Check a page
The checker works with any form, not only Formgong forms. It is free and you don't need an account. It looks at the HTML the page sends, so it works best on the published site.
This form has no action. Unless a script sends it, the browser posts it back to this page and nothing is delivered. Point it to your form backend, for example with a prompt for your builder.
This form has no action, but its attributes suggest that a script sends it. The checker can't see where a script sends data. Send one test message and check that it arrives.
The action "{action}" is not a web address, so the form can't be sent.
The action "{action}" looks like a placeholder that was never replaced. Put your real endpoint there. For Formgong that is https://formgong.com/submit plus your access key.
The form posts to {host}, a local or private address. It only works on the developer's computer, and visitors' messages go nowhere. Use a public endpoint.
The form posts over plain http to {host} from an https page. Browsers warn about this or block it. Use https.
The form posts to {host}. We don't know it as a form service. That can be fine, but make sure it is yours and still running.
The form uses method GET, so the message ends up in the URL, the browser history and server logs. Use method="POST".
The form has no method, so the browser uses GET and puts the message in the URL. Add method="POST".
{count} field(s) have no name attribute, so the browser never sends them: {fields}. Add a name to each field.
There is no email field, so you can't reply to the visitor. Add <input type="email" name="email">.
The email field "{field}" is not type="email". Phones show the wrong keyboard and browsers don't check the address. Use type="email".
No spam protection found: no honeypot field and no CAPTCHA. Contact forms get bot spam within days. Add a hidden honeypot field (Formgong uses botcheck) or Turnstile. How a honeypot works.
This form posts to Formgong, but to {path}. The endpoint is /submit.
This form posts to Formgong but has no access_key field, so every submission is rejected. Add <input type="hidden" name="access_key" value="fk_…">.
This looks like a Formgong form without an action. A script may add the key and send it, which the checker can't see. Send one test message to be sure.
The access key "{key}" is a placeholder or has the wrong format. Copy the real key from your dashboard.
The botcheck honeypot field is missing. Formgong still filters spam, but the honeypot stops most simple bots. Add it back (see the prompts).
The form has a file field but no enctype="multipart/form-data", so files are not sent.
This form has many fields; only the first 120 were checked.
No problems found in this form's HTML.
The address did not return an HTML page, so there was nothing to check.
The page answered with HTTP {status}. Check the address; this may be an error page.
The page is larger than 512 KB, so only the first 512 KB were checked.
The page shows a form from another service in an iframe ({hosts}). The checker can't look inside it; that service handles the messages.
We found {count} form field(s) outside a form element. The form is probably built and sent by JavaScript, which the checker can't run. Send a test message, or paste your code into the prompt for your builder.
This page looks like a JavaScript app (React, Vue or similar). Its form appears only after scripts run, and the checker reads HTML only, so it can't tell whether the form works. Send a test message to be sure.
We found forms, but none looks like a contact form. Search and login forms are skipped.
We found no form in this page's HTML.
The page has more than 20 forms; only the first 20 were checked.
Formgong's fg.js script is on the page.
Enter a full web address, for example https://example.com/contact.
This address is too long.
Only http and https addresses can be checked.
Remove the user name and password from the address.
Only the standard web ports (80 and 443) can be checked.
This address can't be checked (a local or internal name, or Formgong itself).
This address is in a private or local network, so we don't fetch it.
We couldn't find this domain. Check the spelling.
This domain points to a private or local network, so we don't fetch it.
The page redirected more than 3 times, so we stopped.
The page sent a broken redirect.
The site took longer than 8 seconds to answer.
We couldn't load the page.
Too many checks. Please wait a few minutes.
Please complete the security check first.
The security check failed. Please try again.
The checker is unavailable right now. Please try again later.
The request was blocked. Reload the page and try again.
Something went wrong. Please try again.
Result for {url}
Redirects followed: {n}
Form {label}
No forms to check on this page.
Sends to: {target}
this page
contact form
search form
login form
sign-up form
form
Problem
Warning
Note
OK
Formgong key {key}: the form exists and accepts submissions.
Formgong key {key}: no form has this key, so every submission is rejected (unknown_access_key).
This is your form "{name}".
This page's domain is not in the form's allowed domains, so submissions from here are rejected. Change it in the form settings.
This page's domain is allowed for the form.
Turnstile is on for this form, but the page has no Turnstile widget, so submissions will fail.
Send a test submission to my form
Sending…
Test submission sent. Check your inbox and the dashboard.
The test was not accepted ({code}).
This form needs Turnstile, so send the test from the page itself.
Sign in as the form owner to send a test submission from here.
What the checker looks for
- A form without an action, or an action that still holds a placeholder such as YOUR_FORM_ID.
- An action that points to localhost, a private address or an unknown host.
- method GET on a contact form, which puts the message in the URL.
- Fields without a name attribute. The browser never sends them.
- An email field that is not type="email", or no email field at all.
- No honeypot and no CAPTCHA, so nothing stops spam bots.
- For Formgong forms: a missing or placeholder access key, a key that does not exist, and a missing botcheck honeypot.
What it can't see
The checker reads HTML. It does not run JavaScript. Many sites built with React, Vue or an AI builder create the form in the browser, so the HTML has no form yet. In that case the checker says so instead of guessing. It also can't see where a script sends the data. For those sites, send one test message, or paste the form code into the prompt for your tool.
Forms inside an iframe (Google Forms, Typeform and similar) are run by that service, so the checker only names it.
Safety and privacy
The checker sends one GET request to the page, with up to 3 redirects, and never submits a form to the site. It only fetches public addresses on the normal web ports. Local, private and internal addresses are refused before any request, and so is every redirect that leads to one. Pages larger than 512 KB are cut, and slow sites stop after 8 seconds.
We don't store the page or the result. A short counter limits each visitor to a few checks every 10 minutes. For a Formgong key we only say whether the form exists. More details, such as allowed domains and a test button, appear only for the signed-in owner of that form.
After the check
Most problems are fixed by asking your builder to rebuild the form with a clear spec. Use the copy-paste prompts for Lovable, Bolt, v0, Cursor, Claude Code, Windsurf or Replit. For a coding agent that keeps editing the project, add the Formgong rules file so the fix stays in place.
Questions
Does the checker send a test message to my site?
No. It only reads the page. The single exception: the signed-in owner of a Formgong form can send one test submission to their own form, and only to Formgong.
Why does it say my form is built with JavaScript?
Your page sends little or no form HTML and builds the form in the browser. The checker does not run scripts, so it can't judge that form. Send one test message to be sure it works.
Does it work with forms that are not on Formgong?
Yes. All general checks work for any form backend. Only the access key checks are specific to Formgong.
Can it check pages behind a login?
No. It fetches the page like a visitor who is not signed in, so it only sees public pages.
Sources
Checked on 04.10.2026 against these public pages: OWASP SSRF Prevention Cheat Sheet, MDN: <form>, Formgong /agents.md.