Flinkform – GDPR Contact Forms for the Block Editor
Flinkform is a form builder that lives entirely inside the WordPress Block Editor. Forms are composed from native blocks (block.json v3), styled through theme.json design tokens, and powered by the Interactivity API — no separate form builder UI, no shortcodes, no jQuery, under 15 KB of frontend JavaScript (gzipped). Built in Germany for GDPR-first websites. Das deutschsprachige Kontaktformular-Plugin für den Block-Editor. Try it before you install it: live demo forms, including multi-step and conditional logic, at https://demo.flinkform.de/ GDPR by design No IP logging, no user-agent logging, no tracking, no external services in the free core. Spam protection runs on a honeypot, a signed timing check and a proof-of-work challenge with a no-JavaScript maths fallback — no reCAPTCHA, no hCaptcha, no Cloudflare Turnstile, and therefore no data transfer to US servers. Includes a consent field, retention periods with automatic deletion and integration with the WordPress privacy tools. Free, not a trial Multi-step forms and conditional logic are in the free core, not behind a paywall: Multi-step forms with progress indicator and per-step validation Conditional logic for fields, steps, skipping steps and gating the submit button 14 field types including a dedicated consent field Submissions dashboard inside WordPress with search, filters and read state Email notifications with merge tags, plus an optional confirmation mail Automatic theme.json styling — forms match your theme without extra CSS Built for accessibility: the rendered markup passes axe-core against WCAG 2.1 A/AA with zero violations Flinkform Pro The optional Pro add-on adds Stripe payments (card, SEPA direct debit, Apple Pay, Google Pay — whichever methods you enable in Stripe), calculation fields, multi-file upload, SMTP delivery, webhooks, newsletter integrations, CSV export and custom CSS. Details and pricing: https://flinkform.de/pro Requirements WordPress 6.5 or newer, PHP 8.1 or newer, Block Editor (Gutenberg). How it works Block Editor native — forms are built with block.json and the Interactivity API, directly inside the editor theme.json styling — forms inherit your theme’s typography, colours and spacing automatically Modern stack — WordPress 6.5+, PHP 8.1+, no jQuery, frontend JS under 15 KB gzipped Multi-step forms — split long forms into steps with a Page Break block, included in the free core Conditional logic — show/hide fields based on user input, included in the free core Accessible by default — full keyboard navigation, screen-reader compatible, aria-live announcements Privacy by design — no external services, no tracking cookies, no IP tracking — everything stays on your server Features (free core) Form building * 14 field types: Text, Email, Textarea, Number, Date, URL, Phone, Select, Radio, Checkbox, Toggle, Hidden, Consent, Address * Composite Address field: street, postal code and city in a compact grid, with optional address line 2 and country * Dedicated Consent field for privacy-policy agreement * Notice block: a highlighted note between fields (info, success, warning, important) — pair it with conditional logic to surface guidance only when it applies * Section Heading and Page Break blocks for structuring longer forms * Multi-step forms with Page Break block, per-step validation and progress indicator (bar, dots or numbers) * Conditional logic — show/hide fields, skip steps, gate the submit button, with nestable groups for “(A or B) and C” * Two-column layout with per-field full-width override Styling * Automatic theme.json inheritance (colours, typography, spacing, border radius) * Style panel: primary colour, field style (bordered/soft/underline/minimal), label position (above/beside/floating/placeholder), submit button style (fill/outline/ghost), plus colour pickers for labels and help/consent text — and the Section Heading block carries WordPress’s native text-colour option Accessibility * Built accessible: real label/for pairs, fieldset/legend for choice groups, errors announced via role=”alert” and linked with aria-describedby, focus moves to the first invalid field * Multi-step navigation announces the new step via aria-live and manages focus; the progress indicator is a real progressbar with current values * Visible focus rings even when the theme removes them, prefers-reduced-motion respected, and the spam protection needs no CAPTCHA — nothing to squint at, nothing to solve * Works fully without JavaScript, and the form markup passes axe-core (WCAG 2.1 A/AA) with zero violations — including the error state Notifications * Admin notification email on every submission (configurable recipient, merge tags) * Optional confirmation email to the submitter * Sender name and address per form, with a Reply-To for each email — send from your own address without an SMTP plugin * Sends through your site’s standard WordPress mail (wp_mail) Spam protection * Always-on honeypot + signed time-based check (zero configuration) * Built-in proof-of-work challenge with accessible math fallback for visitors without JavaScript * No external service, no API keys, no tracking cookies, 100% GDPR-friendly After submission * Success message or redirect to a custom thank-you URL (with open-redirect protection) * Optional submission ID and form ID query parameters for conversion tracking (GA4, Meta Pixel, Plausible, etc.) Admin * Submissions list with search, filter by form, sort, bulk actions * Single-submission detail view with all field labels and values * Mark as read/unread * Per-form data retention with automatic daily purge Privacy Flinkform is built with privacy by default. Here is what the free core does and does not do: What the free core stores: * Form submissions (the field values visitors enter) in a dedicated database table ({prefix}flinkform_submissions) What the free core does NOT do: * It stores no IP addresses and no browser user-agent strings * It sets no tracking, analytics or marketing cookies. Flinkform sets exactly one strictly-necessary cookie — flinkform_flash (lifetime ~60 seconds, httpOnly) — and only when a form submission fails validation, to carry the error message and the visitor’s input across the page reload. Successful submissions set no cookie at all * It contacts no external service Data retention: * By default, submissions are retained until you delete them. To comply with the storage-limitation principle (GDPR Art. 5), set a per-form retention period (Form block → Data Retention) and Flinkform deletes older submissions automatically each day * Individual submissions can be deleted from the admin submissions screen at any time Data deletion: * All free-core data (the submissions table) is permanently removed when the plugin is uninstalled through the WordPress admin * Flinkform integrates with WordPress’s privacy tools (Tools > Export Personal Data / Erase Personal Data) to support data-subject access and erasure requests Source Code The complete, uncompiled source code (including the src/ directory with the unminified JavaScript/CSS that compiles into build/) is publicly available at: https://github.com/dennisbuchwald/Flinkform Build instructions (Node.js 18+ and npm required): 1. Clone the repository: git clone https://github.com/dennisbuchwald/Flinkform.git 2. Install dependencies: npm install 3. Build the compiled assets into build/: npm run build The build is powered by @wordpress/scripts (webpack). The src/ sources are excluded from the distributed plugin zip to keep it small; this repository is the canonical, reviewable source.
Top keywords
- flinkform12×1.08%
- forms11×0.99%
- block10×0.90%
- field10×0.90%
- form10×0.90%
- submissions10×0.90%
- wordpress10×0.90%
- core8×0.72%
- data8×0.72%
- theme7×0.63%
- build6×0.54%
- conditional6×0.54%