=== InboxMend – Submission Inbox & Email Log ===
Contributors: phpner
Tags: contact forms, form submissions, email log, form entries, smtp
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.4.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Keep WordPress form enquiries in a local inbox and review notification problems. Works with your existing supported forms and mail setup.

== Description ==

InboxMend keeps enquiries from supported WordPress forms in a local inbox, so you can review a saved request when its notification email is missing. It also shows related email sending events.

Many WordPress contact forms rely only on notification emails. If a notification email fails, is blocked, is misconfigured, or is never generated, the website owner may lose the enquiry without knowing it.

InboxMend helps you investigate that risk by keeping captured submissions in WordPress alongside related email activity. You can manage saved leads, coordinate follow-up, build forms, investigate email problems, configure SMTP sending, send conditional visitor auto-replies, and optionally connect InboxMend Cloud for multi-site monitoring.

Use InboxMend with built-in lead forms, or keep using supported form plugins such as Contact Form 7, WPForms, Fluent Forms, Forminator and Ninja Forms.

Gravity Forms compatibility is planned.

Learn more at [InboxMend.com](https://inboxmend.com/).

= Check your first saved submission =

Open **Inbox → Check form capture**. InboxMend lists forms from active supported plugins and your built-in forms. Open the published form page, send a recognizable test using a mailbox you control, then refresh and open the saved request. Check all expected fields and the complete message.

A saved request proves capture at the time shown. A successful mail handoff does not prove mailbox delivery; check your mailbox separately. InboxMend SMTP and Cloud are optional. You can keep your existing mail plugin.

Page discovery covers direct shortcodes and blocks in up to 200 matching published posts. Page builders, widgets and templates may require opening the form page yourself. The checklist shows up to 100 forms per provider. Default lead retention is 90 days for completed leads without a future follow-up. Unfinished work stays saved beyond that period until completed. Review Settings → Lead storage to preview cleanup or explicitly apply age-based deletion to all leads.

= For teams maintaining several sites =

Use the plugin to inspect and handle enquiries on each WordPress site. Optional InboxMend Cloud brings connected sites and their reported issues together for cross-site monitoring. Local capture does not require a Cloud account.


= Find the enquiry when its notification is missing =

A visitor can submit a contact form, but the notification email might not arrive.

This can happen because of SMTP issues, incorrect sender settings, hosting mail restrictions, plugin conflicts, spam filtering, or a form that did not generate an email event.

Built-in forms save the request before queuing a notification. Third-party capture follows each supported plugin's submission hooks; timing and email correlation depend on that plugin. Verify your published form after setup and after changes to its notification settings.

= One workflow instead of separate plugins =

Many WordPress sites use one plugin for forms, another plugin for saving entries, another plugin for SMTP, and another plugin for email logs.

InboxMend brings the form submission workflow together: review captured enquiries, inspect related email activity, manage basic follow-up, and keep everything visible inside WordPress.

= What you can do with InboxMend =

With InboxMend you can:

* Save WordPress form submissions in a local inbox.
* Capture entries from supported form plugins.
* Review leads, submitted fields, source forms, and lead details.
* Organize follow-up with work queues, workflow status, priority, assignee, due dates, internal notes, and bulk actions.
* Optionally email assignees a daily summary of due follow-ups, without including submitted contact details.
* Search, filter, and export saved submissions to CSV.
* Use Email Health to group active sending problems by cause and recommended action.
* Inspect exact WordPress email events, timelines, and related records in the Email Log.
* Configure SMTP sending for WordPress notification emails.
* Build and publish forms with Design Studio, conditional logic, previews, and shortcodes.
* Monitor form performance, readiness, placements, folders, and tags from the Forms workspace.
* Send visitor auto-replies with conditions, reusable designs, previews, and immediate or delayed delivery.
* Protect built-in forms with Google reCAPTCHA v3.
* Configure retention, privacy, and team access settings.
* Optionally connect InboxMend Cloud for multi-site visibility and monitoring.

= Works with popular form plugins =

You do not have to replace your existing form plugin.

InboxMend can capture submissions from supported form plugins and show them in one lead inbox.

Currently supported integrations include:

* Contact Form 7
* WPForms
* Fluent Forms
* Forminator
* Ninja Forms

Planned integration:

* Gravity Forms

When a supported integration is enabled and the related form plugin is active, InboxMend can store captured submissions and help you review related email activity.

= Built-in lead forms =

InboxMend includes built-in forms for common lead capture use cases.

Design Studio lets you arrange fields and blocks, edit content and appearance, add conditional show or hide rules, preview the result, save a draft, publish changes, and copy the shortcode. Submissions are saved in the Inbox, and related notification email activity can be reviewed from the Email Health and Email Log screens.

The Forms workspace also shows performance, inbox, delivery, and readiness signals. Forms can be searched, filtered, organized with folders and tags, and checked for known placements on the site.

Built-in forms are useful when you need a contact form, enquiry form, callback request, service request, or lead capture form without installing a separate form builder.

= Lead workflow and follow-up =

The Inbox groups saved submissions into practical queues such as Unseen, Awaiting action, Unassigned, My leads, Due today, Overdue, Delivery issues, and Archived.

Each lead can carry a workflow status, priority, assignee, follow-up time, and internal notes. Bulk actions help teams update several leads without opening them one by one.

Optional daily follow-up reminders are off by default. Enable them under **Settings → Team access**. After 09:00 in the site timezone, the next WordPress background run queues one summary per eligible assignee for that day. It includes only a count and an authenticated Inbox link. Access, current assignments and due dates are checked again before sending; completed and archived leads are excluded. Low-traffic sites may run later. Mail transport acceptance does not prove mailbox delivery.

When a capture write fails and WordPress can still store options, InboxMend keeps a persistent, non-personal diagnostic alert. A new successful capture from the same form can verify recovery; it does not recover the earlier failed submission. A total database outage can also prevent the diagnostic record from being stored.

= Email Health and Email Log =

InboxMend helps explain what happened after a form submission and what to do next.

The Email Health dashboard groups related email activity into clearer statuses, such as:

* Accepted by WordPress (delivery not verified)
* Failed
* No email generated
* Unknown

Email Health groups repeated problem attempts into active issues, explains the likely cause, and points to the relevant settings or event evidence. This makes it easier to find leads where the submission was saved, but the related notification email may not have worked as expected.

The Email Log helps site owners and admins review WordPress email events and sending attempts, including form notifications, visitor confirmations, WordPress system emails, and other events generated through WordPress. Event details show the recorded outcome, explanation, message data, timeline, and links to related leads, forms, rules, or saved designs when available.

= SMTP sending settings =

InboxMend includes SMTP settings for WordPress notification emails.

You can configure SMTP host, port, encryption, authentication, username, password, From email, and From name.

Using SMTP can help avoid common hosting mail issues where WordPress tries to send email through the default PHP mail function.

InboxMend logs WordPress email events and sending attempts, but it does not guarantee inbox delivery.

= Visitor auto-replies =

InboxMend includes visitor auto-reply designs and rules.

You can connect a rule to a form and visitor email field, add conditions based on submitted values, customize the subject and message, preview the result with sample values, and choose immediate or delayed delivery. Saved designs can be reused or copied into an independent message before editing.

This is useful when you want visitors to receive a confirmation email after submitting a form, while still keeping the original lead saved in your WordPress dashboard.

= Google reCAPTCHA v3 for built-in forms =

Built-in forms can be protected with Google reCAPTCHA v3.

This helps reduce automated spam submissions while keeping the form experience simple for real visitors.

= Optional InboxMend Cloud sync =

InboxMend can optionally connect to InboxMend Cloud at [https://inboxmend.com/](https://inboxmend.com/) when you want visibility across one or many connected WordPress sites.

Cloud sync is designed for agencies, freelancers, WordPress admins, and teams that need a wider operational view across sites. Depending on the selected sync mode, Cloud can help monitor connection health, polling freshness, saved submission activity, Email Health signals, Email Log status, and issue trends.

Cloud sync is optional. The plugin can still save submissions, review leads, and show Email Health inside WordPress without connecting to InboxMend Cloud.

= Best for =

InboxMend is useful for:

* Small business websites that rely on contact forms.
* Agencies managing client WordPress sites.
* Site owners who do not want to lose enquiries.
* WordPress admins who need saved form submissions.
* Freelancers who want a simple lead inbox for client sites.
* Websites that need basic form storage without a full CRM.
* Sites where email notification problems need to be easier to review.

= Privacy and data control =

InboxMend stores form submissions inside your WordPress database.

You control your own data from your WordPress admin area. The plugin also includes CSV export, retention, and privacy settings to help manage saved submissions responsibly.

= External services =

= InboxMend Cloud =

InboxMend can connect to InboxMend Cloud when Cloud Sync is enabled in the plugin settings.

Service URL: [https://inboxmend.com/](https://inboxmend.com/)
Privacy Policy: [https://inboxmend.com/privacy](https://inboxmend.com/privacy)
Terms of Service: [https://inboxmend.com/terms](https://inboxmend.com/terms)

Cloud Sync is used to connect this WordPress site to an InboxMend Cloud site record, check connection health, and synchronize selected operational data according to the configured sync mode.

Depending on the selected sync mode and consent settings, the plugin may send site identity, site URL, plugin version, WordPress version, PHP version, connection status, Email Health summaries, Email Log status, and lead summaries. Lead summary mode uses masked name and email previews plus site-keyed hashes instead of direct contact details. Only when Full lead data is explicitly enabled may the plugin additionally send names, email addresses, phone numbers, message text, source URLs, workflow status, notes, and submitted fields. Sensitive fields are redacted before Cloud sync.

Cloud Sync requests are sent to InboxMend Cloud API endpoints under `https://inboxmend.com/api/v1/plugin`. Protected requests use a site token issued during the connection flow.

Cloud Sync is optional and can be disconnected from the plugin settings.

= Google reCAPTCHA v3 =

InboxMend can use Google reCAPTCHA v3 to score submissions made through built-in InboxMend forms. This integration is disabled by default and is used only after an administrator enables it and provides reCAPTCHA keys.

When enabled, the visitor's browser loads the reCAPTCHA script from Google and requests a token. InboxMend sends that token and the configured Secret Key to Google's verification endpoint. The visitor's IP address is included in the server-side verification request only when the administrator separately enables the "Send the visitor IP address to Google" setting.

Service URL: [https://www.google.com/recaptcha/](https://www.google.com/recaptcha/)
Privacy Policy: [https://policies.google.com/privacy](https://policies.google.com/privacy)
Terms of Service: [https://policies.google.com/terms](https://policies.google.com/terms)

= Administrator-configured SMTP service =

InboxMend can send WordPress email through an SMTP server chosen and configured by the site administrator. This feature is disabled by default. When enabled, SMTP credentials, message recipients, sender details, headers, and email content are transmitted to that configured server as required to deliver the email. The applicable privacy policy and terms are those of the SMTP provider selected by the administrator.

= What InboxMend does not do =

InboxMend does not guarantee that an email reached the recipient's inbox.

It also does not confirm whether a recipient opened or read an email.

The plugin logs WordPress email events and sending attempts, so you can see whether an email was generated, accepted by WordPress, failed, not generated, or ended without a reliable outcome. WordPress acceptance does not verify recipient delivery.

= Bundled libraries =

The form and email design editors bundle GrapesJS 0.22.16 under the MIT license. Its human-readable source and build instructions are available in the [GrapesJS source repository](https://github.com/GrapesJS/grapesjs/tree/v0.22.16). The license is included in `assets/vendor/grapesjs/LICENSE`.

The email editor uses selected Lucide icon paths under the ISC license, with the upstream Feather MIT attribution retained. Source: [Lucide icons](https://github.com/lucide-icons/lucide). The license notices are included in `assets/vendor/lucide-icons/LICENSE`.

== Installation ==

1. Upload the plugin folder to `/wp-content/plugins/`.
2. Activate InboxMend from the WordPress Plugins screen.
3. Open InboxMend in the WordPress admin menu.
4. Optional: configure Settings -> Sending if you want to use SMTP.
5. Create a form, copy its shortcode, and publish it on a page, or enable one of the supported form plugin integrations.

== Frequently Asked Questions ==

= Will submissions be saved if email notifications fail? =

Yes. InboxMend is built around saving form submissions in your WordPress dashboard, so leads can remain available even when a related notification email fails or is not generated.

= Does InboxMend work without Cloud? =

Yes. InboxMend works locally by default. You can save submissions, review leads, use Email Health, and view the Email Log inside WordPress without connecting to InboxMend Cloud.

= Does InboxMend guarantee email delivery? =

No. InboxMend logs WordPress email events and sending attempts, but it cannot guarantee inbox delivery, confirm that a recipient received an email, or confirm that a recipient opened or read an email.

= Which form plugins are supported? =

Supported integrations include Contact Form 7, WPForms, Fluent Forms, Forminator and Ninja Forms. InboxMend also includes built-in lead forms.

= Is Gravity Forms supported? =

Gravity Forms compatibility is planned, but it is not available in the current plugin build.

= Does InboxMend replace Contact Form 7 / WPForms / Fluent Forms? =

No. InboxMend can capture submissions from supported form plugins and show them in a lead inbox. You can keep using Contact Form 7, WPForms, Fluent Forms, Forminator or Ninja Forms when the related integration is enabled and the form plugin is active.

= Where are submissions stored? =

Submissions are stored in your WordPress database first. The local WordPress inbox remains available without Cloud. Cloud Sync is optional and sends selected operational data only when you enable it.

= What does "Accepted by WordPress" mean? =

"Accepted by WordPress" means WordPress accepted the related email for sending. It does not prove inbox placement, recipient delivery, or that the email was opened or read.

= Can I use my own SMTP settings? =

Yes. InboxMend includes SMTP sending settings for WordPress notification emails, including host, port, encryption, authentication, from name, and from email.

= Can I export submissions? =

Yes. Saved leads can be exported as CSV from InboxMend.

= What data is sent to InboxMend Cloud? =

Only when Cloud Sync is enabled. Lead summary mode sends form and timestamp context, masked name and email previews, and site-keyed hashes rather than direct contact details. Only with explicit Full lead data consent may InboxMend additionally send direct lead details. Sensitive fields are redacted before Cloud sync.

= Does it support auto-replies? =

Yes. You can create reusable visitor auto-reply templates and connect them to specific forms and visitor email fields with auto-reply rules.

= Does it store sensitive SMTP passwords safely? =

The SMTP password is stored in the WordPress database as a non-autoloaded plugin setting so WordPress can authenticate to the configured mail server. InboxMend never prints the saved password back into the settings page and does not include it in Email Log or Email Health output. Protect WordPress database access and backups as credentials, and use the settings control to remove the saved password when it is no longer needed.

= Can I create forms with this plugin? =

Yes. The plugin includes built-in lead forms that can be published with a shortcode.

== Screenshots ==

1. Inbox with fictional demo enquiries: see saved submissions, owners, workflow stages, follow-up dates, and separate notification outcomes.
2. Lead detail with the full saved message, internal notes, and Next action controls for stage, priority, assignee, and follow-up.
3. Check form capture: find published forms, open their public pages, and review the latest saved submission for each form.
4. Delivery: understand an active SMTP authentication failure, open the sending settings, inspect problem events, and verify the email route.
5. Forms: manage InboxMend forms and review saved submissions from Contact Form 7 and WPForms in the same workspace.
6. Auto-replies: choose the form and visitor email field, edit a simple confirmation, and preview it safely before saving.
7. Design Studio with a demo enquiry form, draggable fields, a live canvas, and editable design settings.

== Upgrade Notice ==

= 1.4.0 =
Improves capture verification and follow-up. Unfinished enquiries are now protected from age-based cleanup by default; review Settings → Lead storage if you want retention to include all enquiries. Follow-up reminder emails remain off until enabled.


= 1.3.0 =
InboxMend 1.3.0 adds advanced auto-replies, stronger lead workflows, actionable email diagnostics, and production-ready settings.

= 1.2.0 =
InboxMend 1.2.0 adds verified database migrations, durable notification and Cloud queues, safer retention, replay protection, and privacy hardening. Back up the database before updating production sites.

== Changelog ==

= 1.4.0 =
* Added Check form capture to help you find published forms and verify the first saved enquiry.
* Simplified Inbox queues, bulk actions and lead details so the next follow-up step is easier to find.
* Brought sending problems, email history and connection settings together under Delivery.
* Made forms and their latest saved enquiries easier to find; added editable starter content for visitor confirmations.
* Protected unfinished enquiries from automatic age-based cleanup by default, with a cleanup preview and an explicit option to include all enquiries.
* Added optional daily follow-up reminders for assignees, without including submitted contact details in the reminder email.
* Added persistent capture-failure notices with per-form recovery checks and no submitted personal data in diagnostics.
* Fixed incomplete field capture in all five supported form integrations and preserved full messages and ordinary business fields.
* Improved Settings on small screens and kept retention controls available when new capture is paused.
* Improved translated notices and the display of reminder activity counts.
* Updated the WordPress.org banner, screenshots and setup guidance around the enquiry workflow.

= 1.3.0 =
* Redesigned Inbox and Lead Detail with work queues, workflow statuses, bulk actions, notes, and safer notification retries.
* Added conditional auto-reply rules, editable saved designs, previews, tests, delayed delivery, and Forms status integration.
* Rebuilt Email Health and Email Log around actionable incidents, explainable outcomes, verification, event details, filters, retention, and background export.
* Expanded Forms and Design Studio with analytics, organization, conditional logic, placement discovery, and safer publishing and deletion.
* Added bounded retention and anonymous-request rate limiting for form analytics events.
* Redesigned Settings with configuration readiness, responsive navigation, protected credentials, confirmations, and granular team permissions.
* Fixed form-scoped Email Log filters so pagination and export retain the selected form.
* Fixed deactivation cleanup so delayed notification jobs do not remain scheduled.
* Simplified the plugin repository layout and expanded security and regression coverage.

= 1.2.0 =
* Added verified, retryable database migrations with a schema readiness gate and multisite lifecycle support.
* Made lead and field persistence transactional so partial submissions are rolled back instead of reported as successful.
* Replaced transient notification delivery with an idempotent database queue using leases, retries, and exponential backoff.
* Added public form rate limiting and client submission IDs to prevent accidental duplicate leads and replayed requests.
* Added exact request correlation for WordPress mail events so concurrent form submissions cannot attach each other's messages.
* Hardened Cloud Sync with lease/ACK delivery, opaque snapshot cursors, bulk loading, retry scheduling, and site-keyed hashes.
* Reduced Lead summary data to masked name/email previews; direct contact details remain limited to explicit Full lead data consent.
* Added bounded retention for leads, mail logs, Cloud events, notification jobs, and rate-limit records.
* Prevented concurrent settings writers from overwriting unrelated Cloud, SMTP, privacy, or retention values.
* Hardened CSV exports against spreadsheet formulas, stopped exposing saved reCAPTCHA secrets, and preserved honeypot values for server validation.
* Made built-in form field replacement, duplication, deletion, and ordering transactional to prevent partially applied admin changes.
* Fixed auto-reply retries so failed attempts can run again without duplicating messages that were already sent successfully.
* Added critical database indexes, conditional admin-only loading, and fewer summary count queries for large installations.

= 1.1.3 =
* Moved Auto-reply sending settings into the template editor so each template can manage its attached forms in one place.
* Improved the Auto-replies admin flow with clearer labels, menu highlighting, editor headers, and template usage details.
* Added plugin-owned admin notices for Auto-replies and settings messages so success and error feedback remains visible after redirects.
* Improved Auto-reply sending rule layout and validation behavior, including clearer visitor email field selection.

= 1.1.2 =
* Improved the Inbox and Lead detail screen layouts for a clearer review workflow.
* Fixed required field handling so form fields can become optional when required validation is disabled.
* Added editing and deleting support for Internal notes.

= 1.1.1 =
* Improved the form editor inspector so selected elements show their default element styles instead of empty controls.
* Automatically switches the right panel to Inspector when an element is selected.
* Improved Layout inspector sync after resize, including Width and individual margin controls.

= 1.1.0 =
* Rebranded the visible plugin identity to InboxMend while keeping the existing WordPress.org slug and text domain.
* Added InboxMend.com links, Plugin URI, Author URI, and Cloud Sync external service disclosure.
* Added optional InboxMend Cloud polling support for connected sites.
* Added Cloud sync payloads for lead snapshots, Email Log snapshots, Email Health summaries, and source breakdowns.
* Aligned the plugin Cloud connection check with the InboxMend Cloud API by using the existing heartbeat endpoint.
* Improved Cloud Sync settings with a clearer status overview, data sharing controls, diagnostics section, and persistent action notices.
* Improved Cloud connection security by requiring HTTPS for non-local Cloud endpoints and signed protected Cloud API requests.
* Hardened Cloud sync data handling by defaulting to Lead summary mode, redacting sensitive submitted fields, and masking technical error secrets before sync.
* Renamed Email Status surfaces to Email Health in the admin experience.
* Refined the lead detail screen layout by moving secondary source, notes, and activity information out of the long right sidebar.
* Updated WordPress.org assets, screenshots, banners, and readme content to match the InboxMend branding and product positioning.
* Kept Cloud Sync optional; local Inbox, Email Health, Email Log, forms, SMTP, auto-replies, export, retention, and privacy settings continue to work without Cloud.

= 1.0.0 =
* Improved the WordPress.org readme description and short description.
* Added WPForms lead capture compatibility.
* Added Fluent Forms lead capture compatibility.
* Added Forminator lead capture compatibility.
* Added Ninja Forms lead capture compatibility.
* Added auto-reply rules so templates can be assigned to specific supported forms and visitor email fields.
* Added Google reCAPTCHA v3 protection for built-in forms.
* Improved the Auto-replies admin experience, including rule validation, clearer field-level errors, and better form state preservation after validation errors.
* Improved admin screen styling by splitting page-specific CSS for Inbox, Forms, Email, Settings, and Auto-replies.
* Improved Email Log and Email Health handling for supported form integrations.
* Removed email open and click tracking endpoints because engagement tracking is not included in this release.
* Confirmed compatibility with WordPress 7.0.

= 0.1.0 =
* Initial release.
* Added built-in lead forms.
* Added Inbox for saved form submissions.
* Added SMTP sending settings.
* Added Email Log.
* Added Email Health dashboard.
* Added visitor auto-reply templates.
* Added Contact Form 7 compatibility.
* Added CSV export, retention, and privacy settings.
