost-password and password-reset flows. WordPress comments. Custom login forms produced with wp_login_form(). WooCommerce login, registration, lost password, checkout and related account flows supported by the integration. Easy Digital Downloads. Elementor forms. Contact Form 7. WPForms. Gravity Forms. Fluent Forms. Formidable Forms. Forminator. Ninja Forms. Jetpack Forms. JetFormBuilder. Kadence Forms. MailPoet. bbPress. BuddyPress. wpDiscuz. Ultimate Member. MemberPress. Paid Memberships Pro. Kitgenix Plugin Score integration points included in the codebase. Each integration is loaded conditionally and can use integration-specific display/validation behaviour rather than forcing one generic hook onto every form system. Server-Side Turnstile Verification The browser obtains a Turnstile response token from Cloudflare’s official widget. When a protected form is submitted, the plugin sends that token to Cloudflare’s official Siteverify endpoint using the WordPress HTTP API. The protected action is allowed only when the verification result satisfies the integration’s validation flow. This server-side step is important because simply placing a widget in the browser is not sufficient protection on its own. The plugin tracks the most recent verification response, error codes and latency for diagnostics and can record aggregate verification metrics locally. Setup Verification for Login-Sensitive Forms Login, registration and other account-sensitive protections can be gated behind a setup-verification state. The administrator can verify the configured Site Key and Secret Key before those protections are treated as ready. This reduces the risk of enabling a broken key pair on a login screen and accidentally locking legitimate administrators or customers out of the site. Site and secret keys can be supplied from plugin settings or from supported environment variables/constants, allowing security-conscious deployments to keep the secret outside the normal WordPress options table. Replay Protection Turnstile tokens are intended to be short lived and single use. The plugin includes optional replay protection that hashes accepted tokens and temporarily remembers that hash. A token that is submitted again during the replay window can be rejected rather than being accepted repeatedly. The replay window is filterable for developers. Stored replay information is a hash/temporary value, not the raw challenge token itself. Honeypot and Layered Anti-Spam Controls An optional honeypot can be rendered alongside Turnstile. This adds a second low-friction signal for simple bots that fill fields a normal visitor never sees. The plugin also supports whitelisting logic so trusted requests can bypass the challenge where appropriate. Whitelist decisions can take account of configured rules and developer filters rather than hard-coding one bypass mechanism for every site. Trusted Proxy and Client IP Handling Sites may sit behind Cloudflare, another reverse proxy or a load balancer. The client-IP component can be configured to trust proxy headers only when the request path matches the trusted-proxy configuration. This avoids blindly believing spoofable forwarding headers from arbitrary visitors. Administrators can also choose whether the resolved visitor IP is included in the Siteverify request to Cloudflare. A developer filter is available to change that behaviour when required by a site’s privacy or infrastructure policy. Widget Appearance and Placement The plugin supports central defaults plus integration-level overrides for Turnstile appearance. Depending on the supported integration, administrators can control options such as theme, size, appearance and language, and can choose placement behaviour where the integration exposes more than one suitable hook. A manual shortcode is also registered: [kitgenix_turnstile] The shortcode is useful when the site owner needs to render the widget in a supported custom workflow. Rendering a widget alone does not automatically secure arbitrary custom PHP processing; custom form handlers must still validate the submitted token server-side. Diagnostics, Metrics and Site Health The plugin includes diagnostics for configuration and verification health, local counters for passed/failed checks, latency information, recent verification events and integration-level metrics. Site Health integration can surface configuration or connectivity issues to administrators. Developer Mode adds additional troubleshooting detail without changing the fundamental requirement that live submissions be verified correctly when protection is active. Settings Portability Settings can be exported and imported for controlled migration between WordPress installations. The transfer system is designed for plugin configuration rather than for exporting visitor submissions or unrelated site data. Performance and Script Loading The public Cloudflare Turnstile script is loaded only for pages/contexts where the plugin determines that a Turnstile widget may be needed. The loader includes duplicate-script detection so multiple integrations do not intentionally enqueue several copies of the same Turnstile API script. Public assets are kept separate from the admin interface, and admin-only diagnostics/settings code does not need to run as part of every anonymous form request. Privacy and Data Flow Turnstile is an external service provided by Cloudflare, so challenge rendering and server-side verification necessarily communicate with Cloudflare. The plugin itself stores configuration and limited diagnostic/aggregate verification data locally. It does not require a Kitgenix account and does not send form contents to Kitgenix for verification. The exact Cloudflare data flow, WordPress.org Hub request and Google Fonts admin request are documented in the External Services section below. Common Uses Protect a WordPress login page from automated credential attacks. Reduce spam registrations on WordPress or WooCommerce. Add anti-bot verification to WooCommerce checkout and account forms. Protect Elementor and popular WordPress form plugins with one central Turnstile configuration. Add a challenge to membership, forum and community registration/login flows. Replace more intrusive CAPTCHA experiences with Cloudflare Turnstile while keeping server-side validation. Developer Notes Shortcode [kitgenix_turnstile] Main settings option kitgenix_captcha_for_cloudflare_turnstile_settings Useful filters Script and display: kitgenix_captcha_for_cloudflare_turnstile_script_url kitgenix_turnstile_freshness_ms kitgenix_turnstile_inline_style Verification: kitgenix_turnstile_siteverify_url kitgenix_turnstile_siteverify_timeout kitgenix_turnstile_siteverify_sslverify kitgenix_turnstile_siteverify_http_args kitgenix_turnstile_send_remoteip kitgenix_turnstile_remote_ip kitgenix_turnstile_token_from_request kitgenix_turnstile_error_codes kitgenix_turnstile_error_message kitgenix_turnstile_replay_message kitgenix_turnstile_skip_wp_login_validation Replay protection: kitgenix_turnstile_replay_ttl Whitelisting and proxy handling: kitgenix_turnstile_is_whitelisted kitgenix_turnstile_trust_headers kitgenix_turnstile_trusted_proxies Operational alerts: kitgenix_turnstile_alert_window_seconds kitgenix_turnstile_alert_failure_spike_min_failures kitgenix_turnstile_alert_failure_spike_failure_rate kitgenix_turnstile_alert_http_error_min_failures Developer logging action: kitgenix_turnstile_dev_log The plugin also exposes context-specific error-message filtering through kitgenix_captcha_for_cloudflare_turnstile_{context}_turnstile_error_message. Privacy and Local Data The plugin stores its configuration in the WordPress database. Depending on enabled features it also stores local operational data such as setup-verification state, aggregate integration metrics, the recent event log and replay-protection transients. The recent event log is limited to 50 events and contains operational fields such as time, integration, success/failure, error codes and Siteverify latency. It does not store raw form submissions, the raw Turnstile response token, the visitor’s raw IP address or the request URL in that log. Turnstile itself is an external Cloudflare service and receives data when a widget is loaded and when the server validates a token. See External Services below. External Services This plugin relies on third-party services for specific functionality. These connections are documented here so site owners can make an informed decision before enabling and using the plugin. Cloudflare Turnstile Cloudflare Turnstile is the CAPTCHA / bot-verification service that provides the plugin’s core protection. A Cloudflare account and Turnstile Site Key / Secret Key are required. When a protected widget is rendered, the visitor’s browser loads Cloudflare Turnstile from: https://challenges.cloudflare.com/turnstile/v0/api.js The browser communicates with Cloudflare as part of the Turnstile challenge. As with normal web requests, Cloudflare can receive network/request information such as the visitor’s IP address and browser/request metadata, and Turnstile evaluates browser signals to generate a verification token. When a protected form is submitted, the WordPress server sends a POST request to: https://challenges.cloudflare.com/turnstile/v0/siteverify By default, that request contains: The configured Turnstile Secret Key The Turnstile response token The visitor IP address as Cloudflare’s optional remoteip parameter when an address is available The remoteip value can be disabled by developers with the kitgenix_turnstile_send_remoteip filter. Cloudflare documentation: https://developers.cloudflare.com/turnstile/ Cloudflare Terms: https://www.cloudflare.com/website-terms/ Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/ WordPress.org Plugin API The shared Kitgenix Hub in wp-admin uses WordPress core’s plugins_api() functionality to request public WordPress.org plugin-directory information such as plugin details, active-install counts, ratings and media. These requests occur on Kitgenix administration screens. The plugin supplies WordPress.org plugin slugs to WordPress core; the outbound request itself is handled by WordPress and can include normal HTTP request metadata generated by WordPress. Responses are cached locally with WordPress transients to reduce repeat requests. WordPress.org: https://wordpress.org/ WordPress.org Privacy Policy: https://wordpress.org/about/privacy/ Google Fonts The Kitgenix administration stylesheet imports the Inter and Manrope font families from Google Fonts. This occurs on Kitgenix plugin administration screens, not as part of the Turnstile verification request itself. Loading those font resources causes the administrator’s browser to connect to Google-hosted domains such as fonts.googleapis.com and fonts.gstatic.com, which can receive normal request information such as IP address and browser headers. Google Fonts: https://fonts.google.com/ Google Privacy Policy: https://policies.google.com/privacy Google Terms: https://policies.google.com/terms Trademark Notice Cloudflare and Cloudflare Turnstile are trademarks or services of Cloudflare, Inc. This plugin is independently developed by Kitgenix and is not affiliated with or endorsed by Cloudflare, Inc. WordPress and WooCommerce trademarks belong to their respective owners. References are descriptive and identify supported integrations. Support Development Kitgenix CAPTCHA for Cloudflare Turnstile is free software. If the plugin is useful to you, you can support continued maintenance and development through the Donate link shown on the WordPress.org plugin page. More WordPress plugins and development resources are available from Kitgenix.