Sentient Forms is a local-first WordPress plugin for AI-assisted form automation. The current public release supports Gravity Forms, Contact Form 7, WPForms, and Elementor Pro Forms, with builder-specific capability boundaries documented in readme.txt.
The plugin stores site-owned configuration in WordPress: provider settings, external-service consent records, Action templates, custom Actions, form mappings, Execution Events, Submission Ledger records, selected results, migration runs, and model cache data. Webmasters can create and manage their own Actions, including starting from a built-in Action. Sentient Forms Managed Execution remains optional for managed account setup, billing, metering, model execution, support diagnostics, and operational controls. Site owners can also run supported workflows directly through their own OpenRouter account.
For WordPress.org, readme.txt is the public plugin-directory readme and must stay aligned with the submitted package. README.md is a developer-maintenance overview for the GitHub repository.
The clean package builder intentionally excludes this README.md and includes readme.txt, runtime files, generated admin assets, and bundled runtime dependencies. Generated JavaScript and CSS source/build tooling is documented through the public release source URL in readme.txt and assets/dist/SOURCE.md; do not include admin-app/ in the WordPress.org ZIP.
Before submitting a package to WordPress.org, verify the exact ZIP or extracted package, not just the source tree. A submission-ready package must pass:
- WordPress.org package scan.
- WordPress Plugin Check in GitHub Actions.
- GPL-compatible license audit.
- Local and official WordPress.org readme validation.
- Generated admin-asset source verification.
- Release-version surface validation across
sentient-forms.php,readme.txt,admin-app/package.json, and the release manifest.
Do not submit an older public release ZIP after security or compliance fixes land. Build and verify a fresh release artifact, then submit the validated ZIP for that release.
- Local custom tables and repositories for providers, consent, action templates, custom actions, mappings, execution events, migrations, and model cache.
- Direct OpenRouter client using the WordPress HTTP API for key validation and chat completions.
- Optional Sentient Forms Managed Execution for managed AI execution, account state, billing, metering, and support diagnostics.
- Consent-gated provider setup, managed-service setup, telemetry, Site Context generation, and realtime assistant flows.
- Local workspace REST endpoints for templates, custom actions, mappings, execution events, support bundles, and mapping test runs.
- Local prompt rendering, structured JSON result extraction, idempotent execution-event recording, Gravity Forms-style result effects, ledger-backed review surfaces for supported non-Gravity builders, and post-execution notes/email/hooks/webhooks where the adapter supports them.
- Spam Detection and Content Quality Validation during validation on Gravity Forms, Contact Form 7, WPForms, and Elementor Pro Forms. Contact Form 7, WPForms, and Elementor Pro Forms support validation plus ledger-backed after-submission workflows; Elementor Pro Forms requires Elementor Pro Forms APIs.
- Realtime Clarification Assistant suggestions for mapped Gravity Forms fields when an administrator enables the Action and accepts the relevant external-service disclosure. Realtime assistance is not available for Contact Form 7, WPForms, or Elementor Pro Forms. Native notes, spam status, notification controls, webhook controls, and entry links remain descriptor-specific rather than universal.
- Authenticated Spam Guidance that sends selected historical submission excerpts through OpenRouter direct execution or Sentient Forms Managed Execution to improve Spam Detection guidance and save a generated rationale. An active subscription is required; eligible managed credits are used first, with paid Direct OpenRouter fallback when configured and eligible.
- Privacy export/erase hooks, separate retention and cleanup controls for Execution Events and Submission Ledger records, configurable uninstall behavior, and redacted support bundles.
- WordPress.org source/package scanners, release-version checks, readme validation, license audit, and a repeatable clean package-directory builder.
The WordPress.org readme.txt is the authoritative submission disclosure for external services. Keep it current whenever the plugin adds or changes provider paths, telemetry, webhooks, managed-service behavior, realtime suggestions, or AI-generated Site Context.
Current external-service categories disclosed in readme.txt:
- OpenRouter direct execution.
- Sentient Forms Managed Execution.
- Administrator-configured webhooks.
- Realtime Clarification Assistant.
- Spam Guidance using selected historical submission excerpts to produce a generated rationale.
No OpenRouter or Sentient AI execution request should be sent until an administrator has configured and accepted the relevant provider disclosure. Diagnostic consent records remain local metadata; the plugin does not remotely queue or deliver those diagnostic events.
- WordPress stack: Boot the local Docker compose environment or point the plugin at an existing WordPress instance running one of the supported form builders. Activate the plugin with
wp plugin activate sentient-forms. Gravity Forms has the deepest native workflow support. Contact Form 7, WPForms, and Elementor Pro Forms support validation, require the Sentient Forms Submission Ledger for after-submission review workflows, and do not support realtime assistance. Elementor Pro Forms also requires Elementor Pro Forms APIs. - Admin SPA: From
admin-app/, runbun installonce, then use:bun run devfor local SPA development.bun run build:wpbefore committing UI changes; this copies hashed assets intoassets/dist/.bun run check,bun run lint, and targeted Vitest/Playwright suites for SPA verification.
- PHP tooling: Run
composer install, regenerate the class map withphp build/generate-class-map.phpafter adding classes, and execute focused PHPUnit suites undertests/phpunit/. - WordPress.org package checks:
composer wporg-release-version-checkchecks version surfaces in the source tree.composer wporg-source-checkverifies generated admin assets document the public release source URL and build commands.composer wporg-scanchecks the source tree and built admin assets for early package blockers.composer wporg-license-auditchecks source-tree GPL compatibility signals.composer wporg-readme-checkvalidatesreadme.txtlocally.composer wporg-readme-validatevalidatesreadme.txtwith the official WordPress.org readme validator.composer wporg-build-packagebuilds a clean package directory under../temp/YYYY/MM/DD/<time>-wporg-package/sentient-forms.composer wporg-scan-package -- <package-dir>checks the exact package directory.composer wporg-license-audit-package -- <package-dir>checks the exact package directory's license metadata.php scripts/verify-wporg-source.php <package-dir>verifies generated admin asset source metadata in the package.
sentient-forms.phpboots the plugin and registers activation, deactivation, and uninstall hooks.readme.txtis the WordPress.org plugin-directory readme and external-service disclosure.assets/dist/contains generated admin assets copied fromadmin-app/.assets/dist/SOURCE.mddocuments the generated admin asset public source URL and build process for packaged releases.admin-app/contains the SvelteKit admin SPA source, tests, and build scripts.includes/class-sentient-forms-installer.phpowns local table install/upgrade and retention scheduling.includes/repositories/contains local-first data access classes.includes/providers/contains provider-specific clients such as OpenRouter direct execution.includes/services/contains local execution, prompt rendering, result application, privacy/data governance, support bundle, telemetry, and managed-service support.includes/rest-api/controllers/class-local-providers-controller.phpexposes local provider onboarding APIs.includes/rest-api/controllers/class-local-workspace-controller.phpexposes local workspace, execution, support, and test-run APIs.scripts/build-wporg-package.phpbuilds the clean package directory used for WordPress.org artifact checks.scripts/scan-wporg-package.phpperforms early static checks for source/package cleanliness.scripts/audit-wporg-licenses.phpaudits GPL-compatible license metadata.scripts/validate-wporg-readme.phpruns local or official WordPress.org readme validation.scripts/verify-wporg-source.phpverifies generated asset source disclosure.../docs/plans/option-2-local-first-migration-plan.mdis the workspace-level local-first migration plan.
Release confidence is based on the repository gates and the root Sentient Forms greenlight checklist. A production package should not be promoted until the exact built artifact has passed the WordPress.org package scan, Plugin Check, license audit, readme validation, focused PHPUnit/SPA checks, and browser-path evidence for the supported workflows in that release. For 0.12.0 copy, that means validation proof on all four Form Sources, Gravity Forms realtime proof, and after-submission native or Submission Ledger proof without implying Gravity Forms-style native parity for builders that do not support it.
For WordPress.org submission, prefer the latest validated GitHub release ZIP and manifest over an ad hoc local ZIP. The public source tag named in readme.txt and assets/dist/SOURCE.md must exist before upload. If a local rebuild is necessary, run the same package checks against the rebuilt package and preserve the package path/hash in release evidence.
First-party Sentient Forms plugin and admin app code is licensed under GPL-2.0-or-later. Bundled dependencies retain their own GPL-compatible license notices.
This repo ships a tracked pre-commit hook that parses every .github/*.yml file. Enable it once per clone:
git config core.hooksPath .githooksInstall PyYAML if the hook reports that the module is missing.