Changelog

What's new in Formitor.

Every meaningful improvement to the product and the WordPress plugin, newest first.


  1. Product

    A site you pause is never treated as a Formitor pause

    Formitor now records who paused each site: you, or Formitor itself after its one-form containment check. A site you pause with the Pause button on its card stays yours. Formitor support does not triage it, and Formitor never resumes it on its own. Only sites Formitor paused after its own check are reviewed by support and resumed automatically once a fix is in place.

    Read the full post
  2. Product

    Formitor now tells you when it pauses a site itself

    Before Formitor submits to every form on a site, it checks one form and confirms the test notification stayed inside Formitor. If that proof fails, it pauses the whole site. Until now that pause looked the same as one you set yourself, and nothing told you it had happened. A pause made by Formitor now shows up in the **bell** as a critical notification, "Checks paused on (site)", with the reason in plain words. Formitor support is paged at the same time and owns the fix. When a later check proves containment, the site resumes on its own and you get a second notification, "Checks resumed on (site)". You do not need to act in either case. Pauses you set yourself are unchanged.

    Read the full post
  3. Product

    Sites behind a firewall now prove containment through the plugin

    Before Formitor tests a site's forms it checks one form first and confirms that the test email reached only our monitoring inbox. Until now that first check always came from our servers. If your firewall blocked us, the check could never pass, and the site was paused on its first day even though the plugin was ready to run the tests itself. The plugin now runs that first check on its own when our servers cannot reach it, and reports the result back. Once it passes, monitoring continues through the plugin as designed. Also, a first check that fails to submit at all (a firewall, a spam filter, a blocked request) no longer pauses the site: the failure shows up on the form like any other, and the next pass tries again. Requires plugin 0.2.64, which sites install themselves within a few hours.

  4. Plugin · v0.2.63

    Plugin 0.2.63: Fluent Forms token-based spam protection no longer blocks the test

    Fluent Forms has a global setting called token-based spam protection. With it on, a form only accepts a submission that carries a fresh signed token, which a visitor's browser fetches right before it submits. Formitor's test had no token, so the form rejected it as suspicious and every check on that site failed. As of plugin 0.2.63 the test creates that token on your site the same way Fluent Forms creates it for its own conversational forms. Keep the protection on. Sites update themselves within a few hours, or use **Update sites** in the dashboard.

  5. Plugin · v0.2.63

    Plugin 0.2.63: Gravity forms placed by your theme now test cleanly

    Some Gravity forms are not inside a page at all. Your theme puts them there: a newsletter signup in the footer, or a form in a sidebar widget. Formitor could not find a page to submit those on, so it reported the form as unreachable and stopped checking the site. The plugin now also looks at your front page. When the form renders there, the test submits on the front page, which is where Gravity processes it for a visitor too. Update to plugin 0.2.63: sites update themselves within a few hours, or use **Update sites** in the dashboard.

    Read the full post
  6. Product

    Fixed: cached responses no longer trip anti-spam checks

    Some hosting setups cache the data our checker reads from your site. When a site turned on an anti-spam plugin, that cache could serve an older copy of the form details without the new anti-spam fields. Our test submissions then looked like spam to the site, and healthy forms reported failures. The checker now requests fresh data on every check, so it always sees your forms exactly as your visitors do. The fix is on our side. There is nothing to update on your site.

  7. Product

    Fixed: this week's summary email did not go out

    A bug in our reporting service stopped this Monday's weekly summary emails before they were sent. The bug is fixed. Your next summary arrives on schedule next Monday, covering the full week. Site monitoring itself was never affected.

  8. Plugin · v0.2.62

    Plugin 0.2.62: frozen auto-updates on cached sites now clear themselves

    On a site with an external object cache, a stalled update could leave a lock behind that quietly froze all of WordPress's own auto-updates, including the site's core, plugins and themes. Formitor now clears that stuck lock on its own during a routine check, so updates resume without anyone touching the server. Requires plugin 0.2.62.

  9. Plugin · v0.2.61

    Plugin 0.2.61: forms behind WP Armour anti-spam now test cleanly

    WP Armour (the Honeypot and WP Armour Extended plugins) rejects any form submission that does not carry its hidden fields, and can auto-block the sender's IP address. That made Formitor's monitoring submissions look like spam, so a working form could read as broken. Formitor's test now includes those hidden fields the same way a real browser does, across every supported form type, so you can keep WP Armour on and monitoring keeps passing. Requires plugin 0.2.61.

  10. Plugin · v0.2.60

    Formitor keeps itself allowlisted through MalCare

    On sites running MalCare, the security plugin's cloud sync could periodically clear Formitor's monitoring addresses from its allowlist and start blocking checks. The plugin now re-asserts that allowlist on its own, so monitoring keeps working without anyone re-whitelisting by hand. Requires plugin 0.2.60.

  11. Plugin · v0.2.60

    See which plugin sends your email, on the Mail Log tab

    The **Mail Log** tab now shows a badge naming the SMTP plugin a site uses to send mail (for example, SMTP by FluentSMTP), or a clear warning when no SMTP plugin is set up. It is a quick way to confirm a site is actually configured to deliver its form mail. Requires plugin 0.2.60.

    Read the full post
  12. Plugin · v0.2.60

    Plugin 0.2.60: Elementor forms that email the admin are no longer flagged as silent

    Elementor sends a form's notification to the site admin by default, with no recipient saved on the form itself. Formitor read that empty setting as "this form emails nobody" and could report a working form as silent. It now resolves the same default Elementor applies at submit time, so a form that notifies the admin reads correctly. Update each site to plugin 0.2.60 from the dashboard.

  13. Product

    Formitor's checks now identify themselves to firewalls

    Every request Formitor makes to your site now carries the User-Agent `Formitor/1.0 (+https://formitor.com)`. Before this change our checks used a generic programming-library identifier that many firewalls block on sight, and one blocked site looked unreachable for days even though it was fine. If a firewall or anti-spam tool stands in front of your site, you can now add one allow rule for that exact User-Agent string and every Formitor check passes cleanly. The allowlisting guides in the docs show where to add it for common tools.

  14. Product

    A slow site is no longer mislabeled as firewalled

    Reading a site's full form list can take longer than 20 seconds on a busy shared server. When that read timed out, Formitor recorded the site as blocked by a network problem or firewall, and the label stuck even though the site answered every quick check within half a second. Formitor now allows 45 seconds for the form list, and before recording a network problem it first runs a quick health check. If the site answers, no false label is written and any old one is cleared. Two affected sites were identified this way and now monitor normally. This change runs on Formitor's servers and needs no plugin update.

  15. Plugin · v0.2.59

    Plugin 0.2.59: the Elementor containment safeguard no longer refuses checks it could run

    Plugin 0.2.58 added a safeguard for Elementor Pro 4.1 sites: if a test submission cannot be kept away from a form's integrations, the check is refused instead of run. The safeguard itself had a fault. It could not read the list of form actions on a real Elementor Pro install, so it refused every check on those sites even though containment would have worked. Plugin 0.2.59 reads the action list correctly. The refusal stays in place for the cases where containment truly cannot be guaranteed. Nothing ever leaked either way: the refusal fails toward safety, and that part worked exactly as designed.

  16. Plugin · v0.2.58

    Fluent Forms notifications sending to {wp.admin_email} are now read correctly

    Fluent Forms fills its default notification recipient with the smart code {wp.admin_email}, which stands for your WordPress admin address. Formitor's recipient check did not resolve that code, so a healthy form could be flagged as sending mail to nobody. Plugin 0.2.58 resolves the smart code the same way Fluent Forms does, and those forms now read correctly.

  17. Product

    Pausing a form now pauses its inbox placement tests too

    Pausing a form has always stopped the regular checks right away. The daily inbox placement test, which sends a message through your form to a real mailbox to see which folder it lands in, kept its own schedule and did not read the pause. A paused form could still get a test submission about every two days. The placement pass now reads the same pause state as every other check, so paused means paused everywhere. This change runs on Formitor's servers and needs no plugin update.

    Read the full post
  18. Plugin · v0.2.58

    Plugin 0.2.58: test data stays out of your integrations on every Elementor Pro version

    Elementor Pro 4.1 removed the hook Formitor used to keep test submissions away from a form's integrations, such as saving to the database, CRM connections, and webhooks. On sites with that version, a check could hand test data to those integrations. Elementor Pro 4.2 brought the hook back, so most sites were never affected. Plugin 0.2.58 checks how your installed Elementor Pro behaves and contains test submissions on both kinds of version. If containment cannot be guaranteed on a site, Formitor now refuses that check instead of running it. Sites update to 0.2.58 automatically within about 12 hours.

  19. Plugin · v0.2.57

    Fluent Forms' honeypot and monitoring now work together

    If you turn on the honeypot in Fluent Forms' global settings, test submissions now include the hidden honeypot field the same way a visitor's browser does. Before plugin version 0.2.57 the honeypot rejected our test submissions, which reported working forms as broken. You can keep the spam protection on; monitoring keeps passing.

  20. Plugin · v0.2.57

    Test submissions use a fresh email address on every check

    Each check now fills the email field with a one-time address such as monitor+run123@formitor.test. Before plugin version 0.2.57 every check used the same address, and CRM integrations that reject duplicate contacts (Brevo and similar) stopped the form's action chain on the second run, so a healthy form looked broken. A fresh address per run means those integrations treat every check as a new contact and run the full chain.

  21. Plugin · v0.2.57

    Every update now re-proves mail containment before checks continue

    After the plugin updates to a new version, Formitor checks one form first and reads the site's own delivery log to confirm the test notification went to Formitor's monitor inbox and nowhere else. Checks on the remaining forms only continue after that proof. This gate already covered scheduled checks; with plugin version 0.2.57 it also covers Run checks now and background jobs.

  22. Plugin · v0.2.56

    Formitor now notices when WordPress updates are frozen on your site

    An update that dies partway can leave WordPress holding a stale update lock. While that lock sits there, core, plugin and theme auto-updates on the site are silently stuck, sometimes for hours, and nothing reports it. The plugin now checks for locks older than an hour on every health report, and Formitor raises a frozen site with our team so it gets unfrozen instead of quietly falling behind on updates.

  23. Plugin · v0.2.56

    Plugin 0.2.56: Gravity Forms checks now test the page your form actually lives on

    Checks against Gravity Forms used to guess when they could not tell which page a form was embedded on, and a wrong guess looked like a broken form. The plugin now finds the embedding page across shortcodes, blocks, classic widgets and Elementor widgets, so the check submits where a real visitor would. Forms that answer with a redirect after submitting (a thank-you page, for example) are treated as submitted and verified by the stored entry instead of being failed on the spot. If you saw failure alerts for Gravity forms that worked fine in the browser, this release is the fix. Sites update on their own; you can also update from Plugins in wp-admin.

    Read the full post
  24. Plugin · v0.2.51

    The plugin now tells you when a site has connected

    Connecting a site with a pairing code gave you no confirmation. The page came back looking exactly as it had before, with the same empty code box, and if you reloaded it you were told the connection had failed — because the code had already been used. Now you get a clear "Connected" message, and the Formitor screen in WordPress shows the connection with the time it last checked in, so you can see at a glance that the site is still being watched. The Connect button says "Connecting…" while it works, which can take up to twenty seconds. There is also a Disconnect button, and a way to move a site to a different Formitor account.

  25. Plugin · v0.2.52

    Plugin 0.2.52: some working forms were being reported as broken

    If a form had a field that Formitor read as optional but your form plugin actually required — a phone number, a postcode, a dropdown — our test submission left it out, the form quite rightly refused it, and we told you the form was broken. It was not. Real visitors were submitting those forms the whole time. We were reading the setting the way a person would rather than the way Elementor reads it, and the two disagree on forms built from a template or an import. Our test now fills in every field on the form, the way a real visitor does, so this cannot happen for a field we misjudged. Two smaller things came out of the same fix: date and time fields were being filled with text instead of a real date or time, and file-upload fields are now left alone. If you saw a form marked as failing that you could submit yourself, this was almost certainly why, and it is fixed.

  26. Product

    Every Formitor update email now has an unsubscribe link

    Product news and announcements from us now carry an unsubscribe link, and your mail app's own Unsubscribe button works as well. Unsubscribing stops product news only. Alerts about a broken form and your weekly report keep arriving, because those are the service itself rather than news about it. You can change those in your account.

  27. Product

    Adding a site with a pairing code now works

    Pairing codes had been failing every time since we introduced them, so anyone adding a site had to fall back to the older site key method. The fault was in the step that generates the code, and it is fixed. Sites you already connected with a site key are unaffected and stay connected. Thank you to the customer who reported it.

  28. Product

    Your form check history now goes back 90 days

    Formitor used to keep 30 days of form check results. It now keeps 90, on every plan, including the free one. That is a full quarter to look back over. It is enough to answer the questions that only show up later: has this form been quietly failing since the theme was updated, was the site fine before that plugin went on, is this the first time or the fourth. There is nothing to switch on. Results older than 30 days had already been cleared under the old limit, so the extra history builds up from today and the full 90 days will be there in about two months. Uptime history is unchanged at 90 days.

    Read the full post
  29. Plugin · v0.2.50

    Plugin 0.2.50: the sending-domain check is back on, and safe this time

    We paused this check yesterday because it read the wrong address. It is back, and the plugin is now careful about what it will believe. Your site only reports a sending address when something can vouch for it: the address belongs to your own domain, or your SMTP plugin's own settings name it. An address typed into your contact form by a visitor is never treated as yours. That was the bug, and it could have shown a healthy result for a site whose mail was actually failing. We also stopped counting anything recorded before this fix. Your site may show no sending domain for a little while after updating, and will grade on your website domain in the meantime. That is deliberate. A correct answer a bit later beats a confident wrong one now. Along the way we found and fixed six faults that could stop a site sending mail altogether when an SMTP plugin stored an unusual value. Those were the more serious problem, and they are gone. One more change on our side: when your site reports more than one sending domain, we now check every one of them and show you the worst. A busy shop domain can no longer hide a broken one behind it. Most sites update themselves within about a day. To do it now, open **Sites** and use **Update sites**.

  30. Product

    Deliverability is back on your website domain while we fix the sending-domain check

    Yesterday we announced that Formitor reads the domain your site really sends mail from. We have switched that off again. The plugin was reading the wrong address. On sites using Contact Form 7 it picked up the address the person filling in your form typed, not yours. Those are usually Gmail addresses, and Gmail passes every mail check, so a site with genuinely broken mail could have shown a healthy result. That is the one thing this check must never do. Until the fix is reviewed, every site is graded on its website domain again, the way deliverability worked before. There is nothing for you to do, and no plugin update to install. We also closed three faults in the same sweep. One site could stop the deliverability run for every other site. A site we could not reach had its stored result overwritten with a guess. The tooltip under **Deliverability** named the wrong source for some sites, and it names the right one now.

    Read the full post
  31. Plugin · v0.2.48

    Plugin 0.2.48: deliverability now checks the domain your mail actually comes from

    Most WordPress sites do not send mail from their own web address. They send it through a sending domain such as mg.yoursite.com, set up by an SMTP plugin or a mail provider. Formitor used to check the web address instead. Your SPF, DKIM and DMARC records live on the sending domain, where they belong, so the web address had none and the **Deliverability** strip turned red over a domain that never sends anything. The plugin now reports which domain it sends from. WordPress has known this on every send since the beginning and we simply never asked for it. From plugin 0.2.48 the daily check reads that answer and grades the right name straight away, instead of waiting for a test message to arrive in our seed mailbox first. There is nothing for you to do. Sites update themselves within about twelve hours and the next daily check picks it up. Hover the **Deliverability** label to see which domain was checked and where that answer came from. Your site reports the domain only. It never sends us an email address.

    Read the full post
  32. Product

    Password and magic-link sign-in are back, with links that survive email scanners

    Email sign-in is back on the login page. You can create an account with a password, sign in with it, reset it, or ask for a one-time magic link. Google sign-in stays. Every emailed link now opens app.formitor.com and waits for you to press **Sign me in**, so a mail client that pre-opens links can no longer use your link before you do.

  33. Product

    Create your beta account in one step

    The beta invite on formitor.com now creates your account the moment you ask. Enter your name and email under any **Start monitoring** button and a sign-in link reaches your inbox within a minute. The first 100 testers get a seat right away. After that you join the waitlist and we email you when a seat opens. Each inbox gets one seat.

  34. Product

    Formitor is in beta and taking on testers

    We are opening another round of beta testing. There is a short form on formitor.com if you want to join. You get a free account while we build. Testers whose feedback changes the product keep extra room on the free plan once the beta ends.

  35. Product

    AI access tokens now have scopes, and the token list works

    Two changes to **AI access**. Tokens now carry scopes. A new token can read your account and run checks on demand, and it can add sites only if you tick **Let this agent add new sites** when you create it. Tokens you already have keep exactly what they had. The token list on that screen was also showing nothing, even for accounts that had a live token, which left no way to revoke one from the app. It lists them now, and each one has a Revoke button.

  36. Plugin · v0.2.47

    Plugin 0.2.47: connect a site from an AI assistant, without sharing its secret

    If you connect an AI assistant to Formitor with an AI access token, it can now add sites for you. The assistant asks Formitor for a pairing code. You enter that code in WordPress under **Tools → Formitor → Connect this site** and save. The plugin then sends its own credentials straight to Formitor, so the assistant never sees the site's secret. That matters, because the secret is what authenticates every check Formitor runs against the site. Codes last fifteen minutes and work once. Adding sites is off unless you turn it on: tick **Let this agent add new sites** when you generate the token. The usual way of adding a site by hand still works exactly as before.

  37. Product

    Change a site's address without losing its history

    Moving a site to a new domain used to mean deleting it and adding it again, which threw away every check it had ever run. You can now use **Change site address** on the site itself. The forms, the history and the uptime monitors move across with it. The site's secret is still required, because that is how the new address proves it is the same site.

    Read the full post
  38. Plugin · v0.2.46

    Plugin 0.2.46: forms embedded from other services now appear

    Some sites embed a form from another service instead of building one in WordPress. The plugin skipped those, so they were missing from your dashboard with nothing to explain why. They now appear, along with the page they sit on. Formitor cannot submit a test lead through a form it does not control, so these are listed rather than checked. Seeing that a form exists and is not covered is more useful than not seeing it at all.

  39. Plugin · v0.2.45

    Plugin 0.2.45: fixes from an outside security review

    Two independent reviewers went through the plugin's update and test machinery. Two problems came out of it, and both are fixed. On a site running several checks close together, test context could carry over between forms, so a result could be recorded against the wrong form. Separately, the updater could accept a package whose signature had not been fully verified. Sites update themselves within about twelve hours. To update sooner, go to **Plugins** in your WordPress admin.

    Read the full post
  40. Plugin · v0.2.43

    Plugin 0.2.43: sites behind a firewall now update themselves

    Formitor updates itself on most sites without anyone doing anything. On some sites it could not. WordPress checks for plugin updates by calling back to your own site, and Formitor can push an update in from the hub. A firewall or a security plugin that blocks incoming requests stops both, so a site could sit on an old version for months with nothing pointing at the cause. Version 0.2.43 adds a route that only travels outward. Your site already reports in to Formitor every few minutes, and that report now comes back carrying the current plugin version. A site that has been behind for more than a day installs the update on its own. Nothing needs to reach in. When a site still cannot update, it now says why. The reason appears on the site row in your dashboard: PHP too old, installs disabled by the host, files not writable, or auto updates switched off. The plugin also refuses to install a release that your PHP version cannot run, rather than installing it and taking the site down. Sites running 0.2.42 or earlier need to get to 0.2.43 first. Use the update on the site's **Plugins** screen, or **Update sites** in the hub.

  41. Plugin · v0.2.36

    Plugin 0.2.36: stricter redirect handling during tests

    When Formitor submits a test entry or checks a checkout page, the plugin follows redirects the way a browser would. Version 0.2.36 checks every hop against the same rules as the original address, instead of trusting the first one, so a redirect cannot send a test somewhere it was never meant to go. Nothing changes for a site that behaves normally. Your sites update themselves within about 12 hours.

  42. Product

    Sign back in without losing what you had open

    If you leave the dashboard sitting overnight, or close your laptop with it open, your sign-in eventually lapses. Until now that showed up as a bare login screen, or a message telling you to reload the page, and whatever you had open was gone. The dashboard now checks your session when you come back to the tab, and renews it quietly when it can. When it has genuinely expired you get a banner telling you so, and signing back in puts you where you were, with your work still on screen.

  43. Product

    A simpler way to read the dashboard

    The view switcher at the top has a new option: **Simple view**. Every form collapses to a single line with just its name, pass or fail status, when it was last checked, and the error if it is failing. Click any row to expand the full detail (check buttons, frequency, pass rate, delivery and so on) and click the name to collapse it again. Sites with a failing form open automatically so problems stay in sight, and the site header keeps everything it shows today: uptime, SSL, deliverability and checkout status. Your choice sticks, so if you prefer the quieter view the dashboard always opens that way.

  44. Product

    Jump from a warning straight to the form

    When the browser render check flags a form as possibly broken, the dashboard now gives you a way to go see for yourself: an **Open page** link next to the warning takes you straight to the page the form lives on, in a new tab. Forms also show a small arrow next to their name whenever Formitor knows which page they are on, so a manual look is always one click away.

  45. Product

    Removed forms: a clear heads-up instead of a silent red

    When a form disappears from your site, because it was deleted or the plugin powering it was deactivated or removed, Formitor now notices within a few minutes. Instead of the old failing status lingering for a month, the form flips to an amber Removed state on your dashboard, and you get one email listing everything that vanished from that site. That way an accidental plugin deactivation gets caught right away. If the removal was intentional, click **Dismiss** on the removed form to hide it immediately, or just leave it: it hides on its own after 7 days. Monitoring history is kept for 30 days, so a form that comes back within that window resumes with its full record intact. After 30 days the history is cleared for good.

  46. Product

    Truer results for Contact Form 7 dropdowns

    Many Contact Form 7 dropdowns use their first line as placeholder text, something like "Choose one". Our test submissions used to pick that first line, and Contact Form 7 rejected it, so a healthy form could show as failing even though real visitors had no problem. Test submissions now skip the placeholder and choose a real option, so those forms report their true status. The plugin updates itself to v0.2.35 within 12 hours; there is nothing you need to do.

  47. Product

    Smarter DMARC checks and a dismissible warning

    Formitor now checks DMARC the same way mailbox providers do. When a site sends from a subdomain such as www or mail, receivers fall back to the record on the main domain, so our check follows the same order. Sites that publish DMARC at the top level no longer see a false "DMARC missing" warning for their subdomains. If a site really has no DMARC record and you have decided that is fine for now, you can hide the warning. Open the site's **Deliverability** strip and choose **Dismiss DMARC warning**. The badge changes to a grey **DMARC dismissed** instead of green: Formitor keeps checking every day, and the real status returns on its own the moment a record appears. **Restore DMARC warning** brings it back at any time.

  48. Product

    Failing checks now explain themselves

    Click any error in **Results** and the detail window now leads with two new sections: **What this means**, a plain explanation of what actually happened, and **How to fix it**, the most likely fix for that exact failure. The raw technical detail stays underneath for support conversations. The explanations cover the failure types we see in practice: broken email sending, anti-spam and captcha rejections, firewall blocks, forms with no notification configured, unreachable sites, and more.

  49. Plugin · v0.2.33

    Fewer false alarms: three fixes from a full audit of failing checks

    We audited every failing form across the fleet and traced each failure to its root cause. Three turned out to be on our side, and all three are fixed. Forms that have no email notification configured (for example a form that only feeds a CRM or webhook) used to fail every delivery test, since there was never an email to verify. They now pass on successful submission, with delivery shown as unverified rather than failed. Forms protected by WPForms' anti-spam token used to reject our tests with "Antispam token is invalid"; the plugin now includes a valid token with every test. And on servers that answer internal connections without HTTPS, local delivery tests used to fail before reaching the form; the plugin now falls back to a safe internal connection automatically. Sites update to v0.2.31 on their own.

  50. Product

    Email reminders when a site stops updating the plugin

    Connected sites normally update the Formitor plugin by themselves. When one falls behind (one version behind for five days, or two or more versions behind for three days), that usually means something on the site is blocking the update check, so we email the account owner with the exact steps: open **Plugins**, find **Formitor Spoke**, click **Check for updates**, then **Update now**. One email per release, never a stream of them. Releases that fix a security issue skip the waiting period: owners of sites still on an older version hear from us within minutes of the release being flagged.

  51. Plugin · v0.2.30

    The plugin now tells you when a firewall blocks our checks

    If a firewall or security service starts blocking Formitor's checks after a site is connected, the site's WordPress admins now see a notice right in wp-admin: which service is doing the blocking, the two IP addresses to allow, and a link to the matching guide. The notice goes away on its own once the addresses are allowed. Dismissing it snoozes it for seven days; while the block remains, the reminder comes back. Monitoring keeps running in protected mode the whole time, since the plugin reports out on its own. Sites update to v0.2.30 automatically.

  52. Product

    Firewalled sites now connect in protected mode

    Adding a site that sits behind Cloudflare, a WAF, or a security plugin used to fail with a connection error. Now it connects in protected mode: monitoring starts through the plugin's own reporting, and the connection window tells you which firewall blocked our direct checks, with steps to optionally allow our IP addresses for instant rechecks and full browser checks. A test button confirms the moment the allowlist works. Step by step guides cover Cloudflare, Sucuri, Wordfence, MalCare and host level firewalls, and every guide lists both of our IP addresses so a failover never breaks an allowlist.

  53. Plugin · v0.2.29

    Delivery tests now run on sites behind a firewall

    Until now, a site that blocked incoming requests reported its status, plugin version, and form list, but delivery tests stayed off. The plugin now runs those tests on the site itself. Formitor queues the test, your site picks it up on its next report, submits the test entry locally, watches the notification email go out, and reports the raw result back. The verdicts and alerts you see on the dashboard are the same ones a directly checked site gets. When a test submission fails, the result now also records the exact response the form returned, so the error shown on the dashboard tells you what went wrong instead of only that it failed. Update to plugin version 0.2.29 or later to get both changes; sites on automatic updates pick them up on their own.

  54. Plugin · v0.2.27

    Sites behind a firewall now report their status automatically

    If your site sits behind Cloudflare, a WAF, or a security plugin that blocks outside requests, Formitor could not always reach it. The dashboard would show the plugin as inactive even when it was installed, running, and perfectly healthy. The plugin now reports out to Formitor on its own schedule instead of waiting to be contacted. Outgoing requests are not affected by the rules that block incoming ones, so protected sites come through correctly. What this fixes: - Sites that showed "plugin inactive" by mistake now show their real status. - The plugin version and your form list stay up to date on those sites. - Nothing to configure. No firewall rules, no allowlisting, no IP addresses to add. This happens quietly in the background and adds no measurable load to your site.

  55. Product

    Incidents, escalation & maintenance windows

    Uptime monitors now open trackable incidents you can acknowledge, resolve, and annotate. Add per-monitor escalation policies (notify more channels if an incident stays unacknowledged), schedule one-off or recurring maintenance windows that pause alerts without denting uptime, and set a latency threshold to flag a monitor as degraded (slow but up).

  56. Product

    Uptime monitoring

    Monitor any website, URL, TCP port, SSL certificate, or cron heartbeat, with latency history, 24h/7d/30d/90d uptime %, incident tracking, and optional display on your public status pages. Add monitors from the new Monitors section in the sidebar.

    Read the full post
  57. Plugin · v0.2.25

    Fixed: updating a site from the hub no longer deactivates the plugin

    When you pushed a plugin update from the hub, WordPress could leave the plugin deactivated after the update (which also made the site look like it needed a manual update). The plugin now reactivates itself automatically after a hub-triggered update. Note: a site still on an older version runs the old code to install this one, so that single update may still need a one-time reactivation; after a site is on 0.2.25 or newer, hub updates are safe.

    Read the full post
  58. Product

    Connect an AI agent to Formitor (MCP)

    You can now connect an AI agent (Claude and others) to Formitor over MCP. From More, open AI access to generate a token, then add it to your agent. The agent can list your sites, ask what is broken right now, pull a single site's full status, and read your recent alerts. Access is read-only and scoped to your account. Tokens are shown once and can be revoked anytime.

    Read the full post
  59. Plugin · v0.2.23

    Hijack forms: live-test any form straight to your own inbox

    Turn on Hijack forms from the top admin bar (it shows on your front-end pages too), enter one or more email addresses (it defaults to your own), and every form notification you trigger while testing goes to those inboxes instead of the client. Test on Gmail, Outlook, anywhere, without editing each form's recipient. Real visitor submissions are never affected, and the mode turns itself off automatically after the window you pick.

    Read the full post
  60. Product

    Reconnect a site without deleting it

    Regenerated a site key or secret? Open a site's Edit panel and choose Update connection keys. The URL and site key are already filled in, so you just paste a fresh secret and reconnect. Your site keeps all of its monitoring history. A successful reconnect also clears the plugin inactive badge right away.

  61. Plugin · v0.2.22

    Copy your site URL, and your shared secret stays hidden

    The Formitor plugin's Tools screen now shows your Website URL with a one-click Copy button, so connecting a site to the hub is copy, copy, copy. Your shared secret is now masked by default with a Show/Hide toggle, so it will not sit in plain sight on your screen or in a screenshot. Copy still grabs the real value.

  62. Product

    Security & reliability hardening

    A deep security pass across the whole platform: stricter database access rules (including uniform MFA enforcement on all account data), hardened server-side request validation on every site-facing check, per-account rate limits on the AI assistant and support tickets, integrity-verified plugin updates (each release is now checksum-verified before installing), and integrity-pinned dashboard scripts. No action needed on your side.

    Read the full post
  63. Product

    Enable deep browser checks on any form, and see the screenshot when it fails

    Tier-3 deep check is now available to all Pro subscribers. Enable it per form with the new **🤖 On/Off** toggle in the form row. When active, a real headless browser fills out the form and clicks Submit every week. It catches problems that server-side checks can't see, like hidden-required fields that block submission, broken submit buttons, or JavaScript errors that only appear in a real browser. If a deep check fails, click the **✕ deep check failed** badge to open the screenshot taken at the moment it got stuck, so you can see exactly what went wrong.

    Read the full post
  64. Product

    Search all your form test results from one place

    The new Mail Log in the dashboard gives you a searchable, cross-site view of every form check result. Filter by site, form, delivery status, or date range, or type any text to search by email address, subject, error message, or source page. Useful for tracking down a specific failed delivery or seeing at a glance what happened across all your sites.

    Read the full post
  65. Plugin · v0.2.17

    Search and filter the mail log in wp-admin

    The Mail Log tab in the Formitor plugin now has a full filter bar: search by recipient email, subject, form name, or page URL; narrow to a specific form from a dropdown; and limit results to the last 7 or 30 days. All filters compose together and stay active when you page through results or switch between the All / Sent / Failed / Formitor tests / Real mail tabs.

    Read the full post
  66. Product

    Update the plugin on all your sites from one button

    No more updating the Formitor plugin site by site. The new "Update sites" button in the dashboard pushes the latest plugin to every connected site at once and shows you a per-site result. And from this version on, each site keeps its Formitor plugin up to date automatically: when we ship an update, your sites pull it within about a day with nothing for you to do. (A site running a much older plugin needs one final manual update from its own wp-admin to switch this on; after that it's hands-off.)

    Read the full post
  67. Product

    See when a site's Formitor plugin is deactivated

    If the Formitor plugin gets deactivated on a site while the site itself is still up, the dashboard now shows a “Plugin inactive” badge on that site, so you know monitoring has stopped there and can reactivate it, instead of it silently going quiet.

  68. Product

    Paused sites show as “Paused” on shared status pages

    If you pause a site or a form, your shared/public status page now shows it as “Paused” (grey) instead of hiding it or showing green, so people viewing the link aren't misled into thinking everything's being checked.

    Read the full post
  69. Product

    A friendlier welcome for invited users

    When you accept an invite to Formitor, you now get a short welcome with a one-click option to set a password, and a reminder that you can also sign in with a magic link or with Google.

  70. Product

    See each form's 7-day test history

    Every form now has a History button that opens the last 7 days of synthetic checks: when it passed, the delivery status, how long each check took, and the exact error on any failure. Quick way to see whether a form has been flaky.

    Read the full post
  71. Product

    Pause an individual form, with a timer

    Each form now has a Pause control in the dashboard: pause for 1h, 4h, 24h, or until you resume. Paused forms aren't submitted and don't alert, and timed pauses resume themselves automatically.

    Read the full post
  72. Plugin · v0.2.14

    Gravity Forms test emails fully blocked (async notifications)

    Gravity Forms sends its notifications through a background process on a separate request, which slipped past the request-scoped test-mail guard, so a synthetic test could reach a Gravity form's real recipient. v0.2.14 adds an always-on guard that blocks any notification for a Formitor test entry, including those async background sends. Update Gravity sites to v0.2.14.

    Read the full post
  73. Product

    Pause monitoring at any level (admin)

    The admin dashboard has a new Monitoring tab to pause synthetic checks for the entire system, a single client, a site, or an individual form. Paused means no test submissions and no alerts until you resume. The per-site pause is also on each site card in the main dashboard.

    Read the full post
  74. Product

    Render-check now names the affected forms

    When the browser render-check flags forms that may be broken in-browser, the dashboard now lists exactly which forms and badges each one in the form list, instead of only showing a count. In the grid and compact views the warning is shortened so it no longer overflows the card.

    Read the full post
  75. Product

    Pause monitoring for a site in one click

    Each site card now has a Pause/Resume button. Pausing a site stops Formitor from submitting test data and from sending alerts for it until you resume, handy while a site or its forms are being worked on. Paused sites show a “Paused” badge and are dimmed so they don't read as healthy.

    Read the full post
  76. Plugin · v0.2.13

    Test emails can no longer reach client Cc/Bcc recipients

    Hardening for synthetic test submissions. When a test notification is redirected to your monitoring inbox, Formitor now strips every To/Cc/Bcc the form itself set, so the monitoring inbox is the only recipient. Previously a client address placed in a form notification's Bcc (or Cc) could still receive the synthetic test email. Update your sites to v0.2.13 to apply.

  77. Plugin · v0.2.11

    Update the Formitor plugin in one click

    No more downloading a zip and uploading it by hand. Formitor now updates like any other WordPress plugin: when a new version is available, your site's **Plugins** screen shows an update notice with a one-click **Update now** button, and you can switch on **automatic updates** if you prefer. A **Check for updates** link (on the Plugins row and on the Formitor settings page) checks for the newest version on demand, and the installed version is shown right on the Formitor page. One-time note: a site needs to be on v0.2.9 or later once (a single manual upload) before one-click updates begin. After that, every future update is one click.

    Read the full post
  78. Product

    See which sites need a plugin update

    Your dashboard now flags any site running an outdated Formitor plugin. An **Update** badge appears on the site card showing the installed version and the latest available one, so you can keep your whole fleet current at a glance.

    Read the full post
  79. Plugin · v0.2.7

    Gravity Forms is now supported

    Formitor now discovers and monitors **Gravity Forms**, alongside WPForms, Contact Form 7, Elementor, Fluent Forms and Ninja Forms. Each Gravity form is tested end to end like any other: a real (synthetic) entry is submitted, the stored entry is confirmed, and the notification email's delivery is verified. It also handles Gravity forms protected by **reCAPTCHA**, so a CAPTCHA-guarded form still gets a genuine, passing check instead of a false failure. Update the Formitor plugin to v0.2.7 or later on the site to pick it up.

    Read the full post
  80. Product

    In-app notifications

    Your alerts now show up right in the dashboard. A new **bell** in the top bar surfaces form failures and recoveries, site outages, SSL expiries, deliverability problems, lead-volume anomalies and checkout issues, each **tagged with the site (and form)** it's about and color-coded by severity. Mark them read, dismiss, or click through. These arrive **alongside** your existing email / Slack / Teams / SMS alerts (not instead of them), so an important heads-up is harder to miss.

    Read the full post
  81. Product

    Formitor now checks your forms in a real browser

    Your standard checks confirm the back end accepts a lead. But a form can pass that and still be impossible for a real visitor to submit: a required field hidden by conditional logic, or a popup that never opens. Formitor now also opens each form in a real browser, the way a visitor would, and flags any that can't actually be submitted (and names exactly which ones). See the guide “when a form looks fine but won't submit” in the Help center.

    Read the full post
  82. Plugin · v0.2.3

    Spam-filter-aware form testing (CleanTalk)

    Formitor now tests your forms correctly even when your site runs the **CleanTalk** anti-spam filter. Previously CleanTalk could block our synthetic test submissions (usually because they arrive from our monitoring servers rather than a normal browser) and a perfectly healthy form would show up as failing. Signed Formitor tests are now recognised and allowed through, so your results reflect what real visitors actually experience. Your spam protection for real visitors is completely unchanged: only Formitor's own cryptographically-signed test request is let through, and only for that single request. No setup needed: just update the Formitor plugin to **v0.2.3** on each site.

    Read the full post
  83. Plugin · v0.2.1

    Checkout monitoring for WooCommerce

    Formitor now monitors your WooCommerce checkout, not just your forms, because a broken checkout means lost sales. On a schedule it places a tiny $0 test order, confirms the order completes and its confirmation email is actually delivered, then deletes the test order. No payment is ever charged, and your store admin is never notified of the test. The checkout page itself is also health-checked every ~10 minutes to catch a white screen or fatal error fast. Turn it on per site from your dashboard with the 🛒 Checkout button (point it at a $0 test product), and the status shows on your dashboard and on the status pages you share with clients. Fluent Cart and SureCart support are on the way.

    Read the full post
  84. Product

    Clearer pass-rate on every form

    Each form now shows its pass rate as a count and a percentage (for example 50/65, 77%) so you can see at a glance how many of the recent checks passed, not just the percentage.

  85. Product

    Tell us what to build next

    The Help center now has a "Request a feature" option alongside Contact us and Report a bug. Pick a category, describe the idea, and it comes straight to us. It's a quick way for beta testers to help shape where Formitor goes.

  86. Product

    Website uptime & SSL monitoring

    Formitor now watches whether each site is actually up, not just whether its forms pass. Every site is checked about every 10 minutes, and a page that loads but shows a white screen, a WordPress critical error, or a maintenance screen now counts as down (a 200 OK that's really broken won't fool it). When a site goes down it's confirmed within about a minute, and recovery is caught just as quickly: fast alerts without false alarms from a momentary blip. Formitor also tracks each site's SSL certificate and warns you before it expires (30, 14, 7 and 1 day out, and immediately if it's already invalid). Uptime and SSL status show on your dashboard and on the status pages you share with clients.

    Read the full post
  87. Product

    AI assistant: chat & deliverability explainer

    Ask the in-app assistant how to use Formitor or how to fix a deliverability issue. It is grounded on your own sites and the latest SPF/DKIM/DMARC results, with a safe, deterministic fallback.

    Read the full post
  88. Product

    Weekly email reports

    Get a Monday digest of uptime, failing forms, leads and deliverability across all your sites. Turn it on under Notifications.

  89. Product

    Help center: What's new and always-current articles

    The Help center now includes this "What's new" changelog, and the help articles are kept continuously up to date.

  90. Product

    Inbox placement & deliverability diagnostics

    See where your form emails actually land (Inbox, Promotions or Spam) and get SPF/DKIM/DMARC checks with one-click rechecks and tailored fixes.

    Read the full post
  91. Product

    Account security: passwords and 2FA

    Set a password, enable two-factor authentication with any authenticator app, and manage your profile from the dashboard.

    Read the full post
  92. Product

    Sharper deliverability verdicts

    Inbox-placement and DKIM checks now read authentication results from real delivered messages, for hard, accurate verdicts instead of guesses.

    Read the full post
  93. Plugin · v0.1.30

    hCaptcha support: full CAPTCHA coverage

    Forms protected by hCaptcha are now monitored too, including Contact Form 7 and Elementor. With Turnstile and reCAPTCHA v2/v3 already covered, Formitor now works behind every major CAPTCHA, on all five form plugins.

    Read the full post
  94. Product

    Report a bug or contact us

    Reach the team right from the dashboard. Bug reports automatically attach helpful context so issues get fixed faster.

  95. Product

    Client status pages

    Share a clean, read-only status page with each client: no login required, with your choice of default view, revocable anytime.

    Read the full post
  96. Plugin · v0.1.29

    reCAPTCHA v2 support completed

    Both reCAPTCHA v2 and v3 are now fully supported across all five form plugins.

    Read the full post
  97. Product

    In-app Help & Knowledge Base

    A searchable help center covering setup, alerts, deliverability and sharing, plus an AI assistant you can ask about your own sites.

  98. Plugin · v0.1.28

    reCAPTCHA v3 support across every form plugin

    Forms protected by reCAPTCHA v3 are now monitored across Contact Form 7, Fluent Forms, WPForms, Elementor and Ninja Forms.

    Read the full post
  99. Plugin · v0.1.25

    Admin screen polish

    Refinements to the in-WordPress admin: the menu-location dropdown stays readable on dark themes and on hover, and long mail-log subjects are clamped with a full-text tooltip. (Versions 0.1.16, 0.1.19, 0.1.21, 0.1.24-0.1.25.)

  100. Product

    More ways to get alerted

    Send alerts to Slack, Discord, Microsoft Teams, SMS (via your own Twilio), or any webhook (Zapier, Make, n8n). Alerts fire only on a change of state.

  101. Product

    Integration heartbeat

    For forms wired to a CRM or automation, Formitor watches that real leads keep reaching your integration, and warns you if they stop.

    Read the full post
  102. Product

    Lead-volume anomaly alerts

    Formitor learns each form's normal lead volume and warns you if leads suddenly dry up. It catches silent failures even when the form still looks fine, and it never stores your lead data.

    Read the full post
  103. Plugin · v0.1.20

    Monitors forms behind Turnstile and reCAPTCHA

    Test submissions now pass cleanly through forms protected by Cloudflare Turnstile and Google reCAPTCHA. The protection stays fully on for real visitors: only Formitor's own signed test is recognised, so bots gain nothing.

    Read the full post
  104. Product

    Recipient deliverability checks

    Each form's notification address is checked for a dead or misconfigured domain, a common cause of silently lost leads.

    Read the full post
  105. Plugin · v0.1.18

    New safety nets: lead-volume alerts and recipient checks

    The plugin now powers lead-volume anomaly alerts (a heads-up if enquiries suddenly dry up) and checks each form's notification address for a dead or misconfigured domain, all without ever storing your form data.

    Read the full post
  106. Plugin · v0.1.17

    More resilient on hardened sites

    Monitoring keeps working on sites that lock down the WordPress REST API, without weakening their security.

  107. Plugin · v0.1.15

    Reliability improvements

    Behind-the-scenes fixes for consistently accurate delivery checks, including correct matching on sites in timezones behind UTC.

  108. Product

    Site uptime monitoring

    Every site is pinged on a schedule, so you see real uptime percentage and get an alert the moment a site goes down or recovers.

    Read the full post
  109. Plugin · v0.1.12

    Better support for complex forms

    Forms with required choices (consent checkboxes, radio buttons and dropdowns) are now detected and completed correctly during tests, including Contact Form 7 required fields.

  110. Product

    Dashboard redesign and List / Grid / Compact views

    A refreshed dark dashboard that follows your system theme, with site logos, starring and drag-to-reorder, plus three views: List, Grid, and a compact "NOC wall" for watching a large fleet at a glance.

  111. Product

    Core form monitoring

    Formitor tests your forms on a schedule and confirms the notification email is actually sent and delivered. It alerts you only when something changes (a form starts failing, or recovers), so there is no constant noise.

  112. Plugin · v0.1.9

    A cleaner in-WordPress setup screen

    A redesigned Tools > Formitor screen: one tidy page with Settings and Mail Log tabs, one-click copy of your connection details, and a clean branded look.

  113. Product

    Find your $0 test product automatically

    The 🛒 Checkout dialog now has a **Find $0 products** button: Formitor asks your site's plugin for its $0 products and offers them in a dropdown. Pick one and the test product ID (and checkout URL, if empty) fill themselves. Works for WooCommerce product IDs and SureCart price IDs alike, so no more hunting through edit-screen URLs.

    Read the full post
  114. Plugin · v0.2.2

    SureCart checkout monitoring

    Checkout monitoring now supports **SureCart** stores alongside WooCommerce. By default Formitor runs a silent pipeline probe (verifies your SureCart connection, test product, and $0 checkout pricing; no order created, no emails sent). Optionally, enable the **full order test** per site to also verify order creation and the customer confirmation email via a test-mode order (heads-up: SureCart platform-sends a TEST-labeled new-order notice to your store's notification recipients on each run, which Formitor can't suppress; that's why it's opt-in). Configure it from the site's 🛒 Checkout dialog; the test product ID accepts SureCart price/product IDs (UUIDs) as well as WooCommerce numeric IDs.

    Read the full post
  115. Plugin · v0.1.0

    Formitor plugin launches

    The Formitor plugin (the "spoke") arrives: automatic form discovery across WPForms, Contact Form 7, Elementor, Fluent Forms and Ninja Forms, a signed HMAC-authenticated API, synthetic test tagging, and automatic cleanup. Test submissions are tagged and never reach your real CRM, integrations, or notification inboxes.

Stop losing leads you can't see.

Put a smoke detector on every client’s lead form. Set up in minutes.