Skip to content

NXForms Changelog ​

What's new in NXForms. Versions up to 1.3.1 were released as NXP Easy Forms, in Free and Pro editions; their entries are merged below.

1.3.1 — 2026-09-28 ​

  • Form login now refuses accounts with multi-factor authentication if their MFA settings can't be checked.
  • Forms now show the normal captcha error instead of a server error when the captcha provider is unreachable.
  • Hardened spam protection so its tokens can never be signed with a default key.
  • Removed the NXP Insiders invitation from the Forms list.
  • Hardened payment status and capture links so they can never be signed with a default key.
  • Fixed the Form API lockout for repeated invalid API keys, which was not taking effect.
  • Fixed a PHP notice when recording payment webhook events.
  • License activation and checks now always connect to nexusplugins.com, including from local and staging sites.

1.3.0 — 2026-09-13 ​

  • Improved form-page cache safety and submission reliability. Sensitive form and resume responses are protected from shared caching across supported Free configurations.
  • Added query-string prefill for supported fields. Configure eligible fields to accept approved values from named URL parameters, with server-side validation and Pro capability protection.
  • Improved form-page cache safety and submission reliability. Sensitive form and resume responses are protected from shared caching across supported Pro configurations.

1.2.9 — 2026-08-28 ​

  • NXP Insiders access. Site administrators can join the private Discord, get early builds, and support continued development of the Free edition through a pay-what-you-want one-time membership.
  • The License screen shows a grace deadline only while your license is actually in grace. An active license no longer shows a grace date under its expiry date.

1.2.8 — 2026-08-25 ​

  • Better warnings when duplicating or importing forms. Duplicating a form now applies the same safeguards as import, and both show readable messages about any settings that were adjusted.
  • Existing payment forms keep working after your license expires. Forms that already had payments enabled continue to create checkouts, complete Stripe and PayPal payments, and run their confirmation emails and integrations on the installed version. Enabling payments on another form, or changing a payment form's settings, requires renewal.
  • Payment forms never submit unpaid. If the payment runtime is missing or broken, the visitor sees a general error and nothing is stored or sent, instead of the submission going through without a charge.
  • Clear payment state in the builder and the Forms list. Payment forms are labeled as operational, grandfathered, or blocked. A grandfathered form's payment settings and its bound Price or Calculation amount are shown read-only, and a Turn off payments action is always available; turning payments off cannot be undone until renewal.
  • Payment credentials and task reminders stay available. With Pro installed, you can still rotate Stripe and PayPal keys and see the payments cleanup task reminder in Options while your license is expired.
  • More resilient payment completion. Provider notifications that arrive while the payment runtime is unavailable are retried by the provider, a payment is never marked complete until its fulfillment has been dispatched, and pending completions are retried automatically at increasing intervals.
  • Safer form duplication. Duplicating a payment form on a lapsed license produces a copy without payments and a warning, instead of a second payment form.

1.2.7 — 2026-08-19 ​

  • Fixed a form-builder regression affecting Select fields. Numeric option values and imported Select configurations now save and validate reliably.
  • Numeric Selects can now drive Pro calculations and payment totals.

1.2.6 — 2026-08-18 ​

  • Fixed a form-builder regression affecting Select fields. Numeric option values and imported Select configurations now save and validate reliably.
  • Fixed failed sign-ins being treated as successful. A login form that rejected the credentials could report success and continue as though the visitor had signed in; it now shows the correct error.
  • Safer error messages on public forms. Unexpected server errors on the login form now show a general message instead of internal technical detail.
  • Correct results and no caching for public form responses. Form submissions and login replies now return the right outcome status and are no longer stored by browsers or shared caches.
  • Session recovery in the form builder. The builder keeps your administrator session alive while you work, tells you clearly if it expires, and lets you sign back in and carry on without losing unsaved changes.
  • Under-the-hood maintenance. Internal modernization for future Joomla compatibility, with no changes to features or workflows.
  • Fixed multi-step navigation button labels. A Page Break's custom Next and Previous text now belongs to the step it starts, while the first step uses its own form-level Next button setting.
  • Clearer first-step settings. The first step's title and Next button controls now have matching help text, better spacing, and clearer descriptions for screen readers.
  • Reliable payment provider notifications. Stripe and PayPal now receive the correct result for every webhook, so genuine failures are retried by the provider instead of being silently accepted.
  • Correct Save & Resume responses. Saving a draft now reports its real outcome, such as an expired security token, instead of appearing to succeed.

1.2.5 — 2026-07-12 ​

  • Under-the-hood maintenance. Internal housekeeping and stability improvements around installation and updates. No changes to features or workflows.
  • Custom first-step titles for multi-step forms. Name the first progress step directly from the form builder; later step titles and navigation button labels remain independent.
  • Hardened Pro update-channel protection with automatic repair. A Pro installation now always stays on the Pro update channel: accidentally installing the Free package over Pro is blocked with clear instructions, older dual-package installations are repaired automatically, and an expired or deactivated license never switches your site to the Free channel. If the installed Pro plugin version ever falls out of step with the component, the admin shows exactly what to reinstall instead of implying a license problem.

1.2.4 — 2026-07-10 ​

  • Unlimited active forms on the free edition. Create and publish as many forms as you need.
  • Multi-column form layouts are now free. Arrange fields side by side in two- or three-column grids and set each field's width, right from the canvas header. Previously a Pro-only feature.
  • Fixed privacy cleanup when deleting multiple paid submissions. Deleting several submissions with linked payments now clears the stored visitor details (submission data and IP address) from every linked payment record, not just one. The financial record itself is still retained.
  • Fixed Save & Resume cleanup on bulk delete. Deleting multiple submissions now also removes the matching saved (partial) entries for all of them, instead of only one.
  • Licensing and updates hardened ahead of launch. Pro now installs as the same package as Free, so upgrading from Free to Pro is a clean in-place upgrade; Pro updates resolve by a stable product identifier; and a license issued for a different product is correctly rejected instead of activating here. No action needed.

1.2.3 — 2026-06-05 ​

  • Automatic submission cleanup now actually runs. The per-form "Automatically delete old submissions" privacy setting is now enforced by a scheduled task, so old submissions are removed on the schedule you set instead of the setting just being saved. Submissions still waiting on a payment are never deleted, and runs are batched so large sites stay responsive. Set up Joomla's Scheduled Tasks (cron) for it to run; the form settings show a reminder if the task isn't scheduled.
  • Fixed deleting multiple submissions at once. Bulk-deleting submissions, and deleting a form that has submissions, now removes every selected record instead of leaving most of them behind. If earlier deletions left stray records, a form re-delete now clears them.
  • Fixed false "Pro feature reverted" warnings on save. Saving a form in the Free edition no longer shows incorrect Pro-feature revert notices for the default notification email and confirmation email settings. Forms that don't use those Pro features now save cleanly.
  • Removed a harmless form-builder console error. Opening the form builder no longer logs a failed request for a stylesheet that wasn't part of the package. No visual change.

1.2.2 — 2026-06-04 ​

  • Classic appearance controls. Free forms can now use a per-form brand color and light, dark, or auto color mode without custom CSS.
  • Better builder preview. The form preview can be pinned beside the canvas and now reflects the form structure, layout, and submit button settings more accurately.
  • Safer Custom Text content. Safe formatting is preserved while unsafe markup is stripped before save, preview, and render.
  • Admin workflow polish. Forms and Submissions list filtering, sorting, per-page controls, Options shortcuts, field ordering, mobile dragging, and alias layout are more reliable.
  • Integration retry scheduled task support. The retry task installs and enables more consistently, with an admin notice when the task is not scheduled.
  • Security and anti-spam hardening. Browser submissions, login forms, CAPTCHA checks, rate limits, honeypot/time-trap handling, AJAX errors, and integration error logging were tightened.
  • Accessibility baseline pass. Improved autocomplete support, focus visibility, contrast, and error-to-field association.
  • General polish. Better CAPTCHA placement, form color-scheme handling, drawer organization, translations, plugin installation, and builder UI consistency.
  • Form theme presets. Added Material, Clean, Card, and Underline themes for Pro forms, with live preview picking, brand color support, and light/dark/auto mode.
  • Expanded Pro builder toolkit. Added Calculation, Dynamic Select, Divider, Heading, Rating, Three-column layout, Modal form trigger, Multi-File Upload, and additional Pro validation options.
  • Payments for forms. Added Stripe and PayPal payments, install-level provider credentials, payment-bound Price and Calculation amounts, payment return handling, and payment cleanup support.
  • Calculation-powered payments. Calculations can now provide the authoritative payment amount, with currency display, server-side re-evaluation, and admin warnings for unbounded numeric inputs.
  • Form API submissions. Pro forms can expose a per-form API key for trusted server-to-server submissions.
  • Twilio and submitter confirmation emails. Added SMS notifications and visitor-facing confirmation emails alongside the existing admin notification flow.
  • Import/export hardening. Pro fields, payment bindings, Dynamic Select sources, and sensitive validation settings now survive imports more safely and warn admins when follow-up is needed.
  • PDF, Save & Resume, and Pro plugin reliability. Improved PDF output, Save & Resume behavior, Pro plugin installation, scheduled task setup, payment-table upgrades, and deletion handling for paid submissions.

1.2.1 — 2026-05-09 ​

  • Cleaner field editor drawer. Informational hints are tucked behind help buttons, with tighter spacing across long configuration panels.
  • 13 new validation rules. Adds common field checks such as alpha, numeric, length, email, URL, IP address, phone, ZIP, and same-as matching, with custom messages.
  • Brevo integration. Send submissions to Brevo contact lists using the same queued integration flow as the other email-marketing integrations.
  • Submit button rendering option. Choose whether the submit control renders as a <button> or an <input>.
  • Localized country names. Country dropdowns follow the site language when the server supports localized region names.
  • Expanded file-upload categories. File Upload fields can accept audio, video, and archive formats with stronger server-side validation.
  • Placeholders in subject and success messages. Email subjects and success messages can use form and field placeholders.
  • Queued integration data encrypted at rest. Pending integration payloads are encrypted while waiting for retry.
  • AI Assistant builder workflow. Generate forms, review existing forms, and draft notification copy from the form builder.
  • AI Assistant reliability controls. Added multilingual output, reasoning/token controls, usage caps, test-connection throttling, clearer errors, and safer encrypted API-key handling.
  • Save & Resume. Visitors can save long forms and continue later from an emailed resume link.
  • PDF downloads. Admins can export individual submissions as branded PDF files.

1.2.0 — 2026-05-07 ​

  • Two new form templates. Membership Application (account-creation flow with admin approval queue) and GDPR Data Subject Request (standardised intake form for access, erasure, rectification, and portability requests).
  • Inline links in consent checkboxes work. Anchor tags in checkbox labels (e.g. I agree to the terms) now render as real links instead of escaped text.
  • Icons on the template picker. Each form-template card shows a small Tabler icon for quicker recognition.
  • Client Onboarding template. Added a Pro intake template for multi-step onboarding forms.
  • AI Assistant foundation. Added the Pro AI settings area with encrypted API-key storage, usage limits, risk acknowledgement, and connection testing.

1.1.0 — 2026-05-05 ​

Few security improvements that apply to everyone.

  • Slack notifications are now marked Deprecated. Still functional; future releases may remove the dedicated card. If you need Slack alerts, the General Webhook integration with Slack's Incoming Webhooks URL is the recommended replacement and gives you the same outcome.
  • Webhook URLs are redacted in the log file. Make, Zapier, and Slack URLs contain credentials in the path itself — they're not just identifiers. The component log no longer prints them in full when an integration fails. Hostname is still visible, plus a short hash so you can tell two failure lines apart.
  • Stricter URL validation when you save Make/Zapier/Slack. Saved URLs must be https:// and resolve to a known vendor host (hook.make.com, hooks.zapier.com, hooks.slack.com). URLs you've already saved aren't re-validated, so existing forms keep working unchanged.
  • Mobile-friendly form builder. The builder now actually works on a phone. Below ~768px the layout stacks to a single column, the field palette becomes a tap-to-open bottom sheet (via a floating "Add field" button), drag-and-drop is replaced with explicit ⬆/⬇ reorder buttons on each card, and the field-editor drawer slides up from the bottom of the screen instead of in from the right. On large desktop screens the builder also gets wider (up to 1640px on 1920+ displays, was capped at 1100px) so two-column forms have more breathing room.
  • Fixed an install failure on MySQL 8.0.45. Some sites couldn't install or upgrade past 1.0.32 with the error "This command is not supported in the prepared statement protocol yet" - and a follow-on "Duplicate column name 'alias'" if the schema row was left stale by the first failure. The component's schema-update files have been emptied so the installer runs cleanly across all supported MySQL versions; the schema migration itself now happens during the component install/update step in PHP, is fully idempotent, and tolerates already-applied state. The component now also auto-records its schema version in Joomla's tracker, so customers no longer need to click "Update structure" in Database Maintenance to resolve the warning before the next install will run.

The integration tier restructure release. Highlights for Pro customers:

  • HubSpot and Salesforce are now Pro-exclusive. Pro customers keep full edit access; Free installs that already had either configured see them preserved as read-only.
  • Make and Zapier on Pro: unlimited forms. No per-install cap on the Pro tier — every form can dispatch to Make and/or Zapier independently.
  • Custom-auth API keys for Make webhooks (new). Optionally attach an x-make-apikey header to outbound calls so you can expose your Make scenarios publicly behind custom-auth gates without anyone being able to forge submissions. Encrypted at rest, write-only from the UI (the stored key is never sent back to the browser), and removable by toggle on save. Only available on Pro. Note: the earlier release notes mentioned the same for Zapier — Zapier's Webhooks-by-Zapier doesn't have an equivalent receive-side convention, so we removed the field entirely; if you want to authenticate a Zap, do the check inside the Zap itself.
  • Submission preview now shows image thumbs and clickable file links. When previewing a submission with file uploads, image attachments render as thumbnails (click to open full size) and other files (PDF, DOC, XLS, CSV, etc.) render as clickable filenames. SVGs are linked rather than inlined as a security precaution.
  • Pro integrations are surfaced on the license screen. A new "Pro integrations in use" panel lists every form using Make, Zapier, HubSpot, or Salesforce, with edit links. Useful to audit at a glance.
  • Downgrade safety. If a Pro license lapses while a form has a stored API key on Make, the encrypted key and the URL both stay in place and continue dispatching authenticated calls — but the URL becomes locked at save time so a downgraded site can't redirect the still-decryptable key to a different endpoint. Re-license to edit.

1.0.33 — 2026-05-04 ​

  • Component log file is now its own thing. Component messages go to administrator/logs/com_nxpeasyforms.log.php instead of being mixed into Joomla's everything.php. Easier to tail and easier to grep when something goes wrong.
  • Log level setting improvements. Options → General → Log level. Setting it to Errors only silences integration-misconfiguration warnings; Warnings and above (the new default) surfaces them; Verbose debug opens up every detail if you're actively troubleshooting.
  • Less log noise. A single misconfigured integration now logs at most once per form submission instead of once per dispatch attempt. Messages are also tighter — less noise per line.
  • New default: Warnings and above. Misconfigurations are visible without needing to flip a switch first. Existing installs keep whatever log level they had set.

1.0.32 — 2026-05-04 ​

  • Faster, more resilient form submission. Slow third-party integrations no longer hold up the "thanks" response. Each integration gets a 3-second window; anything slower is queued for automatic retry with backoff. Several smaller speed-ups across listing pages, multi-shortcode articles, and the country/state field.
  • Email delivery has per-channel timeouts. API providers (SendGrid, Mailgun, Postmark, Brevo, SMTP2GO) cap at 3 seconds; SMTP relays at 10 seconds. A misbehaving mail server can no longer block the form submit for minutes.
  • Form data is preserved on uninstall. Removing the component no longer wipes your forms and submissions — both tables stay in your database, and re-installing on top picks up where you left off. To remove the data permanently, drop #__nxpeasyforms_forms and #__nxpeasyforms_submissions via phpMyAdmin or your database tool.
  • Single Form menu item now uses a proper picker. Browse-and-select modal replaces the manual ID text field.
  • Misconfigured integrations log a warning instead of failing silently. When an integration cannot run because of missing credentials or mapping, a warning now appears in the Joomla log naming the specific issue.
  • Mailchimp Audience picker keeps the saved selection. When you reopen a form, the dropdown auto-loads your audience list so the saved choice is visible immediately.
  • A small database index migration runs automatically on upgrade to speed up rate-limit checks.
  • Performance: Pro plugin manifest is parsed once per request instead of on every page load. Small but site-wide win — the Pro plugin participates in every Joomla bootstrap, so this trims a few milliseconds off every page on every Pro install.
  • Performance: conditional-visibility validation is faster on free-of-Pro-rules paths. When a form is submitted and the conditional logic resolver hasn't been registered (e.g. during API submissions), the validator no longer re-attempts component bootstrapping for every field. A 30-field form now boots once, not 30 times.

1.0.30 — 2026-04-30 ​

  • Reliability: Pro plugin updates install cleanly through Joomla's update manager regardless of how many times the package has been reinstalled. The plugin previously failed with "Could not open update site" or "Invalid extension update" depending on whether the broken state was caught at the discovery leg or the install leg of Joomla's update flow. The auth token is now injected only at the package-download leg (where Joomla does dispatch a plugin event); update-manifest fetches no longer require authentication. Requires the licensing server to run com_nxpeasydownload 1.5.3 or later (already deployed at nexusplugins.com). Supersedes 1.0.26 and 1.0.28, which attempted the same fix from different angles before we identified that Joomla's install-time manifest re-fetch bypasses plugin events entirely.

1.0.24 — 2026-04-30 ​

  • Security: licensed update checks and Pro package downloads no longer carry the raw license key in the URL. Activation now issues a per-install token that's used for every subsequent update check and download. The license key itself stays in encrypted local storage and only travels to the licensing server over HTTPS POST during activate / validate / deactivate. Requires the licensing server to run com_nxpeasydownload 1.5.0 or later (already deployed at nexusplugins.com).

1.0.16 — 2026-04-29 ​

  • Polish: form builder Save → the toolbar button now flips from "Cancel" to "Close" the moment a new form gets its first ID, no full reload needed.
  • Reliability: bundled content and webservices plugins are now enabled automatically when the package installs — no manual publish step.
  • Polish: license screen tidied — a redundant internal identifier that had no actionable meaning is no longer shown.
  • Reliability: the Pro system plugin is now activated automatically the moment the Pro package installs.

1.0.15 — 2026-04-19 ​

  • Submission count column on the Forms list, plus a small badge in the builder header showing how active each form is.
  • Free edition limits introduced: up to 3 active forms and 100 stored submissions per install. Forms continue to email and integrate beyond the limit; only database storage is capped.
  • Stability improvements across the builder.
  • Fixed: Mailchimp API key was being re-encrypted on every save.

First Pro release.

  • Two-column layout. Toggle two-column mode from the canvas header and set per-field width (full or half). Fields collapse to a single column on mobile.
  • Multi-step forms. Break long forms into steps with a progress indicator, Next/Previous navigation, and validation per step.
  • Conditional field visibility. Show or hide fields based on other answers. Eight comparison operators including equals, contains, greater_than, and is_empty. Hidden fields are also skipped on server-side validation.
  • Submission preview in admin. One-click preview from the Submissions list to see all values, files, and metadata without leaving the page.
  • License management. Built-in screen to activate, refresh, and deactivate your Pro license. Domain matching and renewal reminders included.
  • Unlimited forms. Removes the 3-form cap that applies to the free edition.

1.0.13 — 2026-03-13 ​

  • Add a CSS class to any visible field from the builder. Useful for theming individual fields without touching template overrides.

1.0.12 — 2026-03-12 ​

  • Four new field types: URL, Date & Time, Number, and Range.
  • Internal cleanup of the legacy frontend bundle.

1.0.11 — 2026-02-19 ​

  • Submissions list gained a search bar, form selector, and ordering controls.
  • New "Orphaned (deleted form)" filter to find and clean up submissions whose parent form is gone.
  • One-click publish/unpublish toggle in the Forms list.
  • Fixed: filter "Clear" button needed two clicks; export task lingered after download; toolbar layout cramped on wide screens.
  • Security: tighter webhook hostname validation; stricter cross-site origin checks for browser submissions.
  • Removed the non-functional "Submission status" column and filter.

1.0.10 — February 2026 ​

  • New site module mod_nxpeasyforms to render any active form in a module position.
  • Builder toolbar shows "Close" while editing an existing form and "Cancel" only for unsaved new forms.

1.0.9 — 2025-01-09 ​

  • Country and State field types with linked dropdowns.
  • 9 email delivery providers (SendGrid, Mailgun, Postmark, Brevo, Amazon SES, SMTP, and more).
  • Custom form aliases for SEF-friendly URLs.
  • Modal form selector for menu items.
  • Encrypted CAPTCHA secret storage.
  • Security hardening across uploads, CSRF, encryption keys, and SQL safety.
  • Fixed: frontend validation display, Joomla 5.4 file uploads, login menu SEF routing, and CAPTCHA loading.

1.0.0 — 2025-09-22 ​

Initial Joomla 5 release of NXP Easy Forms.

  • Vue.js 3 drag-and-drop form builder.
  • 15 pre-built form templates.
  • 12 field types (Text, Email, Telephone, Password, Textarea, Select, Radio, Checkbox, File Upload, Date Picker, Hidden, Custom Text).
  • {nxpeasyform id="…"} shortcode plugin for Joomla articles.
  • SEF routing with custom router.
  • Joomla Article integration with field mapping.
  • Built-in integrations for common marketing and automation workflows.
  • User registration forms with email verification.
  • Honeypot, CSRF, rate limiting, CAPTCHA providers; IP anonymisation and auto-deletion.