Descripción
Este plugin te permite insertar un «formulario seguro» en tu web a través de un shortcode. Está pensado para cuando necesitas recibir información sensible de cualquier tipo, estableciendo un «canal seguro».
Los datos enviados están cifrados con tu clave pública PGP.
Modo de uso
Solo completa algunas opciones del plugin:
- El correo electrónico de destino (tu correo electrónico)
- Tu clave pública PGP en versión blindada ASCII
Sugerencia: para ver tu clave privada, puedes ingresar a la consola de tu ordenador y ejecutar dos comandos, uno para listar y otro para exportar (debes tener GnuPG):
gpg --list-keys
gpg --armor --export username@email
Recuerda que tu clave pública debe exportarse en versión blindada ASCII, esto significa que estará rodeada con:
-----BEGIN PGP PUBLIC KEY BLOCK-----
your-long-key-string-will-be-here
-----END PGP PUBLIC KEY BLOCK-----
Una vez lo insertes en una página o entrada, el shortcode mostrará un formulario con los siguientes campos:
- Nombre
- Correo electrónico
- Asunto
- Mensaje
¿Cómo funciona?
El campo mensaje se cifrará con tu clave pública PGP y se enviará como archivo adjunto en ASCII al correo electrónico de destino que hayas configurado.
Al crear la lógica del plugin me he asegurado de que el campo mensaje nunca sea enviado al servidor, los datos son encriptados (al vuelo) usando la librería OpenPGP.js en el navegador del usuario que está visitando la web.
Solo podrás descifrar el contenido del archivo adjunto si tienes la clave privada PGP perteneciente a la clave pública con la que se ha cifrado el mensaje.
Recuerda que la función del plugin es solo mostrar un formulario en tu web y cifrar la información que se envía a través del campo «mensaje». Este plugin no se encarga de descifrar el archivo adjunto, esta tarea se deja a cada usuario de la manera que desee.
Algunos ejemplos de uso
- Recibir mensajes secretos
- Recibir contraseñas de clientes o amigos
- Recibir información sensible
- Offering a private channel to sources, whistleblowers or people asking for help
Why private communication matters
Some messages cannot travel through an ordinary contact form. A source writing to a journalist, an employee reporting wrongdoing inside their own company, a lawyer receiving documents from a client, someone asking for help where asking is itself dangerous: for all of them, whether the channel is private is not a detail, it is the entire point.
A normal contact form sends the message in plain text to the web server, where it is kept in the database, in mail logs and in whatever backups the hosting provider takes. Every one of those copies is a place where it can be read, demanded or leaked. This plugin encrypts the message in the visitor’s browser, so what reaches the server is already unreadable to everyone, including you until you decrypt it with your private key, and including your hosting provider.
The Universal Declaration of Human Rights protects both freedom of expression and privacy of correspondence, and the two hold each other up: people only speak freely when they can choose who is listening. Giving your readers a channel that does not betray them is a small, practical way of defending that.
What this plugin does not do
Encrypting the message is one piece of a larger picture, and it is only honest to say where the picture ends.
- The name, email and subject fields are not encrypted. Only the message is. Anyone who can read your server can see who wrote and what the subject was.
- The plugin does not hide the fact that someone visited your website.
- It cannot protect a message once you have decrypted it on your own computer.
If someone’s safety depends on this channel, the way they reach your site and the way you store what you receive matter just as much as the encryption itself.
Requisitos
Your site must be served over HTTPS. The message is encrypted by the visitor’s browser, and browsers only allow encryption on secure connections. On a plain HTTP site no message can be sent at all. If your site is not on HTTPS yet, ask your hosting provider for an SSL certificate, they are usually free.
Para utilizar este plugin, debes tener o crear un par de claves PGP. Si no has generado tu par de claves, puedes buscar en Internet cómo generarlas.↵
Hay muchas formas de generar las claves, cada una tiene un impacto diferente en seguridad.
Software recomendado
Soporte
Cuando no puedas encontrar la respuesta a tu pregunta en la sección de preguntas frecuentes, consulta el foro de soporte en WordPress.org. Si no puedes encontrar ningún tema que resuelva su problema en particular, publica un nuevo tema.
Recuerda que el soporte se ofrece de forma gratuita y puede tardar algunas horas/días en responder y resolver tus problemas.
Supporting the plugin
This plugin is free and stays free. It is maintained in the time left over from paid work, which is the honest reason why some things take a while.
If your organisation needs something it does not do yet, a custom field, an integration with your own systems, or a hand setting up your key pair and the form, that work can be commissioned at charrua.es. Paying for a feature is what funds the hours behind the plugin, and whenever a change makes sense for everyone it goes into the free version too, so the work ends up in the hands of people who could never have paid for it.
That is the arrangement we like: those who can afford it pay for the tools that everyone else gets to use.
Spam protection (optional)
The plugin can add a Cloudflare Turnstile challenge to the form. It is disabled by default and does nothing until you enable it and enter your site key and secret key in the plugin settings.
The message is always encrypted in your visitor’s browser before anything is sent, with or without Turnstile.
If Cloudflare cannot be reached, submissions are allowed through and the problem is written to the diagnostic log, so an outage never costs you a legitimate message.
Aviso de privacidad
Con la configuración por defecto, este plugin, por si mismo:
- Rastrear usuarios de modo encubierto
- No escribe ningún dato personal del usuario en la base de datos
- No envía ningún dato a servidores externos
- No utiliza cookies
External services
This plugin does not connect to any external service unless you enable Cloudflare Turnstile in its settings.
When you do enable it, the plugin relies on Cloudflare Turnstile to tell human visitors apart from bots:
- The form loads the Turnstile widget script from
https://challenges.cloudflare.com/turnstile/v0/api.js. Loading it makes the visitor’s browser contact Cloudflare, which collects the data described in their documentation to run the challenge. - When the form is submitted, your server sends the token produced by the widget, together with your secret key, to
https://challenges.cloudflare.com/turnstile/v0/siteverifyto check whether the challenge was passed. - The plugin never sends the message, the form fields or the visitor’s IP address to Cloudflare.
Cloudflare’s terms of service and privacy policy apply to that service.
Traducciones
Actualmente el plugin está disponible en ingles y traducido al español.
Puedes contribuir y traducir este plugin a tu propio idioma.
Capturas






Instalación
- Sube la carpeta completa
secure-encrypted-formal directorio/wp-content/plugins/. - Activa el plugin a través de la pantalla de Plugins (Plugins > Plugins instalados).
You will find Secure Encrypted Form menu in your WordPress admin screen. Once configured, insert the form in any page or post using the shortcode [secure-encrypted-form].
FAQ
-
¿Cómo prevenir y filtrar el SPAM?
-
The plugin has built in support for Cloudflare Turnstile. Create a free Turnstile site in your Cloudflare dashboard, then enable it in the plugin settings and paste the site key and the secret key. It is off by default.
-
The Turnstile widget does not appear, and the form says the spam check could not be completed
-
This is almost always a caching or optimisation plugin combining, minifying or deferring the Cloudflare script. Turnstile needs its own script tag to start, so when it is merged into a bundle the widget never renders, no token is produced, and the form rejects the submission. The browser console usually shows «Could not find Turnstile valid script tag».
The plugin already asks SiteGround Speed Optimizer, LiteSpeed Cache, WP Rocket and Autoptimize to leave that script alone, and marks it in the page so other optimisers skip it too. If yours does not honour that, exclude this script by hand:
https://challenges.cloudflare.com/turnstile/v0/api.jsIt is registered under the handle
cloudflare-turnstile, which is what some plugins ask for instead of the URL. Exclude it from combining, from minifying and from deferring, then clear every cache. -
I get an error about my encryption key, but the key is fine
-
Check that your site is served over HTTPS. Browsers only give access to the encryption API on secure connections, so on an HTTP site the form cannot encrypt anything. From version 1.3.0 the plugin tells you this directly, both in the admin and in the form.
-
Mi servidor no envía correos electrónicos
-
Tu servidor puede estar restringido o desactivado para enviar correos electrónicos. En ese caso, puedes usar un plugin SMTP para enviar correos electrónicos autenticados como WP Mail SMTP.
Reseñas
Colaboradores y desarrolladores
«Secure Encrypted Form» es un software de código abierto. Las siguientes personas han colaborado con este plugin.
Colaboradores«Secure Encrypted Form» está traducido en 2 idiomas. Gracias a los traductores por sus contribuciones.
Traduce «Secure Encrypted Form» a tu idioma.
¿Interesado en el desarrollo?
Revisa el código , echa un vistazo al repositorio SVN o suscríbete al registro de desarrollo por RSS.
Registro de cambios
1.3.0
- Added a note on how to support the plugin: commissioning custom work is what funds it, and changes that make sense for everyone land in the free version.
- Rewrote parts of the plugin description: why a private channel matters, and an honest list of what the plugin does not protect.
- Removed the donation panel, links and email footer. The donation page no longer exists.
- The Cloudflare Turnstile script is now excluded from the optimisations of SiteGround Speed Optimizer, LiteSpeed Cache, WP Rocket and Autoptimize, and marked so other optimisers skip it. Combining or deferring that script stops the widget from appearing and makes the form reject every submission.
- Added a «Delete all log files» button to the Debug log screen. Useful if you are upgrading from a version before 1.2.0, whose logs recorded the email addresses and subject of every message.
- The plugin now warns you when your site is not served over HTTPS. Browsers only allow encryption on secure connections, so on an HTTP site no message can be sent, and until now the only symptom was an error blaming your encryption key.
- The test email form now shows the underlying error instead of always reporting a problem with the public key.
- Added optional spam protection with Cloudflare Turnstile, sponsored by @ericbonetti2017. It is disabled by default and needs both the site key and the secret key to switch on, so nothing changes unless you enable it.
- If Cloudflare cannot be reached, or your secret key is wrong, messages are allowed through and the problem is written to the diagnostic log. A Cloudflare outage never costs you a legitimate message.
- Your visitors’ IP addresses are never sent to Cloudflare.
1.2.0
- Security: log files are no longer written to a predictable, publicly reachable path inside the uploads folder. The log directory now carries a random suffix and ships with server rules that block direct web access. Existing logs are moved to the protected location automatically. Reported by @rayeason.
- Security: the diagnostic log no longer records the sender email address or the message subject.
- Security: hardened the log viewer so it can only open the plugin’s own log files.
- Added a «Diagnostic log» setting with three levels: disabled, errors only (the default) and full log. The log folder is only created when there is something to write.
- Logging is now handled by a single shared class instead of duplicated code in the admin and public sides.
- Security: the test email form is now restricted to administrators. Its endpoint was also registered for logged out visitors and shared a nonce with the public form, so anyone could trigger test emails.
- Fixed the form hanging on the spinner with no message when the encryption key has expired. An expired key fails when encrypting, not when it is read, and that case had no feedback.
- Fixed an unexpected mail error leaving the form without an answer: the visitor got no feedback and nothing was written to the log. Any failure is now reported and logged.
- Uninstalling the plugin now deletes its log files.
- Updated Monolog from 2.8.0 to 2.11.1, which removes the deprecation notices shown on PHP 8.4 and newer.
- Updated «Tested up to» to WordPress 7.1.
- Fixed the version number declared when enqueuing OpenPGP.js (it still said 5.5.0 while the bundled library is 6.3.0), so browsers pick up the right cached file.
1.1.0
- Updated OpenPGP.js from v5.5.0 to v6.3.0.
- Fixed silent encryption error when key is expired or invalid — now shows feedback to the user.
- Improved form field order: name, email, subject, message.
- Improved default form styling.
- Renamed admin submenu item to «Settings».
- Updated «Tested up to» to WordPress 7.0.
- Added «Requires PHP: 7.4».
1.0.1
- Enlaces a donaciones corregidos.
- Añadidos enlaces al registro de depuración en el área de administrador.
- Añadidos parámetros «para» y «de» en registros de depuración.
- Añadida la detección de la función mail() de PHP.
- Actualizados los mensajes de ayuda.
- Corregida la inicialización de las opciones del plugin, gracias a @nilovelez por comentar el problema.
- Corregidos los espacios iniciales en los campos de opciones.
- Añadido ícono de estado de carga.
1.0.0
- Lanzamiento inicial.
