Sichere Whistleblowing-Lösung WordPress-Plugin für Ihre Website

Documentation

All Whistleblowing System features explained in detail

Whistleblowing System Documentation: How do I get started?

Thank you for purchasing the PRO version or installing the Free version of the Whistleblowing System plugin. Before getting started, we recommend reading this documentation. It covers the most important features and settings you need to configure and use the plugin.

If you cannot find the information you are looking for, please contact us at support@whistleblowing-form.de.

PRO

Go to your account dashboard and download the Whistleblowing System plugin.

Whistleblowing System - WordPress-Plugin für Ihre Website - Installation
  1. In your WordPress Dashboard, go to Plugins → Add New.
  2. Click Upload Plugin at the top of the page.
  3. Select the previously downloaded ZIP file and click Install Now.
  4. Once the installation is complete, click Activate Plugin to start using the plugin.

FREE

The Free version can be installed directly from the WordPress Dashboard.

  1. Open your WordPress Dashboard and go to Plugins → Add New.
  2. Enter a search term such as “Whistleblowing” or “Whistleblower” in the plugin search field.
  3. Find the Whistleblowing System plugin in the search results and click Install Now.
  4. WordPress will automatically install the plugin.
  5. Once the installation is complete, click Activate to start using the plugin.

Form Overview

Under Whistleblower → All Forms, you will find an overview of all forms that have been created. From here, you can manage existing forms, view the number of received submissions and create new forms.

The overview contains the following information:

  • Name: The name of the form.
  • Submissions: The number of submissions received through the respective form. Click the number to open the corresponding submissions.
  • Shortcode: The individual shortcode used to embed the form on a WordPress page or post.
  • Date: The date and time when the form was created.
  • Type: Indicates whether the form is a Whistleblowing Form or a Standard Form.
Form Overview

Managing Forms

When you move the mouse pointer over the name of a form, the available actions are displayed:

  • Edit: Opens the form for editing.
  • Duplicate: Creates a copy of the form, including its fields and settings. Existing submissions are not copied.
  • Delete: Deletes the form, including all associated submissions and related data.
  • Preview: Opens a preview of the form.

Click Add New to create a new form.

Important: Deleting a form permanently deletes all associated submissions, chats, attachments and logs.

Form Overview

Form Fields

In the Fields section, you can add, edit and arrange the fields of a form and configure individual field settings. Conditional logic can also be used to create dependencies between individual form fields.

This makes it possible to create both simple forms and complex dynamic forms in which specific fields are shown or hidden depending on previous user input.

Adding Form Fields

The Add Fields section provides various field types that can be added to the form.

Form Edit

Clicking the desired field type adds the field to the end of the form.

The field order is not fixed. Once added, fields can be moved to any desired position within the form using drag and drop.

Editing Form Fields

Existing form fields can be customized at any time.

When you hover over a field, the corresponding Edit and Delete icons appear.

Clicking the Edit icon opens the settings for the selected field under Field Options on the left-hand side.

Form Edit

The available settings depend on the selected field type. This ensures that only options relevant to that particular field are displayed.

Depending on the field type, the available settings may include:

  • Field label (Label)
  • Description or additional information (Description)
  • Selection options (Choices)
  • Adding, editing and deleting individual choices
  • Setting the field as required (Required)
  • Additional field-specific settings

For example, a Single Choice field provides settings for its individual choices, while other field types provide their own corresponding options.

Deleting a Form Field

A field that is no longer required can be removed using the trash icon.

Before the field is deleted, a confirmation prompt is displayed to prevent accidental deletion.

Conditional Logic

With Conditional Fields, form fields can automatically be shown or hidden depending on the values entered or selected in other fields.

This makes it possible to create dynamic forms that only display questions and input fields that are relevant based on the user’s previous answers.

Open the desired form field and navigate to Conditional Fields under Field Options.

Form Edit

For the selected field, you can first specify:

Show this field
The field is displayed only when the defined condition is met.

Hide this field
The field is hidden when the defined condition is met.

Next, select the form field on which the condition should depend. The available conditions and comparison options depend on the selected field type.

For example, conditional logic can be based on specific text entered in a text field or on a selection made in a Radio/Single Choice or Select/Dropdown field.

Use AND to add another condition within the same group.

This means that all conditions connected by AND must be met for the group’s rule to apply.

Use Add new group to create a new OR group.

The groups are connected using OR logic. This means that it is sufficient for one of the defined groups to match.

Form Edit

Header Texts

In the Headers section, you can define individual text content for different areas of the form and the case access interface. Header texts can be configured separately for each form and enabled or disabled as required.

A TinyMCE editor is available for formatting the content. TinyMCE can also be enabled or disabled in the plugin’s global settings.

Form Header

The Form Header is displayed in the frontend above the actual form.

Use Show header to enable or disable the header for the respective form. The desired content can be entered under Header text and formatted using the editor.

This area can be used for introductory information or instructions that users should read before completing the form.

Form Header

Token Header

The Token Header is displayed in the frontend after a report has been submitted. It appears in the token section above the field used to display or copy the generated token.

Important information about the token can be provided here, for example, reminding the user to store the token securely because it is required to access the report later.

The header can also be enabled or disabled using Show header, and its content can be customized under Header text.

Form Header

Login Header

The Login Header appears in the frontend above the token input field on the login page or within the login area.

This section can be used to provide instructions about logging in or using the previously generated token.

The Login Header can also be enabled or disabled using Show header and customized using the editor.

Form Header

TinyMCE Editor

The TinyMCE editor is available for editing header texts. It allows content to be formatted using paragraphs, text formatting, lists, links and other common formatting options.

The TinyMCE editor can be enabled or disabled under Settings → Advanced in the global plugin settings.

Email Settings

The email settings determine whether automatic notifications are sent after a form is submitted and who receives them. Recipients, sender details, subject lines and email content can be configured individually and combined with dynamic values from the form.

Enable Email Notifications

The Send Notification Email option enables or disables email notifications for the respective form.

If this option is disabled, no notification emails will be sent for the form.

Form Email Settings

Email to Administrator

Under Email to Administrator, you can configure notifications for administrators or other responsible recipients.

Define Recipients

Under Email to send submissions to, enter the email addresses that should receive notifications about new submissions.

Multiple fixed email addresses can be entered separated by commas.

Form fields can also be used as dynamic values. For example, if a selection field contains an email address as its stored value, that address can automatically be used as a recipient depending on the user’s selection.

This allows reports to be routed automatically to different people, departments or responsible teams.

Exclude Recipients

The Exclude Email Recipients option can be used to dynamically exclude specific recipients from email notifications.

This can be useful, for example, when a form contains several company departments and a complaint concerns the department selected by the whistleblower. The email address associated with that department can then automatically be excluded from the notification.

Alternatively, Email to send submissions to can be configured so that only the selected department receives the report and other departments are not unnecessarily notified.

Important: If the same email address is included under both Email to send submissions to and Exclude Email Recipients, the exclusion takes priority. No email will be sent to that address.

Sender Email Address

The sender email address is configured under Email From.

We recommend using an email address that belongs to the same domain as your website. This can help prevent email deliverability issues.

If a different sender address is required, the necessary mail server, hosting, SPF/DMARC or other technical configuration should be coordinated with your hosting provider or IT department.

Sender Name

Under From Name, you can enter a fixed sender name or use a form field as a dynamic value.

If the field is left empty, the plugin automatically uses: Whistleblower

Subject

Under Subject, you can enter a custom email subject or use a form field as a dynamic value.

If the field is left empty, the plugin automatically uses: Whistleblower new message

Administrator Email Content

Under Custom Text in Email for Administrator, the content of the notification email can be customized.

Available form fields are displayed above the editor and can be inserted directly into the email content. System information such as Form Title, Form ID, Submission ID and Admin Token is also available.

Use All to include all available form information in the email.

Form Email Settings

Email to User

Under Email to User, you can specify whether the person submitting the form should also receive an automatic email.

Email notifications to the user can be enabled or disabled.

The plugin automatically uses the email address entered by the user in the form’s Email field as the recipient.

If the form does not contain an appropriate Email field, the plugin cannot determine a recipient address for the user email.

The sender address, sender name, subject and content of this email can also be configured individually.

Form fields can be used as dynamic values and inserted directly into the email content.

The User Token is also available. This makes it possible, for example, to send the user’s personal access token together with additional information directly by email.

Form Email Settings

Dynamic Form Values in Emails

Form values can be used dynamically in different areas of the email settings.

Depending on the configuration, this allows you to:

  • automatically determine recipients based on a form selection,
  • exclude specific recipients from email notifications,
  • dynamically use form values as the sender name,
  • use form values in the email subject, and
  • automatically insert submitted information into the email content.

This allows email notifications to be flexibly controlled based on the information submitted through the form.

Display Options

Under Display Options, you can define how the respective form is displayed in the frontend and which texts and content are shown to users. These settings apply only to the form currently being edited and can therefore be configured individually for each form.

Button Texts

The labels of the main buttons in the Whistleblowing Form can be customized. This allows the button labels to be adapted to the language and purpose of each form.

The following button texts can be changed:

  • New case button text – Button used to create a new report.
  • Follow up case button text – Button used to access and follow up on an existing report.
  • Login button text – Button used to log in with the personal token.
  • Reply button text – Button used to send a new message within the chat.

Changes made here apply only to the form currently being edited.

Form Display options

Active Form Design

Under Active form design, a previously created design can be assigned to the form.

Each form can use its own design. This makes it possible to display different forms with different colors, spacing, button styles and other visual settings.

If the selected design is later modified under Designs, the changes are automatically applied to all forms using that design.

Creating and editing designs is described in more detail in the Designs section of this documentation.

Form Display options

Messages After Submission

Under Submit messages, you can customize the system messages displayed after a form has been submitted.

Success message text

This message is displayed when the form has been successfully submitted.

Success message text about token copy for whistleblowing form

For Whistleblowing Forms, a personal token is generated after a successful submission. This text can be used to remind the user to copy and securely store the token. The token is required to access the report later and continue communicating about the case.

This setting applies only to Whistleblowing Forms.

Error message text

This message is displayed when the form could not be submitted successfully.

All texts can be customized individually for the respective form.

Form Display options

Advanced Display Options

The Advanced section contains additional options that control the behavior of the Whistleblowing Form after a report has been submitted.

Show anonymous form after submit

This option determines whether the form remains visible after a successful submission.

When enabled, the form remains visible after submission.

When disabled, the form is hidden after a successful submission. The success message and the section containing the generated token remain visible.

This can be useful for drawing more attention to the generated token and preventing the user from immediately seeing the same form again after submitting it.

Show first message and attachments in chat

This setting determines whether the submitter can continue to access the original report and its associated attachments through the chat after submission.

When enabled, the initial submitted message and its attachments remain accessible to the submitter in the chat.

When disabled, the original message and its attachments are no longer accessible to the submitter through the subsequent chat. Further communication about the case remains possible through the chat function.

Changing this setting later does not affect existing reports retroactively.

Form Display options

Form Settings

The Settings section contains technical settings for the respective form. Here you can configure file uploads for the chat and set up incoming and outgoing webhooks for communication with external systems.

These settings apply to the form currently being edited.

Upload Settings

The upload settings determine whether files can be uploaded within the chat and define the applicable upload restrictions.

These settings apply exclusively to the file upload function within the chat. They do not control an upload field within the actual reporting form.

Enable Uploads

Use Enable upload to enable or disable file uploads within the chat.

When enabled, both users and administrators can upload files as part of the communication related to a report.

Allowed File Types

Under Allowed file types, you can define which file formats may be uploaded in the chat.

Multiple file types can be allowed. The specified file types apply both to uploads by users in the frontend and to uploads by administrators in the WordPress backend.

Maximum File Size

Under File maximum size, you can specify the maximum allowed size of an individual uploaded file in MB.

This limit applies to both users and administrators.

Encrypt Uploaded Files

The Encrypt uploaded files option allows uploaded files to be stored on the server in encrypted form.

When enabled, files are not stored in plaintext. Encryption is performed server-side using AES-256-CBC. A SHA-256 hash is also used to verify file integrity during decryption.

When an authorized user accesses the file, it is decrypted server-side and then made available.

Form Settings

Incoming Webhook

The Incoming Webhook allows external applications to send data to the Whistleblowing System. This can be used, for example, to create new reports from an external system or update existing cases.

Each form provides its own Endpoint URL to which the external system can send data.

Enable Incoming Webhook

Use Enable Incoming Webhook to enable the incoming webhook for the current form.

Once enabled, the displayed Endpoint URL can be used by an external system to send data to this form.

Authentication

The following authentication methods are available for accessing the endpoint:

  • None
  • Bearer Token
  • API Key in Header
  • API Key in Query

For production environments, using a Bearer Token is recommended.

Use Generate to generate the corresponding secret key or token.

Webhook Mode

The Webhook Mode determines how incoming data is processed.

Create new case

The submitted data creates a new report. The submission is created in the Whistleblowing System in the same way as a regular report, and the required tokens are generated.

Update existing case

The submitted data is assigned to an existing case and updates that case. The corresponding case must be identifiable.

Auto-detect

The system automatically determines how to process the request based on the submitted data:

  • If a case_id is provided, the existing case is updated.
  • If no case_id is provided, a new case is created.

Expected JSON Data

The system provides examples of the expected JSON structure directly within the settings.

Expected New Case JSON shows which data can be submitted when creating a new report.

Expected Case reply JSON shows the expected structure for communication with an existing case.

The example values shown must be replaced with the actual data from the external system when sending a real request.

Advanced Field Mapping

Advanced Field Mapping allows JSON keys from an external system to be mapped to the corresponding fields in the Whistleblowing System form.

This is particularly useful when the external system uses different field names.

For example, an external JSON key such as department can be mapped to the corresponding department field in the form. This means that the existing data structure of the external system does not need to be changed to match the plugin’s internal field names.

Return Login Tokens

Under Additional Actions, you can specify whether additional tokens should be returned in the response after the request has been processed.

Return admin login token

Returns the administrator token generated for the corresponding case to the external system.

Return user login token

Returns the case’s user token to the external system. This token can subsequently be used to access and continue communicating about the report.

Because these tokens provide access to the case, these options should only be used when the receiving system and the data transmission are appropriately secured.

Form Settings

Outgoing Webhook

The Outgoing Webhook can automatically send data from the Whistleblowing System to external applications.

This allows the plugin to be connected to internal systems, case management solutions or custom integrations.

Trigger Events

You can define which events trigger the webhook:

New Case Created – Triggered when a new report is created.

New Reply from User – Triggered when a user sends a new message regarding an existing case.

New Reply from Admin – Triggered when an administrator sends a new message.

Multiple trigger events can be enabled at the same time.

Webhook URL and HTTP Method

Under Webhook URL, enter the URL of the external endpoint to which the data should be sent.

The required HTTP method can also be selected. The webhook is therefore not limited to POST requests.

Authentication

Different authentication methods are available for connecting to the external endpoint:

  • None
  • Bearer Token
  • API Key in Query
  • API Key in Header

Additional HTTP headers can be defined under Custom Headers.

The required authentication method depends on the API or external system receiving the webhook data.

Webhook Body

The webhook payload can be configured individually.

Four sections are available:

Global

Contains data that is sent with every triggered webhook.

New Case

Contains additional data for the New Case Created event.

User Reply

Contains additional data when a user sends a new reply.

Admin Reply

Contains additional data when an administrator sends a new reply.

Global values are always combined with the values configured for the respective event.

For example:

Global + New Case

Global + User Reply

Global + Admin Reply

Available Values

Values for the webhook body can be selected from two groups:

Form fields

This section contains the fields available in the respective form, for example:

  • Single Line Text
  • Dropdown
  • Single Choice
  • Email

The fields displayed depend on the structure of the respective form.

Others

Additional system-related values are available, including:

  • Site URL
  • Form name
  • Form ID
  • Case ID
  • Event type
  • Reply message
  • User token
  • Admin token

This makes it possible to send both form data submitted by the user and technical information about the form and the respective case to the external system.

API Key / JSON Key

An API or JSON key is defined for each value to be transmitted. One of the available values from Form fields or Others is then assigned to this key.

This determines the key under which the corresponding information is transmitted to the external system in the webhook payload.

For example, the Case ID can be transmitted under a specific JSON key, while another key contains the value of a particular form field.

Webhook Body Encryption

Optional AES-256 encryption can be enabled for outgoing webhooks.

When encryption is enabled, the webhook body is encrypted before transmission. The receiving system requires the corresponding secret key to decrypt the transmitted data.

The encryption settings must therefore be coordinated with the technical implementation of the receiving system.

Failed Webhooks

Currently, failed Outgoing Webhooks are not recorded in the plugin’s Logs section.

Form Settings

Managing Submissions

All reports received through your forms can be centrally managed under Submissions. The overview displays all forms for which submissions can be stored.

For each form, the form name, number of received submissions and form type are displayed. The system distinguishes between Whistleblowing Forms and Standard Forms.

Click View to open the submissions for the respective form.

Submissions Settings

Submissions Overview

After opening a form, its submissions are displayed in a table. Submitted form values are shown as individual columns based on the fields used in the form.

From here, individual or multiple submissions can be managed, their status can be changed, the chat can be opened and the access credentials for a case can be viewed.

Submissions Settings

Managing Multiple Submissions

Bulk Actions can be used to manage multiple submissions at the same time. Select the desired submissions using the checkboxes and then choose one of the available actions.

The following actions are available:

  • Delete – Delete the selected submissions
  • Activate – Set the selected submissions to Active
  • Block – Set the selected submissions to Blocked
  • Complete – Set the selected submissions to Completed

A confirmation prompt is displayed before submissions are permanently deleted. Deleting a submission removes the entire case and associated data, including chat messages, attachments and tokens.

Submission Status

Each case can have one of three statuses: Active, Completed or Blocked. The status can be changed directly from the submissions overview and can be updated again at any time.

Active indicates an active case. The whistleblower can see the current status in the frontend and can continue sending messages.

Completed indicates that the case has been closed by the company or the responsible case handler. The whistleblower can see that the case has been completed but can still send messages through the chat.

Blocked prevents further communication from the whistleblower. The case status remains visible to the user, but they can no longer send new messages.

Chat

Click the speech bubble icon for a submission to open the corresponding chat directly in the WordPress admin area.

Administrators can view the communication and existing attachments and reply directly to the whistleblower. They do not need to log in through the frontend using a token.

Case Access

Click the Access icon to view the access information for the respective case. The Admin Login Token can be displayed and copied.

This token can be used to access the corresponding case through the frontend without requiring access to the WordPress admin area.

By default, the User Token does not need to be displayed in this area. If you also want the whistleblower’s token to be visible, this can be enabled under Settings → Advanced in the global plugin settings.

Once enabled, the User Token can also be viewed in the Access section.

Exporting Submissions

Use Export CSV to export the submissions of a form as a CSV file.

Access Control

Access Control allows you to assign individual permissions to WordPress users. This makes it possible to define exactly which users can access specific forms and plugin features.

Permissions can be assigned to one or multiple forms and can be modified at any time. Users without an appropriate access rule cannot access the protected areas of the plugin.

Access Control

Select a User

Under User, select the WordPress user for whom you want to create an access rule. Any existing WordPress user can be selected. A specific WordPress user role is not required.

Access permissions are then controlled directly through the plugin’s Access Control settings.

Define Form Access

Under Forms, select the forms to which the permissions should apply. You can select a single form or multiple forms.

Selecting All forms applies the access rule to all forms, including forms that are created in the future.

This allows different employees or departments, for example, to access only the forms that are relevant to them.

Define Permissions

For each user, you can individually determine which functions they are allowed to use within the selected forms.

The following permissions are available:

  • View submissions – View submissions
  • Reply to submissions – Reply to submissions
  • Edit submissions – Edit submissions
  • Change submission status – Change the status of a submission
  • Export submissions – Export submissions
  • Delete submissions – Delete submissions
  • Create forms – Create new forms
  • Edit forms – Edit forms
  • Show logs – View logs
  • Delete logs – Delete logs
  • Export logs – Export logs
  • Manage themes – Access the Designs section and its settings

Form-specific permissions apply to the forms assigned to the respective access rule.

The Edit submissions function is described in a separate section.

Grant All Permissions

Use Allow all to grant all permissions available through Access Control at once. The rule applies to all forms.

This is useful when a user should have full access to all functions managed through Access Control.

Creating and Editing Forms

With the Create forms permission, a user can create new forms. A form created by that user can subsequently also be edited by them as long as their access permissions are not changed afterwards.

The Edit forms permission controls access to editing the assigned forms.

Access to Designs

The Manage themes permission gives the user access to the Designs page. From there, the user can view and modify the available design settings.

This allows access to form design settings to be granted independently of other plugin functions.

Multiple Access Rules for One User

Multiple access rules can be created for the same WordPress user. The permissions granted by these rules are combined.

This allows highly specific access configurations. For example, a user can be allowed to view and reply to submissions for one form while receiving additional permissions for another form.

This makes it possible to configure different permissions for individual forms on a per-user basis.

Managing Existing Access Rules

Existing rules are displayed under Current Rules. The user, assigned forms and granted permissions are shown at a glance.

Click Edit to modify an existing access rule. Click Delete to remove the corresponding rule.

Deleting an access rule removes only the assigned permissions. The WordPress user, forms and existing submissions remain unchanged.

Global Settings

The Settings section contains the plugin’s global settings. These settings apply to all forms and control central functions such as reCAPTCHA, license management, logging and general plugin options.

Any changes are applied to all forms after the settings are saved.

reCAPTCHA

The plugin supports Google reCAPTCHA v2 and v3 to protect forms against spam and automated submissions.

Global Settings Recaptcha

Configure reCAPTCHA

To use the desired reCAPTCHA version, enter the corresponding Site Key and Secret Key.

The following versions are supported:

  • reCAPTCHA v2
  • reCAPTCHA v3

Both a Site Key and a Secret Key are required for the selected version.

Set the Language

The reCAPTCHA Language field can be used to define the language of the reCAPTCHA widget.

Enter the corresponding language code, for example:

  • de
  • en
  • fr
  • es

If no language is specified, Google automatically uses the visitor’s language.

Scope

The reCAPTCHA configuration is global and is used for all forms.

License

License management is used to activate or deactivate the PRO version.

Global Settings License

Activate License

To activate the license, enter the license key you received into the license field and save the settings.

After successful activation, all PRO features become available.

Deactivate License

An active license can be deactivated at any time.

This is particularly useful if the license was initially activated on a development or staging site and later needs to be transferred to the live website.

Logs

The Logs section controls the automatic logging of important plugin activities.

Global Settings License

Enable Logging

Use Logs Active to enable or disable logging.

Only relevant actions related to case communication and management are recorded.

These include, for example:

  • New Case
  • Case Reply
  • Status Changed
  • Form Deleted
  • Submission Deleted
  • Incoming Webhook
  • Outgoing Webhook

Automatic Log Deletion

Under Auto-delete logs after, you can define after how many days older log entries should be automatically deleted.

A value of:

  • 0 = Logs are never automatically deleted.

All other values define the retention period in days.

Advanced Settings

The Advanced section contains additional global plugin settings.

Global Settings Advanced

TinyMCE Editor

Use TinyMCE Active to enable or disable the integrated editor.

When enabled, convenient formatting options are available in the corresponding areas.

When TinyMCE is disabled, standard text fields are displayed instead.

Display User Token

The User token visible option determines whether the User Token is additionally displayed under Submissions → Access.

By default, only the Admin Login Token is displayed there.

This option affects only the display within the WordPress admin area.

Token Length

Under Token Length, you can define the length of newly generated login tokens.

The token length can be set between 6 and 64 characters.

Longer tokens provide greater security and make tokens more difficult to guess.

Changes apply only to newly created cases. Existing tokens remain unchanged.

Designs

The Designs section allows you to create and manage custom design templates for your forms. You can create any number of designs and assign them to the desired forms.

Click Add New to create a new design template. Existing designs can be edited or deleted. The Default column determines which design is automatically assigned to newly created forms. Regardless of the default setting, a different existing design can be selected individually for each form.

The same design can be used by multiple forms at the same time. Changes made to a design template are automatically applied to all forms using that design.

Theme Design Settings

Editing a Design

When editing a design template, you can first assign an individual Theme Title. This is used as an internal name and makes it easier to manage multiple designs, for example, “Corporate Black” or “Corporate Blue”.

The design options are divided into several sections: General, Form fields, Start Buttons, Chat styles, Login styles and Pagination styles. Each section contains settings for the corresponding part of the form.

Under General, you can configure the basic settings for the popup and form container. These include the container height and width, background colors, borders, spacing and overlay appearance.

Layout Background Color defines the background color of the overlay behind the opened popup. Layout Background Color Opacity controls its transparency. Colors can be specified using hexadecimal color values.

For Margin and Padding, standard CSS values such as 20px, 10px 20px or auto can be used.

The General section also includes an area for custom CSS. CSS entered here applies only to the respective design template.

Theme Design Settings

Design changes can be checked directly using the form preview. The design template must be saved for changes to be applied permanently.

If a saved design change is not immediately visible, clear your browser cache and reload the page.

In the Free version, only the default design is available. Creating and managing custom designs is a PRO feature.

Logs

The Logs section centrally records relevant activities within the Whistleblowing System. This makes it possible to track plugin activity and filter or export log entries when required.

Logged activities include creating new cases, replies within a case, status changes, deletion of forms or submissions, and incoming and outgoing webhook activity.

Each log entry contains information such as the date, form, Submission ID, action type, status, a short description of the performed action and the user who initiated it. The logs do not contain sensitive content from submitted reports.

Logs View

Exporting Logs

Use Export XLS to export log entries.

If specific entries are selected using the checkboxes, only the selected entries are exported. If no entries are selected, all log entries are exported.

The Logs feature is available in both the Free and PRO versions of the plugin.

Filtering Logs

Log entries can be filtered using several criteria.

Under Form, you can select a specific form. The Status filter allows you to choose between All, Success and Error. The Type filter can be used to filter entries by the logged action.

Under Created by, log entries can also be filtered by WordPress user or by the corresponding source that triggered the action. This makes it possible to determine who or what performed a specific action.

Use Reset Filters to clear the currently applied filters.

Deleting Log Entries

Individual or multiple log entries can be selected using the checkboxes and manually deleted using Delete selected.

Under Global Settings → Logs, you can also specify after how many days log entries should be automatically deleted. Setting the value to 0 disables automatic deletion.

Logging itself can be completely disabled in the global settings. In this case, no new log entries are created. Existing log entries remain unchanged.