HXFE — Code-First Forms
Define forms as PHP arrays. AI-ready, Git-managed, zero database — contact forms, step forms, chatbots, and surveys. Powered by htmx.
Use with caution
HXFE — Code-First Forms works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
- Tested with the latest WordPress (7.1)
- Small user base (<10 active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where HXFE — Code-First Forms stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| ajax | >100 |
| chatbot | >100 |
| contact form | >100 |
| form builder | >100 |
| htmx | #6 |
About HXFE — Code-First Forms
From the official readme · v1.4.6Description
HXFE — Code-First Forms is a code-first WordPress form plugin. Instead of building forms in a GUI, you define them as PHP arrays and place a shortcode anywhere.
Because forms are PHP arrays, AI coding tools (Claude, Cursor, GitHub Copilot, Codex) can read and edit them directly — no screenshots, no GUI walkthroughs, no copy-paste. Your forms live in your codebase: version-controlled, automatically deployed, and free from database migration issues.
Even if you don’t write PHP yourself, AI agents can handle the schema for you — just describe what you want in plain language and get back working code.
Why code-first?
- AI-ready by design — Forms defined as PHP arrays are the lowest-cost input for AI agents. Ask Claude, Copilot, Cursor, or Codex to “add a phone number field” and get back a diff-ready code change instantly. No screenshots needed, no GUI explanation required. You don’t even need to write PHP yourself — AI agents can build and maintain your forms from plain-language instructions. Ships with
llms.txt,ai-reference.md, andCLAUDE.mdfor agentic coding tools - Fully customizable — All styles use CSS custom properties (design tokens). Ships with
DESIGN.mdfor a complete variable reference and customization examples. - Git history for free — Every change to your form shows up in
git diff - Deploy without fear — Forms are code, so they deploy with your theme. No more “the form disappeared on production”
- Dynamic options — Pull select options from
get_posts(), taxonomies, or any PHP source. No manual updates - One schema, four UIs — Add
step_mode: chatbotorone_by_oneto transform the same fields into a completely different interface
Four UI modes from one schema
- Normal form — Classic input → confirm → complete flow (default)
- Step form — Multi-page with progress bar (
stepsarray) - One-by-one — Question-at-a-time survey style (
step_mode: 'one_by_one') - Chatbot — Chat bubble interface with typing animation, header, and timestamps (
step_mode: 'chatbot')
Key features
- 15 field types: text, email, tel, url, textarea, select, radio, checkbox, checkbox_group, number, date, file, honeypot, reCAPTCHA, privacy
- Conditional logic: show_if, required_if, skip_if (hide_if deprecated) — works in chatbot mode too
- Dynamic routing: to_rules, subject_rules, complete_redirect_rules, complete_html_rules based on submitted values
- Diagnosis mode: use
complete_html_ruleswithoutto— show results without sending email - Download after submit:
download_urlshows a download button on the complete screen (document request forms) - Form availability window:
available_from/available_untilwith custom before/after HTML - Custom validation:
pattern,minlength,maxlength,error_messageschema keys +hxfe_validate_fieldandhxfe_validate_formfilter hooks - Field HTML injection:
before_html/after_htmlschema keys - Page slug tracking: subject auto-appended with
[form-id@page-slug]for per-page aggregation - Webhook support: send to Zapier, Make, Slack, or any HTTP endpoint
- SMTP built-in: Gmail, SendGrid, Mailgun, or custom SMTP
- File upload: attached to email, auto-deleted after send
- IP restriction and password-protected forms
- iframe embedding with per-form CORS control (
allowed_origins) - Zero cookies: GDPR/EU cookie-compliant by design
- Clean default styles: CSS custom properties (design tokens) for easy theme integration, responsive at 768px
- Schema examples panel in admin: 11 copy-paste samples to get started fast
- AI-friendly: ships with
llms.txtandai-reference.mdfor agentic coding tools - Source code: available on GitHub
Minimum example
add_filter( 'hxfe_schemas', function( $schemas ) {
$schemas['contact'] = [
'id' => 'contact',
'to' => 'admin@example.com',
'subject' => 'Contact: {name}',
'fields' => [
[ 'key' => 'name', 'type' => 'text', 'label' => 'Name', 'required' => true ],
[ 'key' => 'email', 'type' => 'email', 'label' => 'Email', 'required' => true ],
[ 'key' => 'body', 'type' => 'textarea', 'label' => 'Message', 'required' => true ],
[ 'key' => 'hp', 'type' => 'honeypot' ],
],
];
return $schemas;
} );
Shortcode: [hxfe_form id="contact"]
Chatbot example
$schemas['support'] = [
'id' => 'support',
'to' => 'admin@example.com',
'step_mode' => 'chatbot',
'bot_name' => 'Support Bot',
'bot_icon' => '🤖',
'greeting' => 'Hi! How can I help you today?',
'fields' => [
[ 'key' => 'name', 'type' => 'text', 'label' => 'Name',
'bot_message' => 'What is your name?' ],
[ 'key' => 'email', 'type' => 'email', 'label' => 'Email',
'bot_message' => 'Thanks {name}! What is your email?' ],
[ 'key' => 'hp', 'type' => 'honeypot' ],
],
];
Diagnosis chatbot (no email)
$schemas['diagnosis'] = [
'id' => 'diagnosis',
// No 'to' — result shown without sending email
'step_mode' => 'chatbot',
'complete_html_rules' => [
[ 'when' => ['plan', '==', 'basic'],
'html' => '<h3>Basic plan recommended</h3><p>Hi {name}!</p>' ],
[ 'when' => 'default',
'html' => '<p>Thank you, {name}. We will be in touch.</p>' ],
],
'fields' => [ ... ],
];
Organize schemas in separate files
// functions.php — one line
require_once get_template_directory() . '/inc/hxfe-forms.php';
Or use HXFE as a standalone plugin with glob() auto-loading.
External Services
This plugin optionally connects to Google reCAPTCHA when the recaptcha field type is enabled in a form schema.
What the service is and what it is used for:
Google reCAPTCHA is a spam-prevention service. When enabled, it loads a script from Google’s servers and verifies the user’s response server-side to determine whether the form submission is from a human or a bot.
What data is sent and when:
When a page containing an HXFE form with reCAPTCHA is loaded, the visitor’s browser loads the reCAPTCHA script from google.com. On form submission, the reCAPTCHA token generated in the visitor’s browser is sent to Google’s verification endpoint (https://www.google.com/recaptcha/api/siteverify) along with your site key. No other form field data is transmitted to Google.
reCAPTCHA is disabled by default. It is only active when a site administrator adds a recaptcha field to a form schema and configures valid API keys in the plugin settings.
Links:
* Google reCAPTCHA Terms of Service: https://policies.google.com/terms
* Google Privacy Policy: https://policies.google.com/privacy
Installation
- Upload the plugin folder to
/wp-content/plugins/ - Activate in Plugins → Installed Plugins
- Add schemas via the
hxfe_schemasfilter infunctions.php - Place
[hxfe_form id="your-id"]in any page or post - View all registered forms at Settings → Form Engine — Forms
Frequently asked questions
What is htmx and why does HXFE use it?
htmx is a lightweight JavaScript library that lets you add AJAX behavior using HTML attributes — no build step, no npm, no React required. HXFE uses htmx to handle the form’s input → confirm → complete flow without page reloads. Since htmx works with server-rendered HTML (which WordPress and PHP are great at), it fits naturally into a WordPress plugin.
Can I use HXFE with AI coding tools like Claude, Cursor, GitHub Copilot, or Codex?
Yes — this is one of HXFE’s strengths. Because forms are defined as PHP arrays, AI tools can read and edit them directly. HXFE ships with llms.txt and ai-reference.md that AI agents can reference to understand the schema format. Just ask your AI assistant to “add a phone number field to the contact schema” and it will return a precise code change — no screenshots or GUI interaction needed. You don’t need to write PHP yourself. AI agents like Claude, Codex, or Cursor can generate and maintain the entire schema from plain-language instructions.
Is HXFE secure?
Yes. HXFE follows WordPress security best practices throughout: nonce verification on all AJAX endpoints, sanitization on input, escaping on output, hash_equals() for password comparison, and REMOTE_ADDR-only IP matching to prevent spoofing. reCAPTCHA fields fail closed in production if misconfigured. Uploaded files are deleted immediately after email delivery. The plugin has passed WordPress.org’s manual security review.
Does HXFE save submissions to the database?
No. HXFE sends email only. This is intentional — forms defined in code stay lightweight and free of database dependencies. Use Webhook support to send data to external services like Google Sheets or a CRM.
Can I use HXFE without writing PHP?
HXFE is designed for developers who want code-first form management. If you need a GUI builder, plugins like WPForms or Fluent Forms may be a better fit.
Does the chatbot mode work with conditional logic?
Yes. show_if conditions work in chatbot mode — hidden fields are automatically skipped. You can also use {field_key} placeholders in bot_message to reference previous answers.
Is HXFE GDPR / EU cookie compliant?
Yes. HXFE uses zero cookies. Form state is preserved via hidden JSON fields on the server side, not browser storage.
Can I embed forms on external domains?
Yes. Use [hxfe_iframe id="contact" site="https://your-site.com"] and configure allowed origins in Settings → Form Engine → iframe / CORS Settings.
How do I connect to Zapier or Make?
Add a webhooks array to your schema with the target URL. HXFE will POST form data as JSON after each successful submission. Webhook failures do not block form submission.
Can I skip the confirmation screen?
Yes. Add 'confirm' => false to your schema. Works for normal forms and step forms.
Can I restrict a form to specific IP addresses?
Yes. Add allowed_ips to your schema with a list of IPs or CIDR ranges. Visitors outside the whitelist see a blocked message, which you can customize with ip_blocked_html. allowed_ips => [ '192.168.1.0/24', '203.0.113.5' ], ip_blocked_html => 'This form is only available on the campus network.',
Can I require a password to access a form?
Yes. Add an auth key to your schema. To keep passwords out of Git, define them as constants in wp-config.php and reference them in the schema. In wp-config.php: define( 'HXFE_STAFF_PASS', 'your-secret-password' ); In your schema: ‘auth’ => [ ‘users’ => [ [ ‘id’ => ‘staff’, ‘password’ => defined(‘HXFE_STAFF_PASS’) ? HXFE_STAFF_PASS : ” ] ] ] Brute-force protection is built in — access is locked for 15 minutes after 5 failed attempts.
Can I prevent PHP files from being edited via the WordPress admin?
Yes. Add this to wp-config.php: define( 'DISALLOW_FILE_EDIT', true ); This disables the theme and plugin editors in the WordPress admin. It pairs well with HXFE’s code-first approach — forms and code are managed via deployment, not the admin UI.
Can I save uploaded files somewhere other than email attachments?
HXFE deletes uploaded files from the server immediately after sending the email. This is intentional — keeping files on the server increases security risk and GDPR responsibility. For permanent storage, the recommended approach is to use Gmail + Google Apps Script (GAS): set up a time-based trigger that reads incoming form emails and saves attachments to a designated Google Drive folder. This keeps files off your WordPress server entirely and lets you manage access through Google’s permission system.
Changelog
1.4.6
- Security: Webhook requests now use
reject_unsafe_urlsto block requests to internal IPs and unsafe ports (SSRF hardening, found in monthly AI-driven security review)
1.4.5
- Added:
hxfe_after_submitaction hook — fires after successful form submission with$form_id,$values,$schema. Enables third-party plugins (e.g. HXMD) to capture submissions
1.4.4
- Added: Cloudflare Turnstile field type (
type: 'turnstile') — privacy-friendly spam protection as an alternative to reCAPTCHA - Added: Turnstile managed mode (auto-verification widget) and invisible mode (no UI, token obtained on submit)
- Added: Turnstile site key / secret key settings under Settings → HXFE
- Added: Server-side verification against Cloudflare’s siteverify API with fail-closed behavior in production
1.4.3
- Fixed: Resolved double URL-encoding of the SMTP test result message (removed redundant urlencode/urldecode)
- Fixed: Sanitize $_GET[‘test_msg’] before use in the settings page
- Fixed: Shortened Short Description to under 150 characters
1.4.2
- Added: SECURITY.md — security policy, vulnerability reporting, and disclosure timeline
- Added: MAINTENANCE.md — architecture overview, htmx update steps, and fork guide
- Docs: Updated ai-reference.md — added design philosophy and maintainability section for AI agents
1.4.1
- Updated: htmx 1.9.12 → 2.0.10
- Changed: htmx script handle renamed to ‘hx-htmx’ (HX series shared handle)
- Improved: Added wp_script_is() check to prevent duplicate htmx loading
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best HXFE — Code-First Forms alternatives
All ajax plugins →FAQ
HXFE — Code-First Forms: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 2, 2026
Is HXFE — Code-First Forms free?
Yes. HXFE — Code-First Forms is free to download and use from the official WordPress.org plugin directory.
Is HXFE — Code-First Forms safe to use in 2026?
HXFE — Code-First Forms works, but test it on a staging site before relying on it in 2026. Was last updated 1 month ago, and scores 60/100 on our health check.
How many websites use HXFE — Code-First Forms?
HXFE — Code-First Forms is active on <10 WordPress websites and has been downloaded 1,198 times since it launched in June 2026. It was downloaded 427 times in the last 30 days.
Does HXFE — Code-First Forms work with WordPress 7.1?
Yes. The developer has tested HXFE — Code-First Forms up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.
What PHP version does HXFE — Code-First Forms need?
HXFE — Code-First Forms requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was HXFE — Code-First Forms last updated?
The latest version, 1.4.6, was released on August 20, 2026 (1 month ago).
Who makes HXFE — Code-First Forms?
HXFE — Code-First Forms is developed and maintained by youheiokubo.
What are the best alternatives to HXFE — Code-First Forms?
The most popular alternatives to HXFE — Code-First Forms are zipaddr-jp (50K+ installs), SearchWP Live Ajax Search (50K+ installs) and WP-Polls (40K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card