Pipeline Forms Suite — Documentation

Guide to installing, setting up and using Pipeline Forms Suite 1.0.2 for WordPress.

Contents

1. Installation

Requirements: WordPress 6.2 or newer and PHP 7.4 or newer. The Suite is a standalone plugin; no other plugin is required.

  1. In WordPress, go to Plugins → Add New → Upload Plugin, choose pipeline-forms-suite-1.0.2.zip and click Install Now.
  2. Click Activate. A Pipeline Forms menu appears with All Forms, Add New, Entries, Settings, Advanced Settings and Popups.

Only one Pipeline Forms plugin can be active at a time. If another one is already active, the second shows a notice and does nothing until you deactivate one of them. The free Pipeline Forms plugin and the Suite use the same forms and entries, so switching keeps them.

2. Getting started

  1. Go to Pipeline Forms → Add New and choose a template: Blank Form, Simple Contact Form, Newsletter Signup or Quote Request.
  2. In the builder, add fields from the palette, edit them in the inspector, and drag (or use the up and down buttons) to reorder.
  3. The builder tabs are Fields, Settings, Notification, Confirmation, More Notifications, Integrations and Advanced Options.
  4. Click Save and place the form with the shortcode [pipeline_form id="123"] (shown in the forms list) or the Pipeline Form block.

Per-form settings include the button labels, extra CSS classes, Store entries in the database (on by default), the honeypot and the captcha switch. A form with a payment field always stores its entries.

3. Fields

The 12 basic field types are single line text, paragraph text, dropdown, multiple choice, checkboxes, numbers, hidden field, name, email, phone, website / URL and consent. The Suite adds an Advanced Fields group:

4. Multi-step forms and conditional logic

Add Page Break fields to split a form into steps. Under Advanced Options choose the progress indicator and the Next and Back button labels. Every field can have conditions (show or hide when all or any rules match). The rules compare with: is, is not, contains, greater than, less than, is empty, is not empty.

Conditional logic is checked again on the server: a field that is hidden by its rules is not required and its value is not saved.

5. File uploads

For each File Upload field you set the allowed extensions (default jpg,jpeg,png,gif,pdf,doc,docx,txt), the maximum size per file in MB (1 to 64, default 5) and whether several files are allowed (up to 10). On the server the file must be an uploaded file, within the size limit, have an allowed extension and not be on the plugin's list of blocked extensions (for example PHP, HTML, JavaScript, SVG and executables), and its content must match its extension according to WordPress.

Accepted files are stored under wp-content/uploads/pipeline-forms/ in your WordPress uploads folder, each in its own subfolder with a random name. The plugin writes an index.php and an .htaccess file there; the .htaccess file only has an effect on Apache-compatible servers, so on other web servers add equivalent rules yourself if you want to block direct access. Files are deleted when their entry is deleted.

6. Calculations and quizzes

Calculations

A Calculation field has a formula such as {price} * {quantity}. It supports numbers, field references, + - * / %, parentheses and the functions round, floor, ceil, abs, min and max. It is evaluated by the plugin's own parser; no code is executed. The value shown in the browser is only a preview: the result saved with the entry is calculated again on the server.

Quizzes

Under Advanced Options → Quiz / scoring turn on scoring, set the passing percentage and the pass and fail messages. Mark choices as correct (with points) in choice fields, or give a correct answer for text, number and rating fields. The merge tags {quiz_score}, {quiz_max}, {quiz_percent} and {quiz_result} work in notifications and confirmation messages, and the score can be appended to the confirmation message.

7. Notifications and confirmation

The Notification tab sends one email per submission (default recipient: the site admin email). Under More Notifications you can add further emails (for example a copy to the visitor), choose a Reply-To field, set conditions, and add routing rules that add recipients depending on an answer. Merge tags: {all_fields}, {form_name}, {entry_id}, {admin_email}, {site_name}, {site_url}, {date}, {ip}, {page_url} and {field:ID}. Emails are sent with WordPress's own mail function; use an SMTP plugin if your host's mail is unreliable. Each entry shows whether the send attempts succeeded.

The Confirmation tab shows a message after submitting or redirects to a URL you enter.

8. Payments (Stripe and PayPal)

Add a Payment field to a form and choose Stripe or PayPal, the currency and either a fixed amount or the value of another field. Enter your own credentials under Pipeline Forms → Advanced Settings (Stripe test and live secret keys and mode; PayPal client ID, secret and sandbox or live mode). The first Payment field in a form is used.

  1. When the visitor submits, the plugin saves the entry with the status Pending payment and sends the visitor to a Stripe Checkout page or a PayPal approval page. The plugin has no card fields; card details are entered on Stripe or PayPal only.
  2. When the visitor returns, the plugin asks Stripe whether the Checkout session was paid, or captures the PayPal order. Only then is the entry set to Complete and the notifications, webhooks and integrations sent.
  3. For Stripe you can also add the webhook address shown on the Advanced Settings page (the REST route pipeline-forms-suite/v1/stripe on your site) in your Stripe dashboard and paste its signing secret. The plugin checks the signature and acts only on the checkout.session.completed event.

If the visitor cancels or the payment is not confirmed, the entry stays Pending payment; filter by that status under Entries. The plugin does not issue refunds.

9. Webhooks and email marketing

Webhooks

Under Integrations add webhook URLs (for example Zapier, Make or a Google Sheets script). Each completed submission is sent to every enabled webhook as JSON (full or flat) or as a form post, with the form ID and name, entry ID, site address, submission time and the field values. If you enter a signing secret, each request carries an X-Pipeline-Signature header with an HMAC-SHA256 of the body. Webhook calls use WordPress's safe remote request function, which rejects URLs that point to local or private network addresses.

Email marketing

Add Mailchimp, ConvertKit, ActiveCampaign or Brevo connections per form, with your own API key (and the ActiveCampaign API URL) saved under Advanced Settings. You choose the list or form ID, the Email field, an optional Name field and an optional consent checkbox: if you pick a consent field, the subscriber is added only when it is ticked. Without a valid email address nothing is sent. The email address and the name are sent to the provider (first and last name to Mailchimp, ActiveCampaign and Brevo; first name only to ConvertKit); tags are sent to Mailchimp only, the other providers do not receive them.

The result of every webhook and connection is shown on the entry.

10. Entries

Under Pipeline Forms → Entries filter by form, date, status (Complete, Partial, Pending payment, or all), read status and starred, and search. Open an entry to see its answers, payment details, notification and webhook results, and to add internal notes. Bulk actions: delete, mark read or unread, star or unstar. The CSV export (shown when one form is selected) exports that form's complete entries matching the current search and dates, with the columns Entry ID, Date (UTC), Status, IP, Source URL and one per field; spreadsheet formula characters are neutralised with an apostrophe.

Partial entries

If you turn on Save partial entries for a form, the visitor's answers are sent to your site while they fill in the form (after a field changes, when a field loses focus, or when the tab is hidden), but only once a valid email address has been entered. They are saved as an entry with the status Partial (file, payment, calculation, hidden and consent fields are left out). When the visitor submits the form, the partial entry is replaced by the final one, and any save still on its way from that page is ignored. A partial entry from a visitor who never submits stays until you delete it. This option is off by default; if you use it, tell your visitors in your privacy policy.

11. Popups

Under Pipeline Forms → Popups create a popup that shows one of your forms as a modal or a slide-in. Choose the trigger (timed, scroll depth, exit intent, immediate or click), the pages (all, home, only listed or all except listed), devices, an optional referrer text, logged-in state, how often it may appear (days between views, maximum views, days to stay hidden after a conversion) and an optional A/B test of the headline and text. For the click trigger place a link with [pipeline_popup_link id="123" text="Sign up"] or link to #plfx-popup-123.

To apply frequency limits and the A/B variant the popup script saves a small record per popup (view count, last view time, conversion time and variant) in the visitor's browser localStorage. It is not sent to your site. Your site keeps only a daily count of impressions and conversions per popup and variant, with no visitor information.

12. Spam protection

13. Settings

Pipeline Forms → Settings: default stylesheet, store visitor IP address with entries (on by default), delete all data on uninstall (off by default), honeypot, minimum seconds, rate limit, captcha provider, site key and secret key. Advanced Settings: API keys for Mailchimp, ConvertKit, ActiveCampaign and Brevo; Stripe and PayPal credentials; blocked IPs and country filter. API keys, secrets and the captcha secret are stored in your WordPress options table as entered. After saving they are not shown again; leave a field blank to keep it, or tick Remove.

14. Privacy and personal data

Everything the plugin collects is stored in your WordPress database and uploads folder. It sends data to outside services only as listed under External Services, and only for features you set up.

DataStored on your siteSent toHow it is removed
EntriesThe answers to your form; the entry date; the visitor's IP address (if IP storage is on); the browser user agent (first 255 characters; stored with every submitted entry and cannot be turned off); the address of the page the form was on (only if it is on your own site); the WordPress user ID if the visitor was logged in, otherwise 0; status, read and star flags; internal notes; quiz score; payment and webhook results; the notification send record.The notification email goes to the addresses you set. Webhooks, email-marketing providers, Stripe, PayPal, Akismet and a captcha provider receive what is listed under External Services.You delete entries under Entries, or delete the form. Deleting an entry removes its meta records and its uploaded files. Entries are never deleted automatically; there is no retention period.
Partial entriesAnswers saved while a form is being filled in (only if the option is on for that form, and only after a valid email address was entered), with the IP address if IP storage is on. No user agent is stored for partial entries.NobodyReplaced by the final entry when the visitor submits; otherwise they stay until you delete them.
Uploaded filesIn wp-content/uploads/pipeline-forms/NobodyRemoved when their entry is deleted.
Payment detailsProvider, the Stripe session or PayPal order reference, amount, currency and status, in the entry. No card data.Stripe or PayPal (see External Services)With the entry. Records at Stripe or PayPal are not touched by the plugin.
Popup countersDaily impression and conversion counts per popup and variant in a database table. In the visitor's browser: a small localStorage record per popup.NobodyThe table is removed on uninstall if the delete option is ticked. Visitors can clear their browser storage.
Rate-limit and throttle countersTemporary counters under a hash of the IP address and site salt.NobodyExpire by themselves; also removed on uninstall.
No built-in privacy tools. The plugin does not add to the WordPress personal data export or erase tools and does not add text to your privacy policy. To answer a request about a person, search the entries for them (for example by email address), view or export the entries, and delete them. Copies already sent to webhook URLs, email-marketing providers, payment providers and notification mailboxes are outside the plugin and must be handled there. The CSV export has no user agent or notes column.

15. Uninstalling

Deactivating or deleting the plugin keeps your forms, entries and settings unless Delete all forms, entries and settings when the plugin is deleted was ticked under Pipeline Forms → Settings before deleting. With that option ticked, deleting the plugin removes all forms and popups, the entries, entry-meta and popup-statistics tables, the plugin's settings and the upload folder with every uploaded file. Whatever that option says, deleting the plugin also removes temporary counters and the per-user notice flag.

16. Troubleshooting

The visitor paid but the entry is still Pending payment

The entry is completed when the visitor returns to your site after paying, or when Stripe's checkout.session.completed event reaches your webhook address. Check that the webhook endpoint and signing secret in Stripe match the ones shown under Advanced Settings.

Payments are temporarily unavailable

This message means the keys for the chosen provider and mode are missing or do not match (for example a live key while the mode is test).

A webhook or integration shows a failure

Open the entry to see the HTTP code or error that was recorded, and check the URL, API key and list ID.

Emails do not arrive

Install an SMTP plugin and check the send record on the entry.

17. External Services & Data

The Suite makes no request to 007aj.com. It connects to an outside service only when you configure the matching feature and a visitor uses it (a submission, a payment, a captcha).

ServiceUsed forWhat is sentTerms and privacy
StripePayments, when a form has a Payment field set to StripeFrom your server to https://api.stripe.com: your secret key, the amount, the currency, the payment description (or the form title) and the entry number as a reference, to create a Checkout session; later your secret key and the session ID to check whether it was paid. The visitor is redirected to Stripe's page. The visitor's name and email address are not sent by the plugin.Terms · Privacy
PayPalPayments, when a form has a Payment field set to PayPalFrom your server to https://api-m.paypal.com (live) or https://api-m.sandbox.paypal.com (sandbox): your client ID and secret to get a token, then the amount, the currency, the description (up to 127 characters) and the entry number as a reference to create an order, and later a request to capture it. The visitor is redirected to PayPal's page. The visitor's name and email address are not sent by the plugin.Terms · Privacy
MailchimpEmail marketing, per form connectionYour API key, the subscriber's email address, first and last name (if a Name field is mapped) and tags you entered, to https://<datacenter>.api.mailchimp.com.Terms · Privacy
ConvertKitEmail marketing, per form connectionYour API key, the subscriber's email address and first name, to https://api.convertkit.com.Terms · Privacy
ActiveCampaignEmail marketing, per form connectionYour API key, the subscriber's email address, first and last name, and the list ID, to the API URL of your own ActiveCampaign account.Terms · Privacy
BrevoEmail marketing, per form connectionYour API key, the subscriber's email address, first and last name, and the list ID, to https://api.brevo.com.Terms · Privacy
Webhook URLs you enterSending submissions to your own or a third-party service (Zapier, Make, a script)The form ID and name, entry ID, your site address, the submission time (UTC) and the submitted field values, to the URL you entered, signed with your secret if you set one. IP address and user agent are not included.Set by the service you point to
AkismetOptional spam check, per form; only if the Akismet plugin is installed and connectedThrough the Akismet plugin, exactly: your site address, the visitor's IP address, the visitor's browser user agent, the content type “contact-form”, the name (first Name field) and email address (first Email field) from the form, and the text entered in single-line text and paragraph fields. Other field types are not sent.Terms · Privacy
Google reCAPTCHA v2Optional captchaThe visitor's browser loads https://www.google.com/recaptcha/api.js. When the form is submitted, your server sends your secret key, the visitor's response token and IP address to https://www.google.com/recaptcha/api/siteverify.Terms · Privacy
hCaptchaOptional captchaThe visitor's browser loads https://js.hcaptcha.com/1/api.js. When the form is submitted, your server sends your secret key, the visitor's response token and IP address to https://api.hcaptcha.com/siteverify.Terms · Privacy

The Suite does not track visitors, sets no cookies and loads no scripts or fonts from a CDN except the captcha script when a captcha is switched on.

18. Support

Email admin@007aj.com. Please include the Suite version (shown under Plugins) and what you expected to happen.

← Back to Pipeline Forms Suite