iinsight Form Notifications
Sends acknowledgement and admin notification emails when the iinsight NDIS external form is successfully submitted. Includes SMTP configuration and a dedicated debug log.
by Stallioni Net Solutions · github.com/sanjeev-stallioni/iinsight-notifications
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/sanjeev-stallioni/iinsight-notifications/archive/refs/heads/main.zipiinsight Form Notifications — WordPress Plugin
Sends acknowledgement and admin notification HTML emails when any iinsight external form is successfully submitted. Works with multiple forms on different pages. Includes SMTP configuration, WordPress visual editor for email templates, and a dedicated debug log viewer.
Installation
- Upload the
iinsight-notifications/folder to/wp-content/plugins/ - Activate the plugin via WordPress Admin → Plugins
- Configure via Settings → iinsight Notify
How It Works
- JS loads on every page and patches
XMLHttpRequest/fetchto watch forapi_referralcalls - A delegated click listener on
documentwatches for the iinsight submit button — this survives forms being injected dynamically and re-injected when a tab is switched (see Tabbed / Dynamic Forms below) - User clicks Submit → the active form is resolved from its rendered
form_id, form values are captured,submitClickedis set, and the per-submission dedupe guard is reset - iinsight makes its API call → intercepted → only the actual save (
COMMANDRC) counts as a submission → on success, notification is sent viasendBeacontoadmin-ajax.php - WordPress AJAX handler validates nonce, sanitises data, calls mailer
- Mailer sends the appropriate email(s): intake forms get the user acknowledgement + admin notification; feedback forms get a single acknowledgement (see Form Routing)
api_referral.php is reused for many operations during form interaction
(SDCHK conditional show/hide, GMG confirmation message, GSC config) —
only the save-referral call (COMMAND RC) means the form was actually
submitted, so the intercept inspects the request body (isReferralSave()) and
ignores everything else. This prevents the acknowledgement firing while a user
is still filling the form or after a failed validation.
Tabbed / Dynamic Forms
The CITTA feedback forms share a single page through an HTML/CSS tab interface
and are injected on demand (Support Coordinator is shown by default; switching
tabs tears down one form and injects the other). Because the form DOM is
created and destroyed at runtime, the listener does not bind to the submit
button up front — it delegates the click on document and resolves the form
at click time.
All field lookups are scoped to the clicked form's #BeSoftware-Scheduler
root rather than read globally, so the plugin is independent of the outer
container a form is embedded in (scheduler-sc, scheduler-participant, a
bare page, or anything else) and is safe even if several forms are present on
one page at the same time.
Form Routing (allow-list)
Routing is by iinsight form_id and is an explicit allow-list — any form
whose id is not listed is ignored (no email is sent). The two maps live at the
top of iinsight-listener.js; add an id to the relevant map to extend it.
| Form | form_id |
Path |
|---|---|---|
| NDIS FORM | 13 |
intake → user acknowledgement + admin notification |
| PRIVATE FORM | 14 |
intake → user acknowledgement + admin notification |
| Support Coordinator Feedback | 15 |
feedback → single acknowledgement (on opt-in) |
| Participant Feedback | 17 |
feedback → single acknowledgement (on opt-in) |
-
Intake forms (
INTAKE_FORMS) captureMEDIUM_TEXT_1/MEDIUM_TEXT_2(name),EMAIL_ADDRESS_1,PHONE_NUMBER_1, the funding dropdowns, and the "Funding Type" field, then send both the user acknowledgement and the admin notification. -
Feedback forms (
FEEDBACK_FORMS) map the discovery-call radio group plus the contact fields revealed on opt-in:Form form_idContact radio Name field Support Coordinator Feedback 15RADIO_BUTTON_7MEDIUM_TEXT_7Participant Feedback 17RADIO_BUTTON_5MEDIUM_TEXT_3When the user answers the discovery-call question with "Yes" or "Maybe", a single acknowledgement email is sent to
EMAIL_ADDRESS_1. No admin notification is sent, and nothing is sent for "Not right now". The acknowledgement subject and body are editable under Settings → iinsight Notify → Email Content → Feedback Acknowledgement Email (defaults live inIinsight_Mailer::default_feedback_subject()/default_feedback_body()). The opt-in is gated in the JS (wantsContact) and re-checked server-side.
File Structure
iinsight-notifications/
├── iinsight-notifications.php # Plugin bootstrap, constants, activation hooks
├── includes/
│ ├── class-iinsight-admin.php # Admin settings page (4 tabs: General, Email, SMTP, Log)
│ ├── class-iinsight-ajax.php # AJAX endpoint (nonce, rate limit, sanitisation)
│ ├── class-iinsight-assets.php # Enqueues JS + passes PHP vars via wp_localize_script
│ ├── class-iinsight-logger.php # Dedicated logger (writes to /logs/, separate from WP)
│ ├── class-iinsight-mailer.php # Email composition & dispatch with placeholder support
│ ├── class-iinsight-smtp.php # Optional SMTP configuration for wp_mail()
│ └── index.php # Directory access guard
├── assets/
│ └── js/
│ └── iinsight-listener.js # Front-end: XHR intercept + sendBeacon + validation
├── logs/ # Auto-created on activation, protected by .htaccess
│ ├── .htaccess
│ ├── index.php
│ └── iinsight-YYYY-MM.log # Monthly rotating log files
├── index.php
└── README.md
Admin Settings
Located at Settings → iinsight Notify with four tabs:
| Tab | Options |
|---|---|
| General | Enable/disable notifications, admin email override, debug log toggle |
| Email Content | WordPress visual editor (wp_editor) for all three emails — User Acknowledgement, Admin Notification, and Feedback Acknowledgement — each with Subject, Body, and Reset to Default. Intake placeholders: {first_name} {last_name} {full_name} {email} {phone} {funding_type} {site_name} {date} {time}. Feedback placeholders: {contact_name} {email} {phone} {contact_choice} {site_name} {date} {time} |
| Mail Method | WordPress default mail or SMTP (host, port, encryption, auth, from address) with live test button |
| Debug Log | View, download, clear monthly log files |
Security
| Feature | Detail |
|---|---|
| Nonce verification | wp_create_nonce / check_ajax_referer on every AJAX request |
| Input sanitisation | sanitize_text_field, sanitize_email, wp_kses_post on all values |
| Rate limiting | Max 200 submissions per IP per hour via WordPress transients |
| Capability checks | All admin actions require manage_options |
| Directory protection | /logs/ has .htaccess (Deny from all) + index.php guard |
| ABSPATH check | Every PHP file exits immediately if loaded directly |