
Flinkform is a form builder that lives entirely inside the WordPress Block Editor. Forms are composed from native blocks (block.json v3), styled through theme.json design tokens, and powered by the Interactivity API — no separate form builder UI, no shortcodes, no jQuery, under 15 KB of frontend JavaScript (gzipped).
Built in Germany for GDPR-first websites. Das deutschsprachige Kontaktformular-Plugin für den Block-Editor.
Try it before you install it: live demo forms, including multi-step and conditional logic, at https://demo.flinkform.de/
GDPR by design
No IP logging, no user-agent logging, no tracking, no external services in the free core. Spam protection runs on a honeypot, a signed timing check and a proof-of-work challenge with a no-JavaScript maths fallback — no reCAPTCHA, no hCaptcha, no Cloudflare Turnstile, and therefore no data transfer to US servers. Includes a consent field, retention periods with automatic deletion and integration with the WordPress privacy tools.
Free, not a trial
Multi-step forms and conditional logic are in the free core, not behind a paywall:
- Multi-step forms with progress indicator and per-step validation
- Conditional logic for fields, steps, skipping steps and gating the submit button
- 14 field types including a dedicated consent field
- Submissions dashboard inside WordPress with search, filters and read state
- Email notifications with merge tags, plus an optional confirmation mail
- Automatic theme.json styling — forms match your theme without extra CSS
- Built for accessibility: the rendered markup passes axe-core against WCAG 2.1 A/AA with zero violations
Flinkform Pro
The optional Pro add-on adds Stripe payments (card, SEPA direct debit, Apple Pay, Google Pay — whichever methods you enable in Stripe), calculation fields, multi-file upload, SMTP delivery, webhooks, newsletter integrations, CSV export and custom CSS. Details and pricing: https://flinkform.de/pro
Requirements
WordPress 6.5 or newer, PHP 8.1 or newer, Block Editor (Gutenberg).
How it works
- Block Editor native — forms are built with
block.jsonand the Interactivity API, directly inside the editor - theme.json styling — forms inherit your theme’s typography, colours and spacing automatically
- Modern stack — WordPress 6.5+, PHP 8.1+, no jQuery, frontend JS under 15 KB gzipped
- Multi-step forms — split long forms into steps with a Page Break block, included in the free core
- Conditional logic — show/hide fields based on user input, included in the free core
- Accessible by default — full keyboard navigation, screen-reader compatible, aria-live announcements
- Privacy by design — no external services, no tracking cookies, no IP tracking — everything stays on your server
Features (free core)
Form building
* 14 field types: Text, Email, Textarea, Number, Date, URL, Phone, Select, Radio, Checkbox, Toggle, Hidden, Consent, Address
* Composite Address field: street, postal code and city in a compact grid, with optional address line 2 and country
* Dedicated Consent field for privacy-policy agreement
* Notice block: a highlighted note between fields (info, success, warning, important) — pair it with conditional logic to surface guidance only when it applies
* Section Heading and Page Break blocks for structuring longer forms
* Multi-step forms with Page Break block, per-step validation and progress indicator (bar, dots or numbers)
* Conditional logic — show/hide fields, skip steps, gate the submit button, with nestable groups for “(A or B) and C”
* Two-column layout with per-field full-width override
Styling
* Automatic theme.json inheritance (colours, typography, spacing, border radius)
* Style panel: primary colour, field style (bordered/soft/underline/minimal), label position (above/beside/floating/placeholder), submit button style (fill/outline/ghost), plus colour pickers for labels and help/consent text — and the Section Heading block carries WordPress’s native text-colour option
Accessibility
* Built accessible: real label/for pairs, fieldset/legend for choice groups, errors announced via role=”alert” and linked with aria-describedby, focus moves to the first invalid field
* Multi-step navigation announces the new step via aria-live and manages focus; the progress indicator is a real progressbar with current values
* Visible focus rings even when the theme removes them, prefers-reduced-motion respected, and the spam protection needs no CAPTCHA — nothing to squint at, nothing to solve
* Works fully without JavaScript, and the form markup passes axe-core (WCAG 2.1 A/AA) with zero violations — including the error state
Notifications
* Admin notification email on every submission (configurable recipient, merge tags)
* Optional confirmation email to the submitter
* Sender name and address per form, with a Reply-To for each email — send from your own address without an SMTP plugin
* Sends through your site’s standard WordPress mail (wp_mail)
Spam protection
* Always-on honeypot + signed time-based check (zero configuration)
* Built-in proof-of-work challenge with accessible math fallback for visitors without JavaScript
* No external service, no API keys, no tracking cookies, 100% GDPR-friendly
After submission
* Success message or redirect to a custom thank-you URL (with open-redirect protection)
* Optional submission ID and form ID query parameters for conversion tracking (GA4, Meta Pixel, Plausible, etc.)
Admin
* Submissions list with search, filter by form, sort, bulk actions
* Single-submission detail view with all field labels and values
* Mark as read/unread
* Per-form data retention with automatic daily purge
Privacy
Flinkform is built with privacy by default. Here is what the free core does and does not do:
What the free core stores:
* Form submissions (the field values visitors enter) in a dedicated database table ({prefix}flinkform_submissions)
What the free core does NOT do:
* It stores no IP addresses and no browser user-agent strings
* It sets no tracking, analytics or marketing cookies. Flinkform sets exactly one strictly-necessary cookie — flinkform_flash (lifetime ~60 seconds, httpOnly) — and only when a form submission fails validation, to carry the error message and the visitor’s input across the page reload. Successful submissions set no cookie at all
* It contacts no external service
Data retention:
* By default, submissions are retained until you delete them. To comply with the storage-limitation principle (GDPR Art. 5), set a per-form retention period (Form block Data Retention) and Flinkform deletes older submissions automatically each day
* Individual submissions can be deleted from the admin submissions screen at any time
Data deletion:
* All free-core data (the submissions table) is permanently removed when the plugin is uninstalled through the WordPress admin
* Flinkform integrates with WordPress’s privacy tools (Tools > Export Personal Data / Erase Personal Data) to support data-subject access and erasure requests
Source Code
The complete, uncompiled source code (including the src/ directory with the
unminified JavaScript/CSS that compiles into build/) is publicly available at:
https://github.com/dennisbuchwald/Flinkform
Build instructions (Node.js 18+ and npm required):
1. Clone the repository: git clone https://github.com/dennisbuchwald/Flinkform.git
2. Install dependencies: npm install
3. Build the compiled assets into build/: npm run build
The build is powered by @wordpress/scripts (webpack). The src/ sources are
excluded from the distributed plugin zip to keep it small; this repository is
the canonical, reviewable source.