A real drag-and-drop canvas
Build a form visually with nine field types — text, textarea, email, number, date, select, radio, checkbox, file — no shortcode-guessing or page-builder workaround required.
A drag-and-drop form builder that stores every entry, defends itself against spam by default, and hands you GDPR consent, export and erasure tools — without the upsell most free form plugins build toward.
free forever · no pro tier · no ads · nothing phones home
Entries, exports and spam protection are usually where a free form plugin starts asking for money. Forms ships all of it, from the first drag to the GDPR erasure request.
Build a form visually with nine field types — text, textarea, email, number, date, select, radio, checkbox, file — no shortcode-guessing or page-builder workaround required.
Every submission is saved with its field values and available as CSV — the data outlives the notification email.
Uploaded files are validated and stored the way a security audit expects, not merely accepted on faith.
A hidden honeypot field and a minimum-fill-time check run on every form for free. Add Cloudflare Turnstile per-form if a site needs a second layer.
An optional per-form consent checkbox whose exact wording at submission time is stored with the entry — a later copy edit never rewrites what an already-submitted entry appears to show.
Wired into WordPress's own privacy tools, entry by entry, for any submission tied to a registered user.
Notification emails go out with a proper From address, not the wordpress@yourdomain fallback most sites never notice is broken until it lands in spam.
Most free form plugins hold back the parts that matter — entries, exports, real spam protection — for a paid tier. Forms ships all of it free, and every tagged release runs through the same WP HealthKit audit the rest of the Oiko line does.
A recent hardening pass added CSRF protection on CSV export, a multisite-aware uninstall, a guarded fallback for sites without the Sodium extension, and capped what had been an unbounded form-list query — exactly the kind of finding a security audit exists to catch before it ships, not after.
Built the Oiko way
No. A honeypot field and a minimum-fill-time check run on every form by default and catch most automated spam. Cloudflare Turnstile is available per-form as an extra layer, but it's optional.
Nothing, for entries already submitted. The exact text a visitor saw is stored with their entry at submission time — not a boolean re-evaluated against your current settings — so a later copy edit never changes what an already-submitted entry appears to show.
Yes — uninstall loops every site on the network rather than cleaning up only the one it happened to run on, the multisite-aware behaviour a security audit checks for.