Title: FW Tools for Elementor Forms
Author: Olaf Lederer
Published: <strong>3 Tuber 2026</strong>
Last modified: 4 Tuber 2026

---

Search plugins

![](https://ps.w.org/fw-tools-for-elementor/assets/banner-772x250.jpg?rev=3727310)

![](https://ps.w.org/fw-tools-for-elementor/assets/icon-256x256.png?rev=3726343)

# FW Tools for Elementor Forms

 By [Olaf Lederer](https://profiles.wordpress.org/finalwebsites/)

[Download](https://downloads.wordpress.org/plugin/fw-tools-for-elementor.0.3.2.zip)

 * [Details](https://kab.wordpress.org/plugins/fw-tools-for-elementor/#description)
 * [Reviews](https://kab.wordpress.org/plugins/fw-tools-for-elementor/#reviews)
 *  [Installation](https://kab.wordpress.org/plugins/fw-tools-for-elementor/#installation)
 * [Development](https://kab.wordpress.org/plugins/fw-tools-for-elementor/#developers)

 [Support](https://wordpress.org/support/plugin/fw-tools-for-elementor/)

## Description

Keep building your forms in Elementor and manage their protection from one settings
page. The plugin checks submissions in the background without asking visitors to
solve a CAPTCHA. You can enable or disable individual checks to suit your site.

When a submission is rejected, the spam log helps you understand why. Use it to 
investigate repeated attempts or troubleshoot problems reported by visitors.

The optional confirmation step serves two purposes: visitors can review their details
before sending, and the additional interaction creates another hurdle for automated
submissions. The form’s configured actions, such as sending an email, run only after
confirmation. You choose which forms use this step.

The plugin requires Elementor and Elementor Pro with the Form widget. It is not 
a standalone form builder.

#### Features

 * Browser verification without an additional CAPTCHA challenge.
 * Checks for missing page information, missing or invalid tokens, and submissions
   made too quickly.
 * Honeypot and JavaScript submit controls.
 * Temporary email field names when browser verification is active.
 * Settings to enable or disable individual protection checks.
 * IP and email rate limiting after repeated suspicious submissions.
 * Optional integration with WP Armour for spam logging and rate limiting.
 * An optional confirmation step with a configurable title for each form.
 * A local spam log with recent entries in the WordPress admin and a downloadable
   JSON Lines file.
 * Optional country detection using Country.is.
 * An option to remove plugin settings and stored data when deleting the plugin.

#### Spam log

Logging is enabled by default and can be switched off independently of rate limiting.
Disabling logging does not delete existing entries.

Entries can contain the submission time, form name, name, email address, IP address,
country code, a message excerpt, and the rejection reason. The message excerpt is
limited to 125 characters, with whitespace and line breaks combined for easier reading.

The log keeps the latest 500 entries by default. Older entries are removed when 
the limit is exceeded; entries do not expire based on their age. Developers can 
change the maximum number of entries with the `fw_tfe_spam_log_limit` filter.

The log is stored as a JSON Lines file in the `fw-tfe-logs` directory inside the
WordPress uploads directory. Spam log entries are not stored in the WordPress database.

#### IP and email rate limiting

Rate limiting can be enabled or disabled in the plugin settings. Save your chosen
setting before using it. When enabled, it uses a separate table in the existing 
WordPress database.

The table stores separate counters for IP addresses and hashes of normalized email
addresses, together with the start of each counting period and the end of any block.
Email addresses are not stored as plain text in this table. Names and messages are
not stored in it.

Three suspicious attempts from the same IP address, or five using the same email
address, within five minutes trigger a block lasting one hour. Further attempts 
during that block do not extend it. Ordinary field validation errors and expired
verification tokens do not count towards the limit.

Expired records are removed in batches during subsequent form requests. Cleanup 
does not rely on WP-Cron. Disabling rate limiting stops enforcement but leaves the
table in place.

#### Confirmation before sending

Enable « Require confirmation before sending » in an Elementor form’s options to
let visitors review their details before the configured form actions run. You can
customize the confirmation title for each form. This feature is off by default.

This is an on-page review step, not email address verification. Forms with upload
fields skip this step and continue through the normal Elementor submission flow.

Pending submissions are stored temporarily in a separate database table, including
form field data, form and page identifiers, and form metadata. A confirmation is
valid for 15 minutes and can be used only once. Confirmed records remain stored 
until cleanup; cancelling an unclaimed confirmation deletes its pending record.

Expired records are removed by an hourly WP-Cron task. Actual deletion can occur
later, depending on when WordPress runs scheduled tasks. Temporary confirmation 
storage is independent of spam logging.

#### WP Armour integration

When WP Armour is active and the integration is enabled, its Elementor form rejections
can be included in this plugin’s spam log and rate limiting. Logging and rate limiting
must each be enabled for their respective functions to apply.

WP Armour is optional and is not bundled with this plugin. Disabling the integration
does not disable WP Armour’s own protection.

### External services

#### Country.is

Country.is is an optional IP geolocation service used to retrieve a country code
for a spam log entry. It is disabled by default and is used only after a site administrator
selects Country.is in the country detection setting.

When logging a rejected submission with a valid IP address, the plugin sends that
address in an HTTPS request to `https://api.country.is/{ip}`. Submitted names, email
addresses, and message contents are not included in this lookup. As with other server-
side HTTP requests, the service also receives the connection from your web server.

Country.is does not require an API key. According to the Country.is website, the
API is free for commercial use, its data comes from MaxMind GeoLite2 and Cloudflare
geolocation, and API requests are not logged by the service.

Country.is does not currently publish separate Terms of Service or Privacy Policy
pages. Therefore, no direct links to such pages can be provided. The service information,
usage conditions and privacy-related information published by Country.is are available
on its website:

[Country.is](https://country.is/)

### Privacy and data storage

When logging is enabled, the plugin stores the personal information listed in the
Spam log section on your server. When rate limiting is enabled, IP addresses, hashes
of normalized email addresses, and temporary rate limit state are stored in a dedicated
database table.

When the confirmation step is used, submitted form fields and metadata are stored
temporarily in a separate database table, along with a hash of the confirmation 
token, an expiry time, and whether the confirmation has been used. This storage 
is not limited to the short message excerpt kept in the spam log.

Only optional country detection sends a visitor’s IP address to Country.is. Include
your use of these features in your site’s privacy information as appropriate.

The spam log has an entry limit rather than an age limit. Rate limit records become
eligible for deletion after their counting period and any block have expired; physical
deletion takes place during later form requests. Confirmation records expire after
15 minutes and are removed by the scheduled cleanup described above.

## Screenshots

[⌊Spam log entries.⌉⌊Spam log entries.⌉[

Spam log entries.

[⌊Plugin information and REST API test.⌉⌊Plugin information and REST API test.⌉[

Plugin information and REST API test.

[⌊Elementor forms setting for confirmation screen.⌉⌊Elementor forms setting for 
confirmation screen.⌉[

Elementor forms setting for confirmation screen.

[⌊Example confirmation screen.⌉⌊Example confirmation screen.⌉[

Example confirmation screen.

[[

## Installation

This plugin requires both Elementor and Elementor Pro to be installed and active.

 1. Upload the plugin directory to `/wp-content/plugins/` and activate FW Tools for
    Elementor Forms in WordPress.
 2. Open Tools > Elementor Forms and select the Settings tab.
 3. Review the protection settings and save your choices for spam logging, IP and email
    rate limiting, and country detection.
 4. Check browser verification on the Information tab and use « Test endpoint » or «
    Test again » if needed.
 5. Optionally enable « Require confirmation before sending » in the options of individual
    Elementor forms.
 6. Submit a test through your Elementor form and check that normal submissions still
    work.

Country detection is optional and disabled by default. The confirmation step is 
disabled until enabled for an individual form.

## FAQ

### Does this work with the free version of Elementor?

The plugin works with the Form widget provided by Elementor Pro. Elementor Pro is
required in addition to Elementor.

### Do I need to change my form fields?

For the spam log to capture a name, set that field’s ID to `name` in Elementor. 
This refers to the field ID, not its visible label.

The plugin uses the first populated email field and the first populated textarea
field for the logged email address and message. Their field IDs can be different.
Forms without those fields can still be used; the corresponding log values remain
empty.

### Does the plugin log every form submission?

No. When enabled, the spam log records rejections from this plugin’s page information,
submit control, honeypot, browser verification, and temporary email field checks.
It can also record WP Armour rejections when the integration is enabled.

Successful submissions are not added to the spam log. Requests rejected because 
an IP address or email address is already blocked do not create additional entries.
The optional confirmation step stores pending form data separately, even when spam
logging is disabled.

### What happens if someone leaves a form open for a long time?

Browser verification tokens expire after two hours. An expired token causes the 
submission to be rejected with a form error. These rejections can be logged but 
do not count towards a rate limit block.

The optional confirmation step has a separate 15-minute validity period.

### Does rate limiting block every visitor using that IP address?

Yes. IP limits apply across forms on the site, so visitors sharing a connection 
can share a block. Email limits also apply across forms, using the submitted email
address independently of the IP address. A block on either identifier prevents submission.

### Can I use rate limiting without the spam log?

Yes. Rate limiting has its own database table and works independently of spam logging.

### Does country detection block countries?

No. It adds a country code to spam log entries to help you analyse rejected submissions.
Country-based blocking is not included.

### What happens when the token endpoint is unavailable?

Token verification is enforced only when the plugin’s REST endpoint check reports
that the endpoint is available. Other enabled checks, including the missing page
information check, honeypot, submit control, and rate limiting, can still apply.
Temporary email field names depend on browser verification.

### What happens when I delete the plugin?

By default, stored settings and data are retained. Enable the option to delete all
plugin settings and the spam log before deleting the plugin if you want uninstall
to remove them. This also removes the rate limit and confirmation tables and their
related settings.

Deactivating the plugin or switching off a feature does not uninstall its stored
data. Deactivation stops the scheduled confirmation cleanup.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“FW Tools for Elementor Forms” is open source software. The following people have
contributed to this plugin.

Contributors

 *   [ Olaf Lederer ](https://profiles.wordpress.org/finalwebsites/)

“FW Tools for Elementor Forms” has been translated into 1 locale. Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/fw-tools-for-elementor/contributors)
for their contributions.

[Translate “FW Tools for Elementor Forms” into your language.](https://translate.wordpress.org/projects/wp-plugins/fw-tools-for-elementor)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/fw-tools-for-elementor/),
check out the [SVN repository](https://plugins.svn.wordpress.org/fw-tools-for-elementor/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/fw-tools-for-elementor/)
by [RSS](https://plugins.trac.wordpress.org/log/fw-tools-for-elementor/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.3.2

 * Added: Optional detection of random-looking names in the field with ID « name».
   Blocked attempts are logged as « random_name » and count toward rate limiting.
 * Fixed: WP Armour compatibility with the confirmation step. Initial submissions
   remain protected by WP Armour; confirmed submissions skip its repeated check 
   after successful single-use token validation.

#### 0.3.1

 * Added Dutch translations
 * Added assetts (icon and banner)

#### 0.3.0

 * Added an optional confirmation step so visitors can review their details before
   sending.
 * Added honeypot and additional browser-side form checks.
 * Added temporary email field names for browser verification.
 * Extended rate limiting to track suspicious submissions by both IP address and
   email address.
 * Added integration with WP Armour to include its Elementor form rejections in 
   spam logging and rate limiting.
 * Added settings to enable or disable individual protection checks.
 * Extended spam logging with additional rejection reasons and the form name.
 * Updated the plugin name to FW Tools for Elementor Forms.
 * Updated documentation for external services, temporary data storage, and data
   removal.

#### 0.2.0

 * Browser verification for Elementor Pro forms.
 * Local spam logging with admin display and download.
 * Optional Country.is country detection.
 * Optional IP rate limiting and cleanup of expired records.
 * Settings for logging, country detection, rate limiting, and uninstall data removal.

## Meta

 *  Version **0.3.2**
 *  Last updated **4 n isragen ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 8.0 or higher **
 *  Languages
 * [Dutch](https://nl.wordpress.org/plugins/fw-tools-for-elementor/) akked [English (US)](https://wordpress.org/plugins/fw-tools-for-elementor/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/fw-tools-for-elementor)
 * Tags
 * [anti-spam](https://kab.wordpress.org/plugins/tags/anti-spam/)[forms](https://kab.wordpress.org/plugins/tags/forms/)
   [rate limiting](https://kab.wordpress.org/plugins/tags/rate-limiting/)[spam protection](https://kab.wordpress.org/plugins/tags/spam-protection/)
 *  [Advanced View](https://kab.wordpress.org/plugins/fw-tools-for-elementor/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/fw-tools-for-elementor/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/fw-tools-for-elementor/reviews/)

## Contributors

 *   [ Olaf Lederer ](https://profiles.wordpress.org/finalwebsites/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/fw-tools-for-elementor/)