WP Manifestindependent plugin directory
manifest / forms / glx-secure-contact

GLX Secure Contact (AJAX + reCAPTCHA)

A minimal WordPress contact form plugin

by vexmage · github.com/vexmage/glx-secure-contact

0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/vexmage/glx-secure-contact/archive/refs/heads/main.zip

A minimal WordPress contact form plugin focused on simplicity, security, and clean architecture.

Built to avoid bloated form plugins while still providing essential protections and a modern AJAX-based user experience.


Features

  • Shortcode: [glx_secure_contact]
  • AJAX submission (no page reloads)
  • Nonce verification
  • Honeypot field (anti-bot)
  • Simple IP-based rate limiting (1 submission per IP per 60s)
  • Optional Google reCAPTCHA v2 ("I'm not a robot" checkbox)
  • Accessible UI (ARIA live region for feedback)

Architecture

This plugin follows a simple separation of concerns:

  • PHP (WordPress layer)

    • Registers shortcode
    • Handles AJAX endpoint (admin-ajax.php)
    • Validates and sanitizes input
    • Sends email via wp_mail
  • JavaScript (client layer)

    • Intercepts form submission
    • Sends data via fetch
    • Handles success/error UI states

This keeps WordPress as a lightweight integration layer while allowing modern frontend behavior.


Installation

  1. Clone or download into your plugins directory:
wp-content/plugins/glx-secure-contact/
  1. Activate GLX Secure Contact in WordPress Admin (Plugins → Installed Plugins)

  2. Add the shortcode to any page:

[glx_secure_contact]

Configuration

Secrets (like email and reCAPTCHA keys) are not committed to Git.

Copy the sample config:

cp wp-content/plugins/glx-secure-contact/config.sample.php \
   wp-content/plugins/glx-secure-contact/config.local.php

Edit config.local.php:

define('GLX_CONTACT_TO', 'you@example.com');
define('GLX_RECAPTCHA_SITE_KEY', 'your-site-key-here');
define('GLX_RECAPTCHA_SECRET', 'your-secret-key-here');

config.local.php is ignored by Git (see .gitignore)


reCAPTCHA Setup

  1. Go to the Google reCAPTCHA Admin Console
  2. Register your domain
  3. Select reCAPTCHA v2 → "I'm not a robot" Checkbox
  4. Copy your Site Key and Secret Key
  5. Add them to config.local.php

Styling

The plugin includes minimal default styles.

Override in your theme’s CSS as needed.


Development

  • PHP 7.4+
  • WordPress 5.8+
  • MIT Licensed

Packaging

Create a zip for upload:

zip -r glx-secure-contact.zip glx-secure-contact/ -x "*.git*" -x "*/node_modules/*"

Notes

This plugin is intentionally minimal and avoids heavy dependencies. It can theoretically be extended to integrate with external services (APIs, databases, or other backends) while keeping the WordPress layer lightweight.


License

MIT License


Credits

Created by Great Lynx Designs