FAQ
Does it need any other plugin?
Only Gravity Forms. The Email attachments box is the plugin's own, so no field plugin or theme feature is involved.
Can anyone download a private file?
Nobody is given an address for one. The file sits in a folder with a long random name. The plugin never prints that name on a screen, in its log, in an entry note or in an email. Nothing links to it, so a visitor or a search engine has nothing to follow, and the name is too long to guess. The protection is that the address is unknown. A server rule is not involved, so it works the same on every host. If someone did learn a file's full address, the file would download, which is why the plugin never discloses one. Signed-in users who can upload files open private files with View, which goes through the plugin. An emailed copy belongs to its recipient, like any attachment. Gravity Forms logging, when it is on, writes each email's attachment list to its log. A private file appears there as a placeholder under its real name. The plugin puts the address back only at the last step, inside WordPress's own mail function, so it never reaches Gravity Forms' log. See Private files.
What name does a private file arrive under?
Its own name. The file is stored under the name you uploaded, made safe for a server. Spaces become dashes and accents are dropped, so "Price list.pdf" is stored as "Price-list.pdf". On WordPress 6.2 and later, WordPress's own mail sends the exact name you see in the list. Older WordPress, and some mail plugins such as Post SMTP, send the stored name instead, so the recipient may see the dashes. Either way it is the file's own name, never a random one. See Private files.
Can a mail plugin log where a private file is stored?
Yes. The plugin hands the file's location to WordPress's mail function at the last step, and the mail plugin needs it there to attach the file. Post SMTP, with its log level set to debug, writes the full path of each attachment to the PHP error log. That log belongs to your server, outside this plugin. Other mail plugins may do the same. Keep mail debug logging off on a live site, and keep the server's error log private. See Private files.
What happens to private files when I delete the plugin?
They are deleted with it, unless you turn off "Delete private files when the plugin is uninstalled" on the plugin's tab under Forms, Settings. Without the plugin nobody can open or even name these files, so keeping them only makes sense if you plan to install it again. Keep your own copies of the originals.
Where do the files from the page come from?
From the Email attachments box on the page the form was sent from. Gravity Forms saves that page on every entry, on the server, when the form is sent. The form has to be on the page itself. An archive or a preview has no page, so a notification that needs one is held back with source_missing. A form in a popup counts as sent from the page the popup opens on.
Can a page send more than one file?
Yes. Add as many files as you like to a page's Email attachments box. They are sent in the order listed, and a notification is held back if any one of them cannot be prepared.
Which file types can I attach?
Any type your Media Library accepts. The plugin does not change what can be uploaded. Mail providers have their own rules, so test a new type with your provider.
Is there a size limit?
One email never carries more than 25 MiB of files, counted over every file before encoding. That includes files visitors upload and files other plugins attach. Encoding adds about a third to the size, and many mail providers accept less, so keep attachments well under it. There is no setting for it. A developer can change it with the dagf_max_total_bytes filter.
Can a visitor get a file they should not have?
Only published pages without a password, of the types you tick, can give files, and only the files in their Email attachments box are read. A visitor can still send a form from any published page, so the files of any such page can reach them. Anything you attach to a public form can reach anyone who fills it in, and an emailed copy cannot be recalled. Only attach files you are happy to send.
Does it work with Prevent Direct Access?
Yes. Media Library files are found by their attachment ID and their current location on the server, so a protected file is attached in the same way as any other. Private files need no protection plugin. Protecting a file's web address does not make an emailed copy private.
What happens if I deactivate the plugin?
While it is inactive it cannot hold a notification back, so Gravity Forms sends notifications without these files. Turn the affected notifications off or change them first. The settings stay on each notification, each page keeps its chosen files, and the private files stay in their folder. They do nothing until the plugin is active again.
What happens to my settings when I import a form on another site?
The settings remember the site they were saved on. On a different site the notification is held back until you open it, check each file, and save it there. Attachment IDs differ between sites, so this stops the wrong file being sent.
Does the plugin send anything to an outside service?
Not your forms, entries or files. Attachments are prepared on your own server and sent through Gravity Forms' normal sending. The one outside call is the More from PlugUpp panel on the plugin's tab under Forms, Settings. Once a day it reads the list of PlugUpp plugins from WordPress.org, and it sends nothing about your site.
Does it change Gravity Forms' own attachment setting?
No. Attach uploaded fields to notification works as before, and other attachment plugins keep adding their files. The plugin checks the whole final email, so a file attached twice goes in once, and the 25 MiB ceiling counts those files too.
Why is there no Email attachments box on my custom post type?
The box shows only on the types ticked under Show the Email attachments box on, on the Additional attachments tab under Forms, Settings. Tick the type and save. Only public post types are listed.
Why does the box sit at the bottom of the block editor for some types?
The sidebar panel saves through the block editor, which only saves this kind of setting for post types that support custom fields. For a type that does not, the box appears in the block editor's area below the content instead. It works the same way and saves with the page.
If I change a page's files, what do resends send?
The files the page holds at the time of the resend. The entry stores the page, not the files, and the plugin keeps no old copies.
Why does a private file have no thumbnail?
The plugin makes a small preview when the file is uploaded. Images always get one when the server has an image library. A PDF gets one only when the server's ImageMagick can read PDFs, which needs Ghostscript, the same as for PDFs in the Media Library. Without it the row shows a PDF icon. The file itself is sent the same either way.
Can I move a file between the Media Library and the private files?
Not directly. Upload the file again in the tab you want, add it where it is needed, and remove the old one.