BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
HXFE — Code-First Forms icon
Actively maintained Tested with WP 7.1

HXFE — Code-First Forms

Define forms as PHP arrays. AI-ready, Git-managed, zero database — contact forms, step forms, chatbots, and surveys. Powered by htmx.

Active installs<10New
Downloads · 30d427▲ +72.2% vs prev. 30d
Rating—0 reviews
Health score60/100Fair
All-time downloads1.2KSince Jun 2026
Support resolved—No recent threads
RequiresWP 6.0PHP 7.4+
Downloads · 7d82▼ -43.1% week over week
Our verdict

Use with caution

HXFE — Code-First Forms works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.

  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

112334Jul 4Aug 17Oct 1
Yesterday9
Daily average (1y)11
Peak day50Jun 12, 2026
Last 12 months1.2K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where HXFE — Code-First Forms stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
ajax >100 8,214 Best ajax plugins →
chatbot >100 1,479 Best chatbot plugins →
contact form >100 8,341 Best contact form plugins →
form builder >100 4,619 Best form builder plugins →
htmx #6 7 Best htmx plugins →

About HXFE — Code-First Forms

From the official readme · v1.4.6

Description

HXFE — Code-First Forms is a code-first WordPress form plugin. Instead of building forms in a GUI, you define them as PHP arrays and place a shortcode anywhere.

Because forms are PHP arrays, AI coding tools (Claude, Cursor, GitHub Copilot, Codex) can read and edit them directly — no screenshots, no GUI walkthroughs, no copy-paste. Your forms live in your codebase: version-controlled, automatically deployed, and free from database migration issues.

Even if you don’t write PHP yourself, AI agents can handle the schema for you — just describe what you want in plain language and get back working code.

Why code-first?

  • AI-ready by design — Forms defined as PHP arrays are the lowest-cost input for AI agents. Ask Claude, Copilot, Cursor, or Codex to “add a phone number field” and get back a diff-ready code change instantly. No screenshots needed, no GUI explanation required. You don’t even need to write PHP yourself — AI agents can build and maintain your forms from plain-language instructions. Ships with llms.txt, ai-reference.md, and CLAUDE.md for agentic coding tools
  • Fully customizable — All styles use CSS custom properties (design tokens). Ships with DESIGN.md for a complete variable reference and customization examples.
  • Git history for free — Every change to your form shows up in git diff
  • Deploy without fear — Forms are code, so they deploy with your theme. No more “the form disappeared on production”
  • Dynamic options — Pull select options from get_posts(), taxonomies, or any PHP source. No manual updates
  • One schema, four UIs — Add step_mode: chatbot or one_by_one to transform the same fields into a completely different interface

Four UI modes from one schema

  • Normal form — Classic input → confirm → complete flow (default)
  • Step form — Multi-page with progress bar (steps array)
  • One-by-one — Question-at-a-time survey style (step_mode: 'one_by_one')
  • Chatbot — Chat bubble interface with typing animation, header, and timestamps (step_mode: 'chatbot')

Key features

  • 15 field types: text, email, tel, url, textarea, select, radio, checkbox, checkbox_group, number, date, file, honeypot, reCAPTCHA, privacy
  • Conditional logic: show_if, required_if, skip_if (hide_if deprecated) — works in chatbot mode too
  • Dynamic routing: to_rules, subject_rules, complete_redirect_rules, complete_html_rules based on submitted values
  • Diagnosis mode: use complete_html_rules without to — show results without sending email
  • Download after submit: download_url shows a download button on the complete screen (document request forms)
  • Form availability window: available_from / available_until with custom before/after HTML
  • Custom validation: pattern, minlength, maxlength, error_message schema keys + hxfe_validate_field and hxfe_validate_form filter hooks
  • Field HTML injection: before_html / after_html schema keys
  • Page slug tracking: subject auto-appended with [form-id@page-slug] for per-page aggregation
  • Webhook support: send to Zapier, Make, Slack, or any HTTP endpoint
  • SMTP built-in: Gmail, SendGrid, Mailgun, or custom SMTP
  • File upload: attached to email, auto-deleted after send
  • IP restriction and password-protected forms
  • iframe embedding with per-form CORS control (allowed_origins)
  • Zero cookies: GDPR/EU cookie-compliant by design
  • Clean default styles: CSS custom properties (design tokens) for easy theme integration, responsive at 768px
  • Schema examples panel in admin: 11 copy-paste samples to get started fast
  • AI-friendly: ships with llms.txt and ai-reference.md for agentic coding tools
  • Source code: available on GitHub

Minimum example

add_filter( 'hxfe_schemas', function( $schemas ) {
    $schemas['contact'] = [
        'id'      => 'contact',
        'to'      => 'admin@example.com',
        'subject' => 'Contact: {name}',
        'fields'  => [
            [ 'key' => 'name',  'type' => 'text',     'label' => 'Name',    'required' => true ],
            [ 'key' => 'email', 'type' => 'email',    'label' => 'Email',   'required' => true ],
            [ 'key' => 'body',  'type' => 'textarea', 'label' => 'Message', 'required' => true ],
            [ 'key' => 'hp',    'type' => 'honeypot' ],
        ],
    ];
    return $schemas;
} );

Shortcode: [hxfe_form id="contact"]

Chatbot example

$schemas['support'] = [
    'id'        => 'support',
    'to'        => 'admin@example.com',
    'step_mode' => 'chatbot',
    'bot_name'  => 'Support Bot',
    'bot_icon'  => '🤖',
    'greeting'  => 'Hi! How can I help you today?',
    'fields'    => [
        [ 'key' => 'name',  'type' => 'text',  'label' => 'Name',
          'bot_message' => 'What is your name?' ],
        [ 'key' => 'email', 'type' => 'email', 'label' => 'Email',
          'bot_message' => 'Thanks {name}! What is your email?' ],
        [ 'key' => 'hp', 'type' => 'honeypot' ],
    ],
];

Diagnosis chatbot (no email)

$schemas['diagnosis'] = [
    'id'        => 'diagnosis',
    // No 'to' — result shown without sending email
    'step_mode' => 'chatbot',
    'complete_html_rules' => [
        [ 'when' => ['plan', '==', 'basic'],
          'html' => '<h3>Basic plan recommended</h3><p>Hi {name}!</p>' ],
        [ 'when' => 'default',
          'html' => '<p>Thank you, {name}. We will be in touch.</p>' ],
    ],
    'fields' => [ ... ],
];

Organize schemas in separate files

// functions.php — one line
require_once get_template_directory() . '/inc/hxfe-forms.php';

Or use HXFE as a standalone plugin with glob() auto-loading.

External Services

This plugin optionally connects to Google reCAPTCHA when the recaptcha field type is enabled in a form schema.

What the service is and what it is used for:
Google reCAPTCHA is a spam-prevention service. When enabled, it loads a script from Google’s servers and verifies the user’s response server-side to determine whether the form submission is from a human or a bot.

What data is sent and when:
When a page containing an HXFE form with reCAPTCHA is loaded, the visitor’s browser loads the reCAPTCHA script from google.com. On form submission, the reCAPTCHA token generated in the visitor’s browser is sent to Google’s verification endpoint (https://www.google.com/recaptcha/api/siteverify) along with your site key. No other form field data is transmitted to Google.

reCAPTCHA is disabled by default. It is only active when a site administrator adds a recaptcha field to a form schema and configures valid API keys in the plugin settings.

Links:
* Google reCAPTCHA Terms of Service: https://policies.google.com/terms
* Google Privacy Policy: https://policies.google.com/privacy

Installation

  1. Upload the plugin folder to /wp-content/plugins/
  2. Activate in Plugins → Installed Plugins
  3. Add schemas via the hxfe_schemas filter in functions.php
  4. Place [hxfe_form id="your-id"] in any page or post
  5. View all registered forms at Settings → Form Engine — Forms

Frequently asked questions

What is htmx and why does HXFE use it?

htmx is a lightweight JavaScript library that lets you add AJAX behavior using HTML attributes — no build step, no npm, no React required. HXFE uses htmx to handle the form’s input → confirm → complete flow without page reloads. Since htmx works with server-rendered HTML (which WordPress and PHP are great at), it fits naturally into a WordPress plugin.

Can I use HXFE with AI coding tools like Claude, Cursor, GitHub Copilot, or Codex?

Yes — this is one of HXFE’s strengths. Because forms are defined as PHP arrays, AI tools can read and edit them directly. HXFE ships with llms.txt and ai-reference.md that AI agents can reference to understand the schema format. Just ask your AI assistant to “add a phone number field to the contact schema” and it will return a precise code change — no screenshots or GUI interaction needed. You don’t need to write PHP yourself. AI agents like Claude, Codex, or Cursor can generate and maintain the entire schema from plain-language instructions.

Is HXFE secure?

Yes. HXFE follows WordPress security best practices throughout: nonce verification on all AJAX endpoints, sanitization on input, escaping on output, hash_equals() for password comparison, and REMOTE_ADDR-only IP matching to prevent spoofing. reCAPTCHA fields fail closed in production if misconfigured. Uploaded files are deleted immediately after email delivery. The plugin has passed WordPress.org’s manual security review.

Does HXFE save submissions to the database?

No. HXFE sends email only. This is intentional — forms defined in code stay lightweight and free of database dependencies. Use Webhook support to send data to external services like Google Sheets or a CRM.

Can I use HXFE without writing PHP?

HXFE is designed for developers who want code-first form management. If you need a GUI builder, plugins like WPForms or Fluent Forms may be a better fit.

Does the chatbot mode work with conditional logic?

Yes. show_if conditions work in chatbot mode — hidden fields are automatically skipped. You can also use {field_key} placeholders in bot_message to reference previous answers.

Is HXFE GDPR / EU cookie compliant?

Yes. HXFE uses zero cookies. Form state is preserved via hidden JSON fields on the server side, not browser storage.

Can I embed forms on external domains?

Yes. Use [hxfe_iframe id="contact" site="https://your-site.com"] and configure allowed origins in Settings → Form Engine → iframe / CORS Settings.

How do I connect to Zapier or Make?

Add a webhooks array to your schema with the target URL. HXFE will POST form data as JSON after each successful submission. Webhook failures do not block form submission.

Can I skip the confirmation screen?

Yes. Add 'confirm' => false to your schema. Works for normal forms and step forms.

Can I restrict a form to specific IP addresses?

Yes. Add allowed_ips to your schema with a list of IPs or CIDR ranges. Visitors outside the whitelist see a blocked message, which you can customize with ip_blocked_html. allowed_ips => [ '192.168.1.0/24', '203.0.113.5' ], ip_blocked_html => 'This form is only available on the campus network.',

Can I require a password to access a form?

Yes. Add an auth key to your schema. To keep passwords out of Git, define them as constants in wp-config.php and reference them in the schema. In wp-config.php: define( 'HXFE_STAFF_PASS', 'your-secret-password' ); In your schema: ‘auth’ => [ ‘users’ => [ [ ‘id’ => ‘staff’, ‘password’ => defined(‘HXFE_STAFF_PASS’) ? HXFE_STAFF_PASS : ” ] ] ] Brute-force protection is built in — access is locked for 15 minutes after 5 failed attempts.

Can I prevent PHP files from being edited via the WordPress admin?

Yes. Add this to wp-config.php: define( 'DISALLOW_FILE_EDIT', true ); This disables the theme and plugin editors in the WordPress admin. It pairs well with HXFE’s code-first approach — forms and code are managed via deployment, not the admin UI.

Can I save uploaded files somewhere other than email attachments?

HXFE deletes uploaded files from the server immediately after sending the email. This is intentional — keeping files on the server increases security risk and GDPR responsibility. For permanent storage, the recommended approach is to use Gmail + Google Apps Script (GAS): set up a time-based trigger that reads incoming form emails and saves attachments to a designated Google Drive folder. This keeps files off your WordPress server entirely and lets you manage access through Google’s permission system.

Changelog

1.4.6

  • Security: Webhook requests now use reject_unsafe_urls to block requests to internal IPs and unsafe ports (SSRF hardening, found in monthly AI-driven security review)

1.4.5

  • Added: hxfe_after_submit action hook — fires after successful form submission with $form_id, $values, $schema. Enables third-party plugins (e.g. HXMD) to capture submissions

1.4.4

  • Added: Cloudflare Turnstile field type (type: 'turnstile') — privacy-friendly spam protection as an alternative to reCAPTCHA
  • Added: Turnstile managed mode (auto-verification widget) and invisible mode (no UI, token obtained on submit)
  • Added: Turnstile site key / secret key settings under Settings → HXFE
  • Added: Server-side verification against Cloudflare’s siteverify API with fail-closed behavior in production

1.4.3

  • Fixed: Resolved double URL-encoding of the SMTP test result message (removed redundant urlencode/urldecode)
  • Fixed: Sanitize $_GET[‘test_msg’] before use in the settings page
  • Fixed: Shortened Short Description to under 150 characters

1.4.2

  • Added: SECURITY.md — security policy, vulnerability reporting, and disclosure timeline
  • Added: MAINTENANCE.md — architecture overview, htmx update steps, and fork guide
  • Docs: Updated ai-reference.md — added design philosophy and maintainability section for AI agents

1.4.1

  • Updated: htmx 1.9.12 → 2.0.10
  • Changed: htmx script handle renamed to ‘hx-htmx’ (HX series shared handle)
  • Improved: Added wp_script_is() check to prevent duplicate htmx loading

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best HXFE — Code-First Forms alternatives

All ajax plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 zipaddr-jp zipaddr-jp zipaddr-jp is a collaborative tool that automatically inputs addresses from postal codes. by ta_terunuma 50K+ ★★★★★★★★★★ 5 (6) 2 months ago 77
2 SearchWP Live Ajax Search SearchWP Live Ajax Search Template powered live search for any WordPress theme. Does not require SearchWP, but will… by Syed Balkhi 50K+ ★★★★★★★★★★ 4.7 (36) 2 months ago 85
3 WP-Polls WP-Polls Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your… by Lester Chan 40K+ ★★★★★★★★★★ 4.2 (136) 1 month ago 87
4 WP-PostRatings WP-PostRatings Adds an AJAX rating system for your WordPress site's content. by Lester Chan 20K+ ★★★★★★★★★★ 4.3 (179) 1 month ago 87
5 WPC AJAX Add to Cart for WooCommerce WPC AJAX Add to Cart for WooCommerce It is a highly effective plugin for helping online stores cut down the site’s loading time… by WPClever 10K+ ★★★★★★★★★★ 4.4 (18) 2 weeks ago 83
6 Ajax Cart AutoUpdate for WooCommerce Ajax Cart AutoUpdate for WooCommerce A light plugin that automatically updates cart page and mini-cart when product quantity is… by taisho 7K+ ★★★★★★★★★★ 5 (214) 6 years ago 46
7 Relevanssi Live Ajax Search Relevanssi Live Ajax Search Template powered live search for any WordPress theme. Compatible with Relevanssi search! by Christoph Vielgrader 7K+ ★★★★★★★★★★ 5 (9) 5 months ago 58
8 Enable CORS Enable CORS Please read the plugin description before installing to ensure compatibility and avoid… by Dev Kabir 6K+ ★★★★★★★★★★ 3.7 (3) 3 months ago 66
9 Load More Anything Load More Anything Add Load More button for your blog post, custom type, Comments, page, Category, Recent… by Akhtarujjaman Shuvo 5K+ ★★★★★★★★★★ 4.5 (73) 11 months ago 59
10 YMC Filter YMC Filter A powerful and flexible plugin to filter and display posts, custom post types, and other… by YMC 4K+ ★★★★★★★★★★ 4.8 (34) 1 day ago 92

FAQ

HXFE — Code-First Forms: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 2, 2026

Is HXFE — Code-First Forms free?

Yes. HXFE — Code-First Forms is free to download and use from the official WordPress.org plugin directory.

Is HXFE — Code-First Forms safe to use in 2026?

HXFE — Code-First Forms works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.

How many websites use HXFE — Code-First Forms?

HXFE — Code-First Forms is active on <10 WordPress websites and has been downloaded 1,198 times since it launched in June 2026. It was downloaded 427 times in the last 30 days.

Does HXFE — Code-First Forms work with WordPress 7.1?

Yes. The developer has tested HXFE — Code-First Forms up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.

What PHP version does HXFE — Code-First Forms need?

HXFE — Code-First Forms requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was HXFE — Code-First Forms last updated?

The latest version, 1.4.6, was released on August 20, 2026 (1 month ago).

Who makes HXFE — Code-First Forms?

HXFE — Code-First Forms is developed and maintained by youheiokubo.

What are the best alternatives to HXFE — Code-First Forms?

The most popular alternatives to HXFE — Code-First Forms are zipaddr-jp (50K+ installs), SearchWP Live Ajax Search (50K+ installs) and WP-Polls (40K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.