formsieve Docs Support
All docs pages

Installing from WordPress.org

From version 1.1.0, Formsieve is one free plugin, distributed through WordPress.org as Formsieve ("Formsieve – AI Contact Form Spam Filter"). It protects Gravity Forms and Contact Form 7 forms (see the Gravity Forms and Contact Form 7 pages on formsieve.com). The AI spam check needs a Formsieve key (Getting a Formsieve key); the local filters work without one.

Requirements

  • WordPress 6.6 or later and PHP 7.4 or later.
  • Gravity Forms 2.9 or later, or Contact Form 7 6.0 or later, or both. With Contact Form 7, Flamingo is recommended, so that blocked submissions are kept and can be restored.

Install

  1. In the WordPress admin, go to Plugins → Add New Plugin and search for "Formsieve".
  2. Install and activate Formsieve. On a site that uses both Gravity Forms and Contact Form 7, the one plugin protects both, with one key.
  3. Open Formsieve in the admin menu and follow the set-up wizard (Getting started).

Until Formsieve is listed on WordPress.org (as of 2026-09-26 it is not yet), the search finds nothing: download the zip from your Formsieve account instead (Key → Downloads; a free trial account is enough), upload it under Plugins → Add New Plugin → Upload Plugin and activate it. That copy gets its updates from Formsieve's update server with your key (see "Critical updates" below).

Nothing is sent anywhere until you enter a key and accept the data notice in the wizard.

Updates

New versions come from WordPress.org like any other plugin's: they show on Dashboard → Updates and on the Plugins screen. There is no licence, and nothing to activate for updates.

Install updates automatically

WordPress can install each new version of Formsieve for you, in the background. It stays off until you switch it on, in any of these places. They are all the same WordPress setting, so a change in one shows in the others:

  • the last step of the set-up wizard: tick Install Formsieve updates automatically (recommended) before Finish setup;
  • Settings → Advanced → Updates: the same box, then Save update setting;
  • the Plugins screen: Enable auto-updates in the plugin's row.

We recommend it. Formsieve's service and its questions change over time, and a plugin that is too old can stop being accepted (Troubleshooting). Formsieve never switches automatic updates on by itself. WordPress looks for updates about twice a day and installs an automatic update soon after it finds one (WordPress's schedule as of 2026-09-26).

Formsieve shows the setting without a box, and says why, when it cannot be changed there:

  • automatic updates are turned off for the whole site, for example with AUTOMATIC_UPDATER_DISABLED or DISALLOW_FILE_MODS in wp-config.php, or by your host;
  • your host or another plugin decides automatic updates for plugins (the auto_update_plugin filter); the screen shows whether they are on or off;
  • your account cannot update plugins (the update_plugins capability). On a multisite network only a network administrator can change it, and the setting applies to every site in the network.

Critical updates (copies downloaded from formsieve.com)

Until Formsieve is live on WordPress.org, copies downloaded from formsieve.com get their updates from Formsieve's update server, with your Formsieve key. There, a release can be marked critical: a security fix that should not wait. When a critical release is newer than the version a site runs, WordPress installs the latest version on that site automatically, even if automatic updates are not switched on for Formsieve. Every other release waits for you, unless you switched automatic updates on. The settings box of these copies says so. It leaves that line out when one of the first two cases below applies, because a critical update then waits too (as of 2026-09-26). When only automatic plugin updates are turned off (the plugins_auto_update_enabled filter, often set by a host), a critical update still installs, and the box says so.

A critical update still waits on the Plugins screen, like any other update, when:

  • automatic updates are turned off for the whole site (AUTOMATIC_UPDATER_DISABLED, DISALLOW_FILE_MODS or your host);
  • a filter on auto_update_plugin returns false for Formsieve;
  • the site's PHP version is lower than the release requires;
  • WordPress cannot write the plugin's files without asking for FTP or SSH details;
  • the plugins folder, or a folder above it, is under version control (Git, Subversion, Mercurial or Bazaar).

The settings box does not check the last three cases.

Copies installed from WordPress.org get every update from WordPress.org, so the critical flag does not apply to them.

Where to get help

  • Questions about the plugin (settings, verdicts, compatibility): support@formsieve.com, or the plugin's support forum on WordPress.org once Formsieve is listed there (as of 2026-09-27 it is not yet).
  • Questions about your account, plan, invoices or key: support@formsieve.com, from the e-mail address of your Formsieve account. Please do not post your key or your visitors' submissions in the public forum.

Before you write, see Troubleshooting, and include the plugin and WordPress versions, the result of Test connection and, for a specific submission, its request ID (shown in the entry's Formsieve panel).

Moving from a formsieve.com download

Copies of Formsieve downloaded from formsieve.com get their updates from Formsieve's update server, with your Formsieve key. Once Formsieve is live on WordPress.org, a further update switches the site to WordPress.org updates automatically. Nothing to reinstall.

If you prefer, you can instead deactivate and delete the downloaded copy and install from WordPress.org: with Settings → Advanced → Uninstall off (the default), deleting the plugin keeps your settings, so the new copy picks them up.

Moving from Formsieve for Gravity Forms or Formsieve for CF7

Before version 1.1.0, Formsieve came as two plugins, Formsieve for Gravity Forms and Formsieve for CF7 (they were never listed on WordPress.org). Formsieve replaces both, and they get no further updates. To move a site that runs one of them, or both:

  1. Back up the site.
  2. Install Formsieve (from WordPress.org once it is listed, or from your account's Key → Downloads) and activate it.
  3. Activation moves the data. It moves the settings, the allow and block lists, the learned senders, the decision log and the connection (key and consent) where this version can use it. The Formsieve pages then show what moved, what did not, and which settings differed between the two old plugins (Formsieve keeps the values of the one that was connected).
    • The copy from your account also switches the old plugins off, and if you had switched on automatic updates for an old plugin, it keeps that choice.
    • The copy from WordPress.org changes no other plugin: a notice asks you to deactivate the old plugin on the Plugins screen, and Formsieve takes over its forms as soon as you do. Decisions the old plugin logs until then move over when you deactivate it. Turn on automatic updates under Settings → Advanced if you want them.
  4. Open Formsieve and finish the wizard if it asks. Version 1.1.0 connects with a Formsieve key only: a site that used its own AI provider key with version 1.0.0 connects a Formsieve key and gives consent again.
  5. Submit a test message and check the entry, the Flamingo message or the Log tab.

The old plugins' data stays for 30 days, so you can go back: deactivate Formsieve and reactivate the old plugin, which works at once with its own settings. After 30 days, or when you click Remove it now in the notice, Formsieve removes the old plugins' options and log tables. Gravity Forms entries, Flamingo messages and their Formsieve details are kept: Formsieve uses them.

You can delete an old plugin from the Plugins screen at any time after the move. Formsieve turns its "Delete all plugin data on uninstall" setting off first, so deleting it removes nothing Formsieve needs.

For developers, hooks, options and constants now use the prefix formsieve_ (FORMSIEVE_ for constants), and the WP-CLI command is wp formsieve (Developer hooks and WP-CLI).

What the plugin sends, and to whom

The readme on WordPress.org has an "External services" section that lists exactly when Formsieve contacts its service, what it sends and never sends, and links to the terms and privacy policies. The same information, in more detail: Data processing.