Title: Ultimate Form – Multi-Step Form Builder, Conversion Analytics &amp; Lead Forms
Author: Delta Web Solution
Published: <strong>May 26, 2026</strong>
Last modified: August 18, 2026

---

Search plugins

![](https://ps.w.org/ultimate-form/assets/banner-772x250.png?rev=3647319)

![](https://ps.w.org/ultimate-form/assets/icon-256x256.gif?rev=3594166)

# Ultimate Form – Multi-Step Form Builder, Conversion Analytics & Lead Forms

 By [Delta Web Solution](https://profiles.wordpress.org/desktopmoe/)

[Download](https://downloads.wordpress.org/plugin/ultimate-form.2.9.6.zip)

 * [Details](https://zh-sg.wordpress.org/plugins/ultimate-form/#description)
 * [Reviews](https://zh-sg.wordpress.org/plugins/ultimate-form/#reviews)
 *  [Installation](https://zh-sg.wordpress.org/plugins/ultimate-form/#installation)
 * [Development](https://zh-sg.wordpress.org/plugins/ultimate-form/#developers)

 [Support](https://wordpress.org/support/plugin/ultimate-form/)

## Description

**Ultimate Form** is a powerful, free form builder for WordPress — and the only 
one with a built-in, **privacy-first conversion dashboard** that shows you exactly
where visitors drop off, so you can fix the steps and fields that cost you leads.

Build multi-step funnels, add conditional logic, collect file uploads, send email
notifications and manage every submission — all from one plugin with **no limit 
on the number of forms, fields or entries**. No cookies, no account, no upsell wall
around the basics.

#### Why Ultimate Form?

 * **It’s genuinely unlimited** — unlimited forms, steps, fields and submissions
   in the free version.
 * **You can see what’s working** — most form plugins collect entries; Ultimate 
   Form also tells you your conversion rate, your funnel and your worst-performing
   fields, with zero personal data.
 * **It looks good out of the box** — a clean, modern form with floating labels,
   a clear focus ring and a consistent brand colour system across the whole plugin.
 * **It respects privacy by design** — hashed entry IPs (salted SHA-256), cookieless
   analytics with no IP at all, Do-Not-Track support and a consent-checkbox generator.

#### Key Features

 * **Drag & Drop Builder** with 25+ field types (text, email, phone, textarea, select,
   radio, checkbox, multi-select, date/time, number, currency, URL, password, rating,
   range slider, color, file upload, multiple files, name, address, ZIP lookup, 
   repeater, calculator, CAPTCHA, …)
 * **Multi-Step Forms** with a configurable progress bar and step navigation
 * **Form Analytics** — privacy-first conversion dashboard: views, start & conversion
   rate, step funnel, step-abandonment, field drop-off, validation hotspots, device&
   traffic source — no cookies, no IP addresses, aggregated data only
 * **Conditional Logic** — show/hide fields and steps based on previous answers
 * **File Uploads** — single and multiple file fields with type and size validation;
   uploads appear as download links in each entry
 * **Email Notifications** — per-form templates for customer, admin and custom recipients
 * **Design Configurator** — live preview for colours, typography, spacing and logo
 * **Entries Management** — view, search, filter, star, paginate and export submissions
   as CSV
 * **Save & Continue** — visitors can resume a long form where they left off
 * **Webhook Integration** — send form data to any external URL via HTTP POST
 * **Honeypot Spam Protection** — invisible spam protection on every form
 * **GDPR Compliant** — hashed entry IPs, cookieless analytics with no IP, consent-
   checkbox generator, optional Strict GDPR mode
 * **Translation Ready** — every user-facing string is translatable
 * **Shortcode Embed** — `[ultimate_form id="X"]` works with any theme or page builder
 * **Elementor Widget** — a dedicated widget to drop any form straight into your
   Elementor layouts
 * **Iframe Embed** — embed a form on external, non-WordPress websites with a ready-
   to-paste iframe snippet
 * **Conversion Tracking** — fire dataLayer / Meta Pixel events on successful submission
   for Google Tag Manager (Google Ads & custom events in Pro)

#### Need More?

**[Ultimate Form Pro](https://delta-web-solution.de/plugins/ultimate-form)** adds
powerful features for businesses:

 * Stripe & PayPal payment processing
 * WooCommerce integration
 * CRM integration (Brevo, HubSpot, ActiveCampaign, Pipedrive, Salesforce, Mailchimp)
 * Native PDF generation from submissions
 * Telegram, Discord & Slack notifications
 * Zapier / Make automation
 * Form cloning, A/B testing, submission limits
 * GDPR data export & erasure tools
 * Signature field
 * Priority support

[Get Ultimate Form Pro](https://delta-web-solution.de/plugins/ultimate-form)

### External Services

This plugin does not communicate with any external service by default. All form 
submissions are stored locally in your WordPress database. The following optional
features may connect to a third-party service, but only when explicitly enabled 
and configured by the site administrator:

#### 1. Webhook Addon (Generic HTTP POST)

**What it does:** Forwards form submission data to an arbitrary URL that the administrator
configures inside the plugin settings (Settings  Addons  Webhook).

**When data is sent:** Only when (a) the Webhook addon is enabled, (b) a valid URL
is provided by the administrator, and (c) a form submission is received that is 
mapped to the webhook.

**What data is sent:** The serialized form submission (form ID, submitted field 
values, submission ID, timestamp). The complete payload is the data the administrator
configured the form to collect.

**Where it is sent:** The endpoint URL is entirely controlled by the administrator.
The plugin does not ship with a pre-configured destination. There is no Ultimate
Form vendor server involved at any point.

**Service provider:** N/A — the destination is user-configured. The administrator
is responsible for ensuring that the receiving endpoint complies with their privacy
policy and applicable law.

#### 2. Plugin Support Form (delta-web-solution.de)

**What it does:** The plugin Help page contains a contact form that, when submitted
by an administrator, sends an email to `ultimate@delta-web-solution.de` (the plugin
vendor) using the WordPress `wp_mail()` function.

**When data is sent:** Only when the administrator clicks “Send” on the Help page
support form.

**What data is sent:** The message text and reply-to email address typed by the 
administrator. Nothing is sent automatically.

**Where it is sent:** Routed via the local WordPress `wp_mail()` mailer to `ultimate@
delta-web-solution.de`. No third-party API is involved.

**Service provider:** Delta Web Solution (the plugin author).

 * Website: [https://delta-web-solution.de](https://delta-web-solution.de)
 * Terms of Use: [https://delta-web-solution.de/agb](https://delta-web-solution.de/agb)
 * Privacy Policy: [https://delta-web-solution.de/datenschutz](https://delta-web-solution.de/datenschutz)

#### Note on the free version

The free Ultimate Form plugin does not contain any license server, telemetry, analytics
or “phone home” code. All feature-detection happens locally inside the plugin code.
There is no upgrade or activation check that contacts a remote server.

## Screenshots

[⌊Form Analytics — privacy-first conversion dashboard with the step-by-step funnel⌉⌊
Form Analytics — privacy-first conversion dashboard with the step-by-step funnel⌉[

Form Analytics — privacy-first conversion dashboard with the step-by-step funnel

[⌊Drag-and-drop form builder — field palette, live canvas and the field inspector⌉⌊
Drag-and-drop form builder — field palette, live canvas and the field inspector⌉[

Drag-and-drop form builder — field palette, live canvas and the field inspector

[⌊Design configurator — colours, typography and spacing with a live preview⌉⌊Design
configurator — colours, typography and spacing with a live preview⌉[

Design configurator — colours, typography and spacing with a live preview

[⌊Multi-step form on the frontend — floating labels and a clean progress indicator⌉⌊
Multi-step form on the frontend — floating labels and a clean progress indicator⌉[

Multi-step form on the frontend — floating labels and a clean progress indicator

[⌊Entries management — search, filter and one-click CSV export⌉⌊Entries management—
search, filter and one-click CSV export⌉[

Entries management — search, filter and one-click CSV export

[[

## Blocks

This plugin provides 1 block.

 *   Form

## Installation

 1. Upload the plugin files to the `/wp-content/plugins/ultimate-form` directory, or
    install via **Plugins > Add New**.
 2. Activate the plugin through the **Plugins** menu in WordPress.
 3. Go to **Ultimate Form** in the admin sidebar to create your first form.
 4. Use the shortcode `[ultimate_form id="1"]` to embed forms on any page or post.

## FAQ

### How many forms can I create?

There is no limit. You can create and publish as many forms as you need. The free
plugin has no form quotas, time limits or feature gates.

### Can I build multi-step forms?

Yes. Add as many steps as you like and turn on the progress bar. Visitors can move
back and forth, and conditional logic can even skip whole steps based on earlier
answers.

### Can visitors upload files?

Yes. The free version includes single and multiple file-upload fields with file-
type and size validation. Uploaded files are stored in your Media library folder
and shown as download links on each entry.

### Does conditional logic work on the free version?

Yes. You can show or hide individual fields and entire steps based on what the visitor
selected earlier — no Pro upgrade required.

### What does the Form Analytics dashboard show?

Views, start rate, conversion rate, average time to complete, a step-by-step funnel,
step-abandonment, the fields where people drop off, and device and traffic-source
breakdowns — all aggregated, with no cookies and no IP storage.

### Can I export my submissions?

Yes. Entries can be searched, filtered and exported to CSV (UTF-8, spreadsheet-safe)
at any time.

### Is the plugin translation ready?

Yes. Every user-facing string is wrapped for translation, so you can localise the
plugin into any language.

### Does the plugin send data to external servers?

By default, no. All form submissions are stored in your WordPress database. The 
plugin does not contact any external server unless you explicitly enable and configure
the Webhook addon. See the “External Services” section for full details.

### Is it GDPR compliant?

Yes. IP addresses in form entries are hashed with a salted SHA-256 (not stored raw,
irreversible), and the analytics never store an IP at all. A consent checkbox generator
is included, and an optional Strict GDPR mode enforces hashing, drops the user agent
and pauses analytics. No data leaves your server unless you explicitly enable an
external integration.

### Which page builders are supported?

The shortcode `[ultimate_form id="X"]` works with Gutenberg, Elementor, Divi, Bricks,
Beaver Builder, Oxygen and the classic editor. A dedicated Elementor widget is included
as well, and you can embed forms on external (non-WordPress) sites via the built-
in iframe embed.

### What are the minimum requirements?

WordPress 6.4+ and PHP 8.0+. Recommended: the current WordPress release and PHP 
8.1+.

### Is there a Pro version?

Yes. Ultimate Form Pro adds payment processing, WooCommerce integration, CRM connections,
PDF generation and more. The Pro version is hosted separately on the author’s website
and is NOT included in or required by the free plugin distributed via WordPress.
org. Visit [delta-web-solution.de](https://delta-web-solution.de/plugins/ultimate-form)
for details.

## Reviews

![](https://secure.gravatar.com/avatar/2c390d42a93a35536ed296f2e1012f4f7df5fed93a408eca5ba2db17797c0424?
s=60&d=retro&r=g)

### 󠀁[Super useful plugin and very kind support](https://wordpress.org/support/topic/super-useful-plugin-and-very-kind-support/)󠁿

 [barthdesigns](https://profiles.wordpress.org/barthdesigns/) August 16, 2026

I’m very happy to have found this plugin! It is super useful, and so easy to use.
I’ve had a small question about the conditional logic method and the Authors got
back to me within some hours – not just with the reply, but even a solved feature
request. I can only recommend the plugin and also the whole Team! Thanks and keep
up the good work!

![](https://secure.gravatar.com/avatar/d0999e20de0e86d3cfd551145b5345f00e5f81b7548b86680bececea984bbc4f?
s=60&d=retro&r=g)

### 󠀁[A Game-Changing Form Experience](https://wordpress.org/support/topic/its-great-to-use/)󠁿

 [Erdinc Bulat](https://profiles.wordpress.org/erdincbulat/) June 12, 2026

In web design, efficiency and stability are absolutely critical. Ultimate Form completely
checks all the boxes, delivering a flawless user experience. Throughout my entire
time using it, I did not encounter any difficulties, bugs, or technical errors. 
The performance is incredibly smooth, instilling immense confidence in the projects
it powers. One of the standout advantages of this plugin is that everything can 
be set up quickly and easily. The configuration process is incredibly straightforward,
making it remarkably accessible. Thanks to its clean and intuitive interface, even
beginners can navigate the settings and build functional forms with ease. The developer’s
commitment to an optimized user experience truly shines through in every single 
detail. Although I don’t usually use forms on my websites, Ultimate Form has completely
changed my perspective with its practicality and polished design. Its seamless integration
and robust design have made it an indispensable asset for future projects. This 
will definitely be the form plugin I use from now on, and I highly recommend it 
to anyone looking for a reliable solution.

![](https://secure.gravatar.com/avatar/b5825812753584efbc188967073d367f80ef343c9550fd305b7c53853c43ba44?
s=60&d=retro&r=g)

### 󠀁[One of the Best Free WordPress Form Builders I’ve Used](https://wordpress.org/support/topic/one-of-the-best-free-wordpress-form-builders-ive-used/)󠁿

 [Rikus Rossouw](https://profiles.wordpress.org/rikusrossouw/) June 5, 2026

Ultimate Form is a very well-designed and powerful form builder for WordPress. It’s
easy to set up and offers a smooth experience for creating both simple and multi-
step forms. The built-in conversion dashboard is a standout feature, giving clear
insight into where users drop off so you can improve your forms and increase submissions.
I also like that it supports conditional logic, file uploads, and email notifications
without unnecessary limitations or upsells. A solid all-in-one solution for anyone
serious about lead generation and form optimization.

![](https://secure.gravatar.com/avatar/226eeea7fa93c85e3572034dd4271fe7e44fd9ccebb2b2d8236f0869d79476d8?
s=60&d=retro&r=g)

### 󠀁[Multi-step forms done right — no bloat](https://wordpress.org/support/topic/multi-step-forms-done-right-no-bloat/)󠁿

 [misterdatabase](https://profiles.wordpress.org/misterdatabase/) May 28, 2026

I’ve tried a handful of form plugins and most of them either drown you in settings
or lock the useful stuff behind a paywall. Ultimate Form keeps it refreshingly focused:
build multi-step forms that actually convert, without wrestling with a hundred options.
Splitting a long form into smaller steps made a real difference for me — completion
rates went up noticeably compared to the single-page form I had before. The setup
is straightforward, and the iframe embed option is handy for dropping a form onto
pages outside the usual flow. Also nice to see security taken seriously out of the
box (nonce validation, rate limiting) — not something every form plugin bothers 
with. Lightweight, loads only where it’s needed, and does exactly what it promises.
Solid work for a newer plugin, looking forward to where it goes.

 [ Read all 4 reviews ](https://wordpress.org/support/plugin/ultimate-form/reviews/)

## Contributors & Developers

“Ultimate Form – Multi-Step Form Builder, Conversion Analytics & Lead Forms” is 
open source software. The following people have contributed to this plugin.

Contributors

 *   [ Delta Web Solution ](https://profiles.wordpress.org/desktopmoe/)

[Translate “Ultimate Form – Multi-Step Form Builder, Conversion Analytics & Lead Forms” into your language.](https://translate.wordpress.org/projects/wp-plugins/ultimate-form)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/ultimate-form/), check
out the [SVN repository](https://plugins.svn.wordpress.org/ultimate-form/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/ultimate-form/) 
by [RSS](https://plugins.trac.wordpress.org/log/ultimate-form/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 2.9.6

 * New: Conversion tracking (Settings  Tracking, its own tab) — on a successful 
   submit, Ultimate Form can push an event to window.dataLayer (Google Tag Manager)
   and call fbq(‘track’,’Lead’) (Meta Pixel) when those scripts are already installed
   on the page. The plugin never sends anything itself. Free: dataLayer push + Meta
   Pixel Lead toggle, plus a single on/off override per form. Pro adds a Google 
   Ads / gtag conversion id (global and per-form), a custom dataLayer event name,
   and optional non-sensitive field values in the event. Disabled entirely while
   Strict GDPR mode is on.
 * Fixed: Conversion tracking is now event-driven and also fires for Stripe/PayPal
   payment forms — those bypass the standard submit flow and previously never triggered
   a dataLayer/Pixel event at all.
 * New: `ultimateform_tracking_config` developer filter to adjust the resolved conversion-
   tracking config per form (documented in the Developer help tab); never runs while
   Strict GDPR mode is on.
 * Improved: A page cache (WP Rocket, W3TC, LiteSpeed, WP Super Cache, SiteGround,
   WP Fastest Cache, Cache Enabler, Breeze, Hummingbird, Autoptimize, WP-Optimize)
   is now purged automatically whenever a form, its design, or settings that affect
   the rendered form (General, Tracking, Captcha) are saved. Server-only settings(
   Email deliverability) no longer trigger a purge.
 * Fixed: Conversion tracking for forms embedded via `<iframe>` now works — iframe
   embeds forward the event to the parent page (postMessage) instead of firing into
   the iframe’s own, tracker-less window; A/B statistics now count variant-B submissions
   correctly (they were previously never recorded); every submission now delivers
   exactly one dataLayer/Pixel event (single delivery on document instead of a duplicate).
 * Fixed: database error “Multiple primary key defined” logged on every plugin (
   re)activation; duplicate abandon event on page leave.
 * Pro edition: declares its own Update URI so WordPress never offers the WordPress.
   org package as an update over a Pro install.
 * Fixed: Field placeholders now work in email subject, header, body and footer —{
   field:slug} inserts the submitted value (legacy {field_slug} and {slug} still
   accepted). Previously only four system tags were replaced and the placeholder
   text ended up verbatim in customer emails; the help page and the editor hint 
   now document the same working syntax. Field values are escaped in HTML and line
   breaks are stripped in subjects.
 * Fixed: The email profile editor’s data-table toggle is now labelled “Include 
   the submitted data table (all fields)” with a visible warning when it is off —
   the old wording implied a subset while OFF meant the email carried no field values
   at all.
 * Improved: Entries list and CSV export show field labels instead of internal names;
   the CSV keeps the technical names as a second header row so existing spreadsheet
   templates keep working.
 * Improved: Conditional-logic rules offer a dropdown of the field’s real options
   as the comparison value (text fields keep free input); works in Field Logic and
   Form Logic alike, existing rules load unchanged.
 * Improved: New fields get readable default names derived from their label (e.g.“
   vollstaendiger_name”) instead of timestamp slugs.
 * Improved: “New profile” / “Rename” in the design editor and the SMTP test recipient
   no longer use blocking browser prompts.
 * Improved: A/B test results are visible in the form editor (Pro) — the statistics
   endpoint existed but had no screen.
 * Fixed (Free): Iframe embed, Elementor widget and Save & Continue are Free features
   and are documented as such again — the help tab and instructions for iframe embedding
   were hidden in the Free build.
 * Fixed: {all_fields_table} label fallback matches the data table (readable label
   instead of raw field key); the email preview and the actual send render byte-
   identically for the same input.
 * Internal: Removed six unreachable legacy AJAX handlers; new release gates (AJAX
   reachability, documentation contract, email preview parity) guard against “documented
   but not wired” regressions.
 * Fixed: The GDPR data export & erasure tools are now actually reachable — a “GDPR&
   Privacy tools” card in Settings (Pro) lets administrators export a person’s entries
   as JSON or erase them permanently by email address. The backend for this existed
   and was fully secured, but no menu or button ever exposed it; the help page pointed
   to a screen that did not exist. Help texts and German translations updated accordingly.

#### 2.9.5

 * Fixed: The builder toolbar on narrow screens — step tabs were unclickable at 
   tablet widths (covered by the toolbar’s left group) and overflowed the viewport
   on phones; below 900px the builder now also explains that it needs a wider window
   instead of silently hiding the palette and inspector.
 * Fixed: Renaming a field now also rewrites calculation formulas that reference
   it — previously {old_name} tokens kept pointing at the former name and the calculation
   silently returned 0.
 * Fixed: The analytics funnel no longer shows phantom steps after steps were deleted
   or restructured; step counts now follow the form’s current definition.
 * Fixed: The email profile preview pane is scrollable now — long templates were
   cut off with no way to reach the rest.
 * Fixed: The keyboard focus ring on design sliders is no longer clipped at its 
   left edge.
 * Improved: Step tabs in the builder show the full step title as a tooltip when
   the label is truncated.
 * i18n: German (de_DE) translations added for all strings introduced in 2.9.4/2.9.5(
   analytics skip detection, step-skip tip, transparent design options, narrow-window
   notice).
 * Compatibility: Tested against WordPress 7.1 (jQuery UI 1.14 drag & drop in the
   builder, iframed post editor, client-side media processing). The form block now
   declares block API v3.
 * Fixed: PDF logos stored as WebP (WordPress 7.1’s client-side media processing
   can convert an uploaded JPEG/PNG logo to WebP) no longer disappear silently from
   generated PDFs — WebP is converted for the PDF like PNG, when the server’s image
   library supports it.
 * Fixed: Choice fields (radio, select, checkbox group) whose stored options are
   plain strings — e.g. created via import or the API — rendered as empty entries
   with no label and an empty value. The server-side validator always accepted that
   format; the renderer now does too.
 * Improved: The analytics funnel now understands steps skipped by conditional logic.
   Skipped visits appear as their own neutral “skipped” count (hatched bar segment)
   instead of being counted as visits with 0% drop-off, and drop-off rates are computed
   against the visits that actually saw each step. Ships dormant behind the analytics_visited_steps
   feature flag; existing dashboards are unchanged until it is enabled.
 * Fixed: The `[ultimate_form id="X"]` embed documented in this readme now works—
   the shortcode previously only accepted `slug="..."` and showed “No form slug 
   specified.” when following the docs. Both attributes are supported now.
 * Improved: The Trigger and Target dropdowns in Form Logic and the rule dropdowns
   in Field Logic now show the step number in front of each question (e.g. “2 / 
   How many rooms?”), so identical questions on different steps are easy to tell
   apart. Single-step forms stay unchanged. (Thanks to Julia for the suggestion.)

#### 2.9.4

 * New: Conditional logic can now branch whole steps. When every field on a step
   is hidden by your show/hide rules, that step is skipped automatically — forwards
   and backwards — so a multi-step form can send visitors down different paths instead
   of showing them an empty screen. (Thanks to Julia for the report.)
 * New: Transparent form and input backgrounds — let a form blend into your page’s
   own background so it looks embedded rather than boxed. Turn on “Transparent” 
   for the Form Card Background and/or the Input Background in Design  Colors, and
   pair it with “Plain form” for a fully borderless look.
 * New: One-click “Minimal / Transparent” quick preset in Design  Quick Presets —
   applies the transparent, borderless look in a single click.

#### 2.9.3

 * New: Choice fields (card style) can show a subtitle under each option title.
 * New: “Card — auto-advance” style advances to the next step on selection (opt-
   in).
 * New: Choice cards can carry an icon — pick from a built-in icon set, or use an
   emoji, image URL or inline SVG — with an optional left-aligned icon layout.
 * New: Optional always-visible “Back” button at the top of each step for multi-
   step forms (shortcode back_top=”1″) — visitors can always go back, handy for 
   auto-advance funnels.
 * New: The Back button is now independently stylable in Design  Buttons (background,
   label colour, border), and the Submit / Next / Back button text can be set there
   too.
 * Fixed: Conversational mode again shows one field at a time (a CSS rule made every
   field-step — each with its own Back button — display at once).
 * New: Self-hosted web fonts (Newsreader, Hanken Grotesk) — loaded locally and 
   only when a design actually uses them. No request to Google’s servers, so no 
   visitor IP is shared (GDPR-friendly by default).
 * New: Bundled “PrivatSafe” premium funnel design (warm/serif look) you can drop
   into Design  Custom CSS; scoped so it never affects your other forms.
 * Improved: Accessibility — ARIA labels on file, CAPTCHA, address and ZIP-lookup
   fields, keyboard focus moves to the active step when navigating, and aria-invalid
   is set on rating and signature fields for screen readers.
 * Improved: Right-to-left (RTL) layouts now honour every design token (checkbox
   sizing, focus ring, required colour), so RTL forms match the left-to-right layout
   exactly.
 * Internal: opt-in diagnostics tracker and groundwork for multiple design profiles—
   both disabled by default, no change to existing forms.
 * Security: Stripe test mode is now enforced end-to-end — no real charge can be
   created while test mode is on.
 * Security: WooCommerce add-on surcharges are locked in at submission, so the amount
   charged always equals the amount shown (no drift if option prices change mid-
   checkout).
 * Security: Payments now verify the captured currency against the server-computed
   currency (not only the amount), on both Stripe and PayPal.
 * Security: Priced option fields are frozen during payment, so a last-moment change
   can’t make the charge differ from the displayed total.
 * Security: Imported form data is sanitized on import (step titles/descriptions)
   and malformed conditions are skipped — defence-in-depth for hand-edited or imported
   forms.
 * Fixed: Multi-step screen-reader progress (“Step X of Y”) stays in the site language
   after navigating between steps.
 * Fixed: Open/close schedules and entry limits now fire at the intended local time
   even when the server timezone differs from the site timezone.
 * Fixed: A confirmation redirect set to a site-relative path (e.g. /thank-you) 
   is no longer cleared when the form is re-saved.

#### 2.9.2

 * Security: Payment amount verification now fails closed when the expected-amount
   token is missing or expired (Stripe & PayPal) — a tampered or unverifiable charge
   amount is rejected instead of being accepted.
 * Security: Hardened value deserialization during form duplication (no object instantiation
   from stored data).
 * Security: Frontend hardening — server and translation strings are HTML-escaped
   before insertion (defence-in-depth against DOM-based XSS).
 * Fixed: Save & Continue reliably stores entered values again (a scope error had
   silently disabled browser-side draft saving entirely).
 * Fixed: A failed submission no longer triggers notification emails or webhooks
   for a non-existent entry.
 * Fixed: The notification preview now matches the email that is actually sent (
   per-profile content mode).
 * i18n: Additional admin strings are now translatable; the German (de_DE) translation
   was completed.

#### 2.9.1

 * Fixed: “The form has expired” on cached sites — the anti-spam time token is now
   set client-side, so page caches (WP Rocket, Cloudflare) no longer freeze it.
 * Fixed: “Security token invalid” on heavily cached sites — the submit nonce is
   refreshed from an uncached endpoint and auto-retried, so forms keep working even
   when the page has been cached for over a day.
 * Fixed: Math CAPTCHA on cached sites — the CAPTCHA token is now cache-safe and
   no longer fails for every visitor once the page cache outlives the old token.
 * Fixed: Saving the form title from the builder toolbar — the toolbar Save now 
   persists the title, description and status (previously the toolbar/Ctrl+S save
   only stored field changes; in some setups it even navigated to a blank page).
 * Fixed: Success-window check icon not showing — the checkmark is now visible even
   when its draw animation does not run (power-saver, some mobile browsers).
 * Fixed: Math CAPTCHA hardening — the answer token is now bound to the form and
   validated from the form schema, so the check can no longer be skipped by omitting
   the token field.
 * Fixed: Clearing the form title in the builder no longer overwrites the saved 
   title with an empty value.
 * Fixed: Design “Reset” no longer fired a duplicate confirmation dialog.
 * Fixed: Field widths on mobile — text areas, checkboxes and full-width fields 
   now span the full width like text inputs.
 * New: Modern success window after submitting — animated checkmark with separate
   heading + description fields (Settings  After submission).
 * New: Per-device design tokens — tune font sizes, spacing and button sizes separately
   for tablet and phone in the Design editor.
 * Improved: “Save & Continue” now uses sessionStorage with a 12h limit and an opt-
   out setting (privacy/GDPR).
 * Improved: Email preview shows true device widths (Desktop/Tablet/Mobile).
 * Improved: Server-side required-field validation hardened (respects conditional
   logic).
 * New: Per-form SMTP routing — assign different mail servers to different forms
   via Settings  SMTP  “Per-profile SMTP accounts” and the new “Send via” picker
   in each email profile.
 * New: Failover SMTP — if a primary account fails, a configured backup account 
   delivers automatically. Recovery events are logged in Settings  Email Settings
   Deliverability.
 * New: Drag any form field directly onto a different step-tab in the form builder
   toolbar to move it across steps.
 * New: Colour picker now has a transparency slider that fades the picked colour
   toward white.
 * Improved: SMTP account host is now required on save (server-side validation prevents
   broken rows).
 * Improved: Mail-error log entries distinguish between hard failures and successful
   failover recoveries.
 * Improved: Existing global SMTP settings are automatically migrated into a “Default
   SMTP” account on update.
 * Fixed: Stale wp_mail_failed reasons no longer leak between consecutive sends.

#### 2.8.3

 * Fixed: Elementor widget — removed the broken “field layout / 2 columns” option
   that forced fields to full width. Forms now render consistently in a single column;
   use per-field widths (½, ⅓ …) for multi-column rows.
 * Improved: form is reliably capped to your configured max width and centered, 
   even inside full-width Elementor sections; verified zero horizontal overflow 
   from phone to desktop.

#### 2.8.2

 * New: **6 refined design presets** in the Design Configurator (Ocean Navy, Sky
   Blue, Cyan Tech, Royal Purple, Sunset Orange, Slate Pro) — Ocean Navy is the 
   default theme.
 * New: **Guided 3-step onboarding** on the dashboard to help you set up your first
   form, email and spam protection.
 * New: **Adjustable textarea height** — set the number of rows (1–10) per textarea
   field in the builder.
 * Performance: **form assets now load only on pages that actually contain a form**,
   and CSS/JS are shipped minified — faster page loads across your whole site.
 * Improved: **single-step forms** no longer show a redundant “Step 1” heading.
 * Improved: **import is now available directly from the empty Forms screen** (templates&
   bundles).
 * Improved: consistent default colour scheme across the form, design and email 
   screens.
 * Fixed: textarea fields no longer rejected on submit when longer than their row
   count.

#### 2.8.1

 * New: **Email Profiles** — reusable email setups (customer + admin notifications)
   with a live preview, configurable colours and an optional header gradient picker.
 * New: **Modernised field inspector** — settings are now grouped into clean cards(
   Field basics · Behaviour & display · Custom CSS) with rounded, consistent inputs.
 * New: **Design configurator** improvements and a shared custom colour picker across
   the design and email screens.
 * Improved: **Accessibility** — visible keyboard focus rings across the builder,
   design and frontend form.
 * Fixed: **Form submission reliability** — the submission endpoint is now registered
   independently of optional integrations, so every form submits correctly.
 * Fixed: the **{field:email}** placeholder in the email “To” field is now preserved
   on save.
 * Fixed: field-palette category icons and several admin UI polish issues.

#### 2.7.4

 * New: **File uploads now work end-to-end** — single and multiple file fields upload
   to your Media library folder (with file-type and size validation) and appear 
   as download links on each entry.
 * New: **Repeater** and **ZIP lookup** fields are now available directly in the
   builder’s field palette.
 * Fixed: **conditional logic** now supports every operator (equals, not equals,
   contains, greater/less than, starts/ends with, is empty / is not empty) for both
   field-level and step-level rules, and re-evaluates correctly across steps.
 * Fixed: **required validation** for multi-checkbox groups, plus minimum/maximum
   character-length checks on text fields.
 * Fixed: **Entries** screen now supports search, status filtering and pagination,
   and the CSV export is hardened against spreadsheet formula injection.
 * Fixed: the **Design configurator** no longer loses a custom font family on save,
   and the “Reset” button restores the true defaults again.
 * Fixed: **Save & Continue** is now stored per form and clears automatically after
   a successful submission.
 * Improved: textarea line breaks are preserved in stored entries; the form focuses
   the first invalid field; double submissions are blocked; and several remaining
   hardcoded strings are now translatable.

#### 2.7.3

 * Fixed: saving the General settings tab no longer wipes the Email-template settings(
   and vice-versa) — each tab now saves only its own fields. This also stops the
   admin notification address and the honeypot/analytics toggles from being reset.
 * Fixed: the “Confirmation message” and “Redirect URL” fields are visible again
   on the Settings screen (a broken script kept both rows hidden).
 * Fixed: “Redirect to URL” after submission now actually redirects (the saved option
   was read under the wrong name).
 * Fixed: spam protection no longer blocks legitimate submissions on forms that 
   contain an unrelated field whose name ends in “_token”.
 * Fixed: leaving a field’s min/max length empty in the builder now means “no limit”
   again instead of forcing it to 0.
 * Fixed: importing a form/template with incomplete conditional-logic rules no longer
   creates broken rules or warnings.
 * Fixed: entry detail no longer double-encodes form titles that contain “&” or 
   special characters.
 * Improved: a saved global e-mail heading is now used for customer confirmations;
   hardened a few output paths against PHP 8.1 notices.

#### 2.7.2

 * Fixed: floating labels now display correctly on the public form — the field label
   sits inside the field as a placeholder and lifts up on focus/fill (a bulletproof
   CSS rule was forcing the label to stay bold and static on forms that use the 
   Design configurator).
 * Fixed: removed a broken script on the form editor screen that threw a JavaScript
   console error (a stray template artifact).
 * Fixed: creating a form from a template now generates a clean slug (e.g. “contact”)
   instead of carrying the internal template prefix (e.g. “tpl_contact”).
 * Fixed: the form-editor preview button now reads “Submit” instead of a leftover
   checkout label.

#### 2.7.1

 * New: **Step-abandonment analysis** in Form Analytics — a visual funnel showing
   exactly which step visitors reach before leaving an unfinished form, with the
   drop-off rate and the field they last touched at each step.
 * Improved: clearer “where visitors stop” reporting to pinpoint the steps and fields
   that cost you conversions.

#### 2.7.0

 * New: **Form Analytics** — a privacy-first conversion dashboard. See views, start
   rate, conversion rate, average time-to-complete, a step-by-step funnel, where
   visitors drop off, which fields throw the most errors, plus device and traffic-
   source breakdowns. No cookies, no IP, no personal data — anonymous and aggregated,
   with an automatic data-retention cleanup and a Do-Not-Track option.
 * New: privacy controls under Settings  “Analytics & privacy” (enable/disable tracking,
   honour Do-Not-Track, set retention days).
 * Design: the public-facing form is fully redesigned — modern floating labels that
   sit inside each field and lift up on focus, softer inputs, a clearer focus ring,
   and primary buttons with subtle depth and a smooth hover lift.
 * Added: a trust line under every form (“Spam-protected · GDPR-compliant”).
 * Improved: the entire plugin (admin + frontend) now shares one consistent brand
   colour system.
 * Fixed: the focus ring and the red “invalid field” border are reliably visible
   again (a defensive style reset was hiding them).
 * Maintenance: uninstall now also removes view counters, analytics tables, the 
   retention cron and orphaned per-field options.
 * Note: floating labels apply to text, email, phone, URL, number, password, textarea,
   select and date/time fields; choice, file, rating and composite fields keep their
   static labels for clarity and accessibility.

#### 2.5.9

 * Design: unified the entire admin colour scheme to a single brand blue (previously
   5 different blue tones were mixed across screens)
 * Design: redesigned the “Create New Form” screen — colourful template icons, a
   feature highlight bar, a clear “start from scratch” entry, hover states and full-
   width gallery
 * Improved: template meta now uses correct singular/plural (“1 step” vs “3 steps”)
   and is fully translatable
 * Improved: replaced inconsistent emoji template icons with crisp inline SVG icons

#### 2.5.8

 * Fix: creating a form from a template now opens the editor correctly instead of
   a blank screen (import routine now returns the new form ID)
 * Fix: the email template editor now saves all fields — greeting, footer, recipient,
   CC, BCC, custom HTML and field selection were previously discarded on save
 * Fix: conditional logic rules are now stored correctly (the save handler read 
   the wrong field keys, so rules were saved empty and never applied on the frontend)
 * Fix: the password field strength meter now renders and works (a duplicate switch
   case had disabled it)
 * Improved: admin notification emails now set Reply-To to the submitter’s address,
   so replying goes straight to the lead
 * Improved: deleting a form now also removes its entries, entry fields and view
   stats (no more orphaned rows)
 * Security: email From header is stripped of CR/LF to prevent header injection 
   via stored settings

#### 2.5.7

 * Maintenance: removed non-WordPress.org contributor handle from the Contributors
   header (silences the import warning shown only to plugin authors)

#### 2.5.6

 * Compliance: radio-card label now escapes the raw option value via `esc_html()`
   at the output site (no longer relies on a pre-escaped variable Plugin Check cannot
   trace)
 * Compliance: the TTL-preserving rate-limit counter increment on `wp_options` now
   carries an explicit Plugin Check annotation explaining why the transient API 
   cannot be used here

#### 2.5.5

 * Compliance: added `/* translators: */` annotations to every `__()`/`esc_html__()`
   call that uses placeholders (Plugin Check requirement)
 * Compliance: replaced `rand()` with `wp_rand()` in the math-captcha renderer
 * Compliance: every `wp_redirect()` in admin page callbacks replaced with `wp_safe_redirect()`
 * Compliance: explicit output escaping for `$total_unread` and radio-card `alt`
   attributes
 * Compliance: `error_log()` debug calls gated behind `WP_DEBUG` + `WP_DEBUG_LOG`(
   no production logging)
 * Documentation: class-level PHPCS justifications added to `UltimateForm_Admin`
   and `UltimateForm_Form_Manager` explaining the plugin’s custom-table architecture,
   the nonce-verification helper indirection, and the intentional cache bypass

#### 2.5.4

 * Fix: registered the public REST route `ultimateform/v1/checkout` that the frontend
   form engine posts submissions to (this route was previously only shipped with
   the Pro edition, which left the free version unable to submit forms)
 * Improved: client IP resolution falls back through CF-Connecting-IP, X-Forwarded-
   For and REMOTE_ADDR, with strict IPv4/IPv6 validation
 * Improved: confirmation message is now passed through `wp_kses_post()` before 
   output

#### 2.5.3

 * Hardened output escaping in the upgrade comparison table (per-cell if/else instead
   of conditional echo expressions)
 * Field renderer attribute output split into separate echo statements with explicit
   per-line phpcs annotations

#### 2.5.2

 * Security: added nonce verification to the entry-detail admin screen before marking
   an entry as read (prevents CSRF state changes via crafted GET URLs)
 * Compliance: removed the Plugin URI header (no broken external link in the directory
   listing)
 * Compliance: contributor list now includes the WordPress.org account that owns
   the plugin

#### 2.5.1

 * Security: recursive sanitization for all JSON-decoded administrator inputs (logic,
   conditions, visible_fields, import payloads)
 * Security: all REST endpoints use a custom permission callback with rate limiting(
   no `__return_true`)
 * Compliance: removed `load_plugin_textdomain()` call (WordPress 4.6+ auto-loads
   translations)
 * Compliance: every PHP file with executable code starts with an `ABSPATH` direct-
   access guard
 * Compliance: file/path resolution uses `plugin_dir_path()`, `plugin_dir_url()`
   and `wp_upload_dir()` only (no hardcoded `site_url()`  `ABSPATH` string replacements)
 * Documentation: External Services section expanded with per-service data flow,
   destination and provider information
 * Documentation: clarification that the free plugin contains no license server 
   calls or telemetry of any kind

#### 2.5

 * Security: replaced permissive permission callbacks with nonce validation and 
   IP rate limiting on all REST endpoints
 * Improved: inline scripts and styles replaced with properly enqueued assets via`
   wp_enqueue_script()` / `wp_add_inline_script()`
 * Improved: all administrator-facing output properly escaped via `esc_html()`, `
   esc_attr()` and `esc_url()`
 * Plugin version constant updated throughout

#### 2.4

 * Split save button: Save as Draft vs Publish in form editor
 * Toast notifications redesigned (fixed full-width banner bug)
 * Delete form action fixed (double event handler removed)

## Meta

 *  Version **2.9.6**
 *  Last updated **4 days ago**
 *  Active installations **10+**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1**
 *  PHP version ** 8.0 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/ultimate-form/)
 * Tags
 * [conditional logic](https://zh-sg.wordpress.org/plugins/tags/conditional-logic/)
   [contact form](https://zh-sg.wordpress.org/plugins/tags/contact-form/)[drag-and-drop](https://zh-sg.wordpress.org/plugins/tags/drag-and-drop/)
   [form builder](https://zh-sg.wordpress.org/plugins/tags/form-builder/)[Multi-Step Form](https://zh-sg.wordpress.org/plugins/tags/multi-step-form/)
 *  [Advanced View](https://zh-sg.wordpress.org/plugins/ultimate-form/advanced/)

## Ratings

 5 out of 5 stars.

 *  [  4 5-star reviews     ](https://wordpress.org/support/plugin/ultimate-form/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/ultimate-form/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/ultimate-form/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/ultimate-form/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/ultimate-form/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/ultimate-form/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/ultimate-form/reviews/)

## Contributors

 *   [ Delta Web Solution ](https://profiles.wordpress.org/desktopmoe/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/ultimate-form/)