(function () {
try {
// AQ-r2 (2026-06-09): respect the explicit-denial sentinel
// written by cookie-consent-harden.js writeATR() on any
// marketing-axis denial (payload.marketing === false; cycle-3 F1).
// Without this gate, the next page navigation re-creates
// gmx_first_touch from the current URL+referrer+utm_*+click_ids,
// silently undoing the reject-all deletion (sweep finding #1).
// The sentinel is cleared the moment the visitor grants
// marketing in the banner (analytics-only grant does NOT
// clear), restoring the writer path on the very next
// page load. Page-cache-safe: the sentinel is a
// browser-resident cookie checked in the inline script, so
// varnish/breeze-served HTML still hits this gate.
if (/(?:^|;\s*)gmx_consent_denied=1(?:;|$)/.test(document.cookie || '')) return;
var CLICK_IDS = ['gclid','fbclid','msclkid','ttclid','wbraid','gbraid','li_fat_id'];
var qs = new URLSearchParams(window.location.search);
var urlClickIdKey = null;
for (var i = 0; i < CLICK_IDS.length; i++) {
if (qs.get(CLICK_IDS[i])) { urlClickIdKey = CLICK_IDS[i]; break; }
}// Parse existing cookie.
var existing = null;
var match = document.cookie.match(/(?:^|;\s*)gmx_first_touch=([^;]+)/);
if (match) {
try { existing = JSON.parse(decodeURIComponent(match[1])); } catch (e) { existing = null; }
}// GWP-273 — referrer-enrichment branch.
// Keep existing unless either (a) URL carries a new click id
// the stored payload lacks (paid click is a higher-value
// signal and upgrades direct/organic), OR (b) the stored
// payload has empty referrer AND the current document.referrer
// is non-empty + external (Safari/ITP/policy-quirk catch:
// first-hit may have missed the referrer; later same-session
// page-loads can recover it).
var existingHasRef = !!(existing && existing.referrer && existing.referrer !== '');
var docRef = document.referrer || '';
var refHost = '';
if (docRef) {
try {
refHost = new URL(docRef).hostname.replace(/^www\./, '').toLowerCase();
} catch (e) { refHost = ''; }
}
var ownHost = (location.host || '').replace(/^www\./, '').toLowerCase();
var currentExternalRef = !!(refHost && refHost !== ownHost);
var canEnrichRef = !!existing && !existingHasRef && currentExternalRef;if (existing) {
if (!urlClickIdKey && !canEnrichRef) return;
if (urlClickIdKey && existing[urlClickIdKey] && !canEnrichRef) return;
}var utm_keys = [
'utm_source','utm_medium','utm_campaign','utm_content','utm_term',
'utm_adgroup','utm_matchtype','utm_network','utm_device','utm_placement'
];
// GWP-273 — merge-preserving base. When enriching an existing
// payload, retain its landing_url + ts + prior click ids /
// utms; only overlay referrer (and any click id appended below
// via the forEach). Branches with/without urlClickIdKey were
// collapsed — both produced the identical Object.assign — the
// click id is added uniformly later.
//
// GWP-273 design choice: "latest external referrer wins" —
// accepted edge case where a user opens a new external tab
// post-empty-first-touch and returns; low-volume, simple, no
// sentinel flag needed.
var data;
if (existing && canEnrichRef) {
data = Object.assign({}, existing, { referrer: docRef });
} else {
data = { landing_url: window.location.href, referrer: docRef, ts: Date.now() };
}
utm_keys.concat(CLICK_IDS).forEach(function (k) {
var v = qs.get(k);
if (v) data[k] = v;
});
// GWP-208 — carry Meta's first-party click-linker cookies (_fbc
// = fb.1.<ts>.<fbclid>, _fbp) into the captured payload so they
// ride the persistent gmx_first_touch cookie cross-page (LP X →
// LP Y) the same way the URL click-ids do. The CF7 hidden-field
// populator copies the whole payload verbatim, so fbc/fbp reach
// the lead even when the form lives on a page without ?fbclid.
var fbcMatch = document.cookie.match(/(?:^|;\s*)_fbc=([^;]+)/);
if (fbcMatch && fbcMatch[1]) data.fbc = decodeURIComponent(fbcMatch[1]);
var fbpMatch = document.cookie.match(/(?:^|;\s*)_fbp=([^;]+)/);
if (fbpMatch && fbpMatch[1]) data.fbp = decodeURIComponent(fbpMatch[1]);
var encoded = encodeURIComponent(JSON.stringify(data));
if (encoded.length > 3800) return;
var expires = new Date(Date.now() + 90 * 864e5).toUTCString(); // GWP-143 C1: match Google Ads 90-day attribution window
var secure = window.location.protocol === 'https:' ? '; Secure' : '';
document.cookie = 'gmx_first_touch=' + encoded + '; Path=/; Expires=' + expires + '; SameSite=Lax' + secure;
} catch (e) {}
})();
/* Meta Pixel base — inline in wp_head so Breeze Delay-All-JS does not defer it; fbevents.js is async-injected (optimizer-invisible). */
!function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function(){n.callMethod?
n.callMethod.apply(n,arguments):n.queue.push(arguments)};if(!f._fbq)f._fbq=n;
n.push=n;n.loaded=!0;n.version='2.0';n.queue=[];t=b.createElement(e);t.async=!0;
t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window,document,'script',
'https://connect.facebook.net/en_US/fbevents.js');/* Symmetric with server GMX_Consent: revoke BEFORE init; cookies/sends held until grant. */
fbq('consent', 'revoke');
fbq('init', '1857131551802431');
fbq('track', 'PageView'); /* queued; flushed to Meta only after consent grant *//* Grant bridge — reads the SAME ATR marketing signal as GMX_Consent.applyConsent(). */
(function () {
function read(name){var m=document.cookie.match('(?:^|; )'+name.replace(/([.*+?^${}()|[\]\\])/g,'\\$1')+'=([^;]*)');return m?decodeURIComponent(m[1]):'';}
function marketingGranted(){
try {
var given = read('atr_cookie_notice_consent_given');
if (!given) return false; // undecided -> stay revoked
var c = JSON.parse(read('atr_cookie_notice_consent') || '{}');
return !!(c.marketing || c.ad_storage === 'granted');
} catch (e) { return false; } // NO-SILENT-OK: parse/read failure degrades gracefully to revoked (consent stays held; no marketing send) — not an error to report.
}
function apply(){ if (marketingGranted()) fbq('consent', 'grant'); }
apply();
document.addEventListener('click', function(ev){
if (ev.target && ev.target.closest && ev.target.closest('[class*="atr-cookie"], #atr-cookie-notice')) setTimeout(apply, 50);
}, true);
window.addEventListener('storage', apply);
})();
var breeze_prefetch = {"local_url":"https://gomixapp.com","ignore_remote_prefetch":"1","ignore_list":["/cart/","/checkout/","/my-account/","https://gomixapp.co.il/(.)/u05d4u05d8u05d5u05e4u05e1-u05e0u05e9u05dcu05d7-u05d1u05d4u05e6u05dcu05d7u05d4/","wp-admin","wp-login.php"]};
//# sourceURL=breeze-prefetch-js-extra
Creating a digital business card with GoMixApp is the fastest, smartest way to consolidate all your business details in one place — a personal web page that updates in real time. Share it via WhatsApp, QR code, NFC or a direct link, and customers can save you with a single tap. Advanced digital business cards replace printed paper and bring you into the digital era — no printing, no lost information, and self-updates possible at any time.
Need a digital business card? For more details fill in your details and we will get back to you shortly.
What is a digital business card?
Creating a Digital Business Card lets you smartly replace the traditional paper business card. Instead of a paper card that gets lost, you get a personal web page that you can share and update any time — without limits.
The digital card includes everything a paper card offers – and much more:
Full contact details (phone, email, address)
Links to social networks and your website
Photo and video gallery
Direct navigation via Waze or Google Maps
One-tap save to phone contacts
Send via WhatsApp, SMS or email
Custom design with your business logo and brand colors
And how does a digital business card promote my business?
A smart business card for your phone solves this problem and many others. We live in a digital age, and every business owner, freelancer and job seeker needs a digital presence. An electronic business card can be an alternative to a corporate website, or an addition to it. If you do not currently have the budget for a full website, do not have enough content yet, or your site is still under construction — a phone business card can fill the gap. An electronic card saves space in your bag, is convenient, accessible and modern. With an electronic card, it is no problem if you opened a new profile, changed your name, or switched roles. You can easily and quickly update the electronic business card without additional payment or redesign. Add photos of new work to your gallery to impress clients even more. And if that is not enough — digital business cards are eco-friendly and help you reduce your carbon footprint. And perhaps most importantly, an online business card saves you money too.
Sounds too good to be true? The business card is interactive – scroll and tap inside the phone in front of you 👈
The interactive business card — scroll and tap inside the phone in front of you 👇
Key Takeaways
Personalized digital business card with professional design
Instant sharing via link, QR or NFC
Real-time updates with no reprinting needed
Hebrew and English support with adaptive text direction
Analytics tracking: views, clicks and saves
Advantages
Never gets lost
Custom design
One-click sharing
Works on all devices
All communication channels
Quick save to contacts
Eco-friendly
Self-update all content
Photo and video gallery
Analytics dashboard
Annual pricing
Setup and design of the business card by professional designers.
Compatibility with all devices.
Photo gallery integration to showcase past work or your services.
Digital business cards — law, education and business
Three examples of digital business cards we designed for a lawyer, a Montessori-based kindergarten and a service-industry business owner.
Digital business card, Raanan Esq.
Digital business card for Raanan the lawyer — practice areas, contact details, direct WhatsApp and email links, and a quick inquiry form for potential clients.
Digital business card, Element Montessori
Digital business card for the Element Montessori kindergarten chain — teaching staff presentation, gallery, contact form and a parent notice board.
Digital business card, Roshar
Digital business card for the Roshar business — service info, customer reviews, weekly specials menu and a direct link to online ordering.
How do you use a digital business card?
We take your details and design the perfect card for you.
With one tap you can send your details in a message or add them as an email signature.
Save the card to home screen
Receive the designed card and save it to your phone home screen — so your card is always with you for instant sharing.
Share with one tap
No prior technical knowledge needed. Send your details and our team of experts will design a business card that fits your needs and personal brand.
Instant NFC tap sharing
GoMixApp offers an advanced service of printing branded NFC cards and NFC stickers. The prospect taps their phone to the card — and your digital card opens automatically, with no typing and no search. A one-time solution that upgrades every business meeting to an impressive experience. NFC technology turns every touch into a business opportunity, making you unforgettable.
Why you need a smart business card?
We live in a digital age where everything is digital.
A digital business card helps you stand out from competitors — especially if you do not yet have a website or active social media profile. As of 2026, more than 300 companies and small businesses have already moved to the GoMixApp digital solution. It is available immediately, self-updatable, and sends a clear message: you are a modern, serious business. If you want to make a professional impression, you must show that you have your finger on the pulse.
An electronic business card is always with you.
Most printed business cards end up in the trash within a few days. The digital solution is always available: send a WhatsApp link, show a QR code at a meeting, set a digital email signature — and even save as a screensaver. A business card that lives in the customer’s phone never gets lost, ensuring you are always within reach.
Add a gallery of photos, videos, or a portfolio.
A standout advantage of a virtual business card is the ability to add a gallery of photos and videos of the services you offer. Saying you are an expert is good — showing it is better. Through the content editor you can update your portfolio at any time, even after you have shared the card with hundreds of clients. Graphic design platforms integrated with vCard format enable direct contact export to CRM apps — an asset that grows with your business.
Get analytics on visits and views of your business card.
A digital business card provides data a paper card never will. At any time you can log in to the dashboard, see how many people viewed the card, which buttons they tapped, and what the conversion rate is — so you can improve your marketing strategy and maximize ROI. Data-driven digital contact sharing is a powerful tool for any business that wants to grow.
Preserve your uniqueness.
Building a digital business card with GoMixApp lets you stand out — a design tailored to your brand colors, logo, and content that reflects exactly who you are. Our experts design a card that fits your personal taste and target audience expectations while meeting recognized digital accessibility standards.
A digital business card fits every profession and field. Here are examples by profession:
Lawyers
Lawyers need a card that conveys credibility and professionalism. The digital card includes specialty details, a link to the bar association profile, navigation to the office and one-tap calling. Ideal for professional events, courts and client meetings.
Therapists and doctors
Psychologists, physiotherapists, dentists and alternative-medicine practitioners – all need a fast way to share contact details and location. The digital card lets patients book an appointment, navigate to the clinic and save the phone number with one tap.
Renovators and tradespeople
Electricians, plumbers, renovators and carpenters – anyone working on-site needs a card that is easy to share. Instead of dictating a phone number — send a WhatsApp link with all the details, a work gallery and navigation.
Insurance agents
A digital insurance-agent business card is a powerful sales tool for agents meeting dozens of clients weekly. The card includes insurance specialties, a meeting-booking button and a direct-call button — turning every encounter into a tangible business opportunity. See the agents and managers template and send one link that delivers all the information to the client in one tap.
Managers and consultants
Managers, business consultants and sales professionals need a business card that reflects their professional level. The digital solution includes LinkedIn, personal-site and portfolio links — enabling fast sharing at business conferences and networking events. A CRM app integrates seamlessly with the digital card and increases the conversion rate from meeting to deal.
Share via WhatsApp
The most popular method in Israel: tap the share button, pick WhatsApp and send. The recipient gets a direct link to your card.
QR Code
Every card comes with a unique QR Code. Print it on marketing materials, signs or presentations – anyone who scans goes straight to your card.
NFC – tap to scan
With an NFC sticker or a physical NFC card – customers tap their phone and jump straight to your digital card. An especially impressive technology for meetings and events.
Direct link
Add the card link to your email signature, social-media profiles or your website.
More digital solutions from GoMixApp
Beyond building digital business cards, GoMixApp offers more business solutions: custom landing pages, secure digital forms, and personalized digital marketing solutions for every industry and profession.
Secure digital forms – sign customers on contracts, agreements and business forms with one click
Three more examples of digital business cards we designed for a real estate broker, a RE/MAX agent and a business consultant.
Digital business card, Hagar
Digital business card for Hagar — a personal landing page with portfolio, customer testimonials, direct contact details and a quick inquiry form.
Digital business card, Michal — RE/MAX
Digital business card for Michal, a RE/MAX real estate agent — active listings catalog, photo gallery, market data and a direct WhatsApp number.
Digital business card, Orit Eldar
Digital business card for Orit Eldar — description of consulting services, mentoring tracks, customer reviews and a discovery-call booking form.
Customers recommend
Pinchas
HOA, Ramla
Service:
★★★★★
Product:
★★★★★
Recommendation:
★★★★★
“With the holiday videos you really nailed it – the residents were thrilled!”
Mor
Academic institution
Service:
★★★★★
Product:
★★★★★
Recommendation:
★★★★★
“The digital notice board looks amazing, and everything works smoothly!”
Inbar Shmueli
Business owner
Service:
★★★★★
Product:
★★★★★
Recommendation:
★★★★★
“Personal, professional service, fast responses, excellent product, very satisfied”
Ready to upgrade your professional presence? Create a smart digital business card with GoMixApp – easy sharing, instant updates and an impressive look.
Join hundreds of businesses already using GoMixApp advanced digital business cards to grow their professional exposure. Setting up a digital business card takes less than 48 hours and lets you start sharing immediately. Building a digital business card with GoMixApp — an easy, fast and affordable platform. For more information on this topic worldwide, visit the Israeli authority’s digital data protection page.
Contact us today and we will start designing the perfect digital card for you — a solution that combines professional graphic design with cutting-edge technology.
Already Collaborating With Us
NFC and QR Code technology — contact sharing in the new era
NFC (Near Field Communication) technology lets you share contact details with one tap between two compatible devices — without typing or searching. GoMixApp supplies branded NFC cards and NFC stickers that can be stuck on any item, turning every touch into a business opportunity.
A unique QR code is attached to every card and allows fast scanning at business conferences, events, outdoor signage and even presentations. The vCard format is embedded in the card so the customer can save the contact details directly to their smartphone — full compatibility with iOS and Android. Read more about NFC adoption in business and how it works in practice.
Frequently Asked Questions
How long does it take to create a digital business card?
Creating a digital business card at GoMixApp takes less than 48 hours. You send your details, our design team builds the card, and you receive a ready-to-share link — with no technical knowledge needed.
Can the card content be updated after sharing?
Absolutely. The digital card can be self-updated at any time via the dashboard — even after you have shared it with hundreds of customers. Changes appear in real time, with no reprinting needed.
How does NFC technology work in the digital card?
A branded NFC card or NFC sticker lets the customer hold their smartphone near it and open the digital card automatically, without scanning or typing. GoMixApp offers NFC card printing as a complementary service.
Is the card suitable for all types of businesses?
Yes. The solution fits every profession and field — from insurance agents, lawyers, therapists and doctors to renovators, managers and business consultants. The card design can be tailored to the brand colors and the specific target audience.
What is the difference between a digital business card and a regular printed card?
A smart digital business card updates in real time, can be shared instantly via WhatsApp, QR code and NFC, and provides tracking data. A printed card is fixed, expensive to update, and usually ends up in the trash — while the digital solution is always within reach.
Digital business card vs. traditional business card
Feature
Digital business card
Traditional business card
Accessibility and sharing
✓Instant sharing across any digital channel
✗Requires in-person physical handover only
Detail updates
✓Real-time updates at no cost
✗Requires reprinting for every change
Device compatibility
✓Displays perfectly on every device
✗Does not support digital display
Communication channels
✓Includes phone, email, social networks and more
✗Limited to printed information only
Design and personalization
✓Flexible design adapted to personal brand
✗Fixed design, expensive to change
Long-term cost
Significant savings – no recurring printing
Expensive – cumulative printing and distribution costs
In summary — the time to switch to a smart business card is now
Building a digital business card with GoMixApp is the smartest investment any professional can make in 2026. We saw how the solution replaces the traditional printed card, provides real-time tracking data, and enables fast sharing via NFC, QR code and WhatsApp — without spending a dime on recurring printing. A smart digital business card grows your exposure, strengthens professional credibility and ensures customers will always find you — even a year after you met. Last updated: January 2026.
Hundreds of businesses and professionals have already chosen GoMixApp as their digital-presence platform — from insurance agents and lawyers to renovators and fitness trainers. It is your turn to take the step. Contact us now and we will start designing the perfect digital card together for you.
document.addEventListener('click', function(e) {
var el = e.target.closest('.gmx-lite-yt');
if (!el) return;
var vid = el.getAttribute('data-vid');
if (!vid) return;
var iframe = document.createElement('iframe');
iframe.src = 'https://www.youtube.com/embed/' + vid + '?autoplay=1';
iframe.style.cssText = 'position:absolute;top:0;left:0;width:100%;height:100%;border:0;';
iframe.allow = 'autoplay;encrypted-media';
iframe.allowFullscreen = true;
el.style.position = 'relative';
el.innerHTML = '';
el.appendChild(iframe);
});
(function () {
var c = document.body.className;
c = c.replace(/woocommerce-no-js/, 'woocommerce-js');
document.body.className = c;
})();
var gmxCf7LegacyUxI18n = {"errName":"Please enter a full name","errPhone":"Please enter a valid phone number","errEmail":"Please enter a valid email address","errRequired":"Required field"};
//# sourceURL=gmx-cf7-legacy-ux-js-extra
var gmxCf7UxI18n = {"progressTemplate":"{N} field(s) remaining","allSet":"All set to send!","sending":"Sending\u2026","successTitle":"Thank you! Your inquiry has been received","successBody":"A representative will get back to you within 24 hours with a tailored quote.","successCtaLabel":"See our areas of expertise","successCtaHref":"/expertise/","errorTitle":"Submission failed","errorBody":"Please try again, or call us directly"};
//# sourceURL=gmx-cf7-ux-js-extra
var atrCookieNoticeSettings = {"cookieName":"atr_cookie_notice_consent","decisionCookieName":"atr_cookie_notice_consent_given","expiryDays":"365","autoHideDelay":"0","enableDebug":"","siteName":"GoMixApp","isPrivacyPage":"","privacyPolicyUrl":"https://gomixapp.com/privacy-policy/","privacyNoteText":"\ud83d\udca1 You can read this page while deciding about cookies","mode":"simple"};
//# sourceURL=atr-cookie-notice-simple-js-extra
(function(){
function cleanUrl(url) {
// Strip query params embedded mid-path: /ID?params/file -> /ID/file
return url.replace(/\?[^\/]+\//g, '/');
}
function addWebPFallback(pic) {
if (pic.getAttribute('data-webp-fb')) return;
pic.setAttribute('data-webp-fb', '1');
var img = pic.querySelector('img');
if (!img) return;
img.onerror = function() {
this.onerror = null;
this.src = cleanUrl(this.src).replace('vi_webp','vi').replace('.webp','.jpg');
var sources = this.parentElement.querySelectorAll('source');
for (var i = 0; i < sources.length; i++) {
sources[i].srcset = cleanUrl(sources[i].srcset).replace('vi_webp','vi').replace('.webp','.jpg');
}
};
}
var observer = new MutationObserver(function() {
var pics = document.querySelectorAll('.video-seo-youtube-picture');
for (var i = 0; i < pics.length; i++) addWebPFallback(pics[i]);
});
observer.observe(document.documentElement, { childList: true, subtree: true });
})();
(function(){
var siteKey = "6Ldnu_gsAAAAAGpkh7vCd_h3L9BA193yFU59I4Do";
var action = "submit_lead_form";
var loaderUrl = "https:\/\/www.google.com\/recaptcha\/enterprise.js?render=6Ldnu_gsAAAAAGpkh7vCd_h3L9BA193yFU59I4Do";
// GWP-506 (perf): the reCAPTCHA Enterprise runtime costs ~900ms of main-thread
// work (PSI contactus TBT 660ms, perf 69). It was loaded eagerly on every page
// carrying a CF7 form. It now loads on the FIRST real page interaction
// (scroll/pointer/key/touch) — warming the runtime well before the user can
// reach submit — and never loads on a no-interaction (lab) page view, so the
// perf win holds. The token is still stamped on form focusin and refreshed at
// submit. IMPORTANT: the server gate is fail-CLOSED by default (GWP-412
// require_token) — a missing token at submit is treated as spam — so the
// runtime MUST be warm before submit; that is exactly why the warm trigger is
// first-page-interaction, NOT focusin-only (focusin-only left a race where a
// fast focus→submit could POST before the ~900ms download finished and drop a
// legit lead). The eager <script src> is gone.
var greReady = false, greWaiters = [], greLoadStarted = false;
function pollGre(attempts) {
if (typeof grecaptcha !== 'undefined' && grecaptcha.enterprise) {
greReady = true;
var queued = greWaiters;
greWaiters = [];
queued.forEach(function (fn) { try { fn(); } catch (e) {} });
return;
}
if (attempts > 200) {
// no-silent-failures: enterprise.js never became ready (network-blocked,
// consent/privacy blocker, or a Google outage). Surface it — a missing
// token fails CLOSED server-side (GWP-412) and drops the lead.
if (window.console && console.warn) {
console.warn('[GMX recaptcha] enterprise.js not ready after ~10s; token will be missing (submit fails closed).');
}
return; // give up after ~10s (200 * 50ms)
}
setTimeout(function () { pollGre(attempts + 1); }, 50);
}
function loadGre() {
if (greLoadStarted) return;
greLoadStarted = true;
var s = document.createElement('script');
s.src = loaderUrl;
s.async = true;
document.head.appendChild(s);
pollGre(0); // begin polling only once the runtime is actually loading
}
function whenGreReady(cb) {
if (greReady) return cb();
greWaiters.push(cb);
}
function stampToken(form) {
if (!form.querySelector('.wpcf7-form-control-wrap input[type="submit"], .wpcf7-submit')) return;
loadGre(); // lazy: kick off enterprise.js on demand (idempotent)
whenGreReady(function () {
grecaptcha.enterprise.ready(function () {
grecaptcha.enterprise.execute(siteKey, { action: action }).then(function (token) {
var hidden = form.querySelector('input[name="gmx_recaptcha_token"]');
if (!hidden) {
hidden = document.createElement('input');
hidden.type = 'hidden';
hidden.name = 'gmx_recaptcha_token';
form.appendChild(hidden);
}
hidden.value = token;
}).catch(function () {
// no-silent-failures: token generation failed; the server gate is
// fail-CLOSED (GWP-412), so this submit will be rejected as spam.
if (window.console && console.warn) {
console.warn('[GMX recaptcha] token execute failed; submit will fail closed.');
}
});
});
});
}
document.addEventListener('wpcf7submit', function (e) { stampToken(e.target); });
// Also stamp on first focus into any CF7 form (so token ready before submit).
// `whenGreReady()` queues the stamp until grecaptcha loads, so the once-
// listener stays safe even if grecaptcha isn't ready at focus-in time.
document.querySelectorAll('form.wpcf7-form').forEach(function (form) {
form.addEventListener('focusin', function once() {
form.removeEventListener('focusin', once);
stampToken(form);
});
});
// GWP-506: warm enterprise.js on the FIRST real page interaction so the ~900ms
// runtime is ready before the user reaches submit (closes the focusin-only race
// against the fail-CLOSED server gate, and covers AJAX/popup-injected forms that
// missed the focusin binding above). Never fires on a no-interaction (lab) view,
// so the perf win holds. Idempotent via loadGre()'s greLoadStarted guard.
var warmOpts = { passive: true, capture: true };
var warmEvents = ['pointerdown', 'keydown', 'touchstart', 'scroll'];
function warmGre() {
loadGre();
warmEvents.forEach(function (e) { window.removeEventListener(e, warmGre, warmOpts); });
}
warmEvents.forEach(function (e) { window.addEventListener(e, warmGre, warmOpts); });// GWP-507 (CONFIRMED LIVE: 19 real leads dropped in 8 days): capture-phase
// submit GATE. The warm/focusin logic above only *helps* the token be ready;
// it is NOT a guarantee. The race: a user whose FIRST interaction is clicking
// submit on an autofilled form (no prior scroll/field-touch to warm the
// ~900ms enterprise.js), or who submits before the runtime readies, serializes
// the AJAX POST with an EMPTY gmx_recaptcha_token → the fail-CLOSED server gate
// (GWP-412 require_token) drops the lead as spam. CF7's `wpcf7submit` fires
// AFTER the AJAX POST (too late), and CF7 exposes no documented pre-POST JS
// hook (verified: contactform7.com/dom-events). So the ONLY seam is to
// intercept the native DOM submit/click in CAPTURE phase, HOLD it until
// greReady + token stamped, then re-dispatch. grecaptcha token lifetime is
// 2 minutes, so holding briefly is safe.
//
// TIMEOUT-FALLBACK CHOICE (a): if enterprise.js never readies within the
// ~10s ceiling (network-blocked / consent-blocker / Google outage), we
// RE-ENABLE the button and let the submit proceed WITHOUT a token rather than
// hard-blocking the user. It will fail-CLOSED server-side (GWP-412), but the
// console.warn fires loudly (no-silent-failures) — we never trap a real user
// behind a spinner they can't escape.
var GATE_TIMEOUT_MS = 10000; // matches pollGre ceiling (200 * 50ms).
function gmxFormHasToken(form) {
var hidden = form.querySelector('input[name="gmx_recaptcha_token"]');
return !!(hidden && hidden.value);
}
function gmxSetVerifying(form, on) {
var btn = form.querySelector('.wpcf7-submit, input[type="submit"], button[type="submit"]');
if (!btn) return;
if (on) {
btn.disabled = true;
btn.setAttribute('data-gmx-verifying', '1');
} else {
btn.disabled = false;
btn.removeAttribute('data-gmx-verifying');
}
}
function gmxReleaseSubmit(form) {
// Mark released so the re-dispatched submit passes straight through the
// capture gate (no re-gate loop), re-enable UX, then re-trigger.
form.__gmxGateReleased = true;
gmxSetVerifying(form, false);
if (typeof form.requestSubmit === 'function') {
form.requestSubmit();
} else {
form.dispatchEvent(new Event('submit', { bubbles: true, cancelable: true }));
}
// GWP-507 finding-1 (BLOCKER fix): reset the release flag on the NEXT tick
// so any FUTURE user submit (user edits a field + resubmits) is re-gated and
// stamps a FRESH token. reCAPTCHA tokens are single-use with a ~2-min
// lifetime — without this reset, __gmxGateReleased stayed true forever after
// the first release, letting a second submit bypass the gate and POST a
// stale/used token. The setTimeout(0) lets the synchronous re-dispatch above
// complete (which short-circuits on the still-true flag) before we re-arm.
setTimeout(function () { form.__gmxGateReleased = false; }, 0);
}
function gmxSubmitGate(e) {
var form = e.currentTarget;
if (form.tagName !== 'FORM') { form = form.form || form.closest('form.wpcf7-form'); }
if (!form) return;
// Idempotent: a programmatic re-submit we already released proceeds. This is
// the ONLY pass-through — it lets the freshly-stamped re-dispatch reach CF7.
// (The flag is reset on the next tick in gmxReleaseSubmit, so the NEXT user
// submit is re-gated.)
if (form.__gmxGateReleased) return;
// GWP-507 finding-2 (stale/used token fix): every USER submit HOLDS + stamps
// a FRESH token — we do NOT early-return on an already-present token. A token
// already sitting in the hidden input may be stale or already used (single-
// use, ~2-min lifetime); proceeding on it would POST a dead token. enterprise.js
// is warm by submit time, so grecaptcha.enterprise.execute() resolves in
// ~100-300ms — the per-submit hold is brief. stampToken() OVERWRITES the
// hidden input value (hidden.value = token), so no stale token lingers.
// HOLD: block CF7's submit handler before the AJAX POST.
e.preventDefault();
e.stopImmediatePropagation();
if (form.__gmxGateWaiting) return; // a click + submit may both fire; hold once.
form.__gmxGateWaiting = true;
loadGre(); // kick the warm if not started.
gmxSetVerifying(form, true);
var released = false;
function release(missing) {
if (released) return;
released = true;
form.__gmxGateWaiting = false;
if (missing && window.console && console.warn) {
console.warn('[GMX recaptcha] submit gate timed out (~10s); releasing without token (submit fails closed).');
}
gmxReleaseSubmit(form);
}
var timer = setTimeout(function () { release(true); }, GATE_TIMEOUT_MS);
whenGreReady(function () {
stampToken(form);
// stampToken resolves the token asynchronously (enterprise.execute
// promise); poll briefly for the stamp, then release. Bounded by the
// same overall timer above.
(function awaitStamp(n) {
if (released) return;
if (gmxFormHasToken(form)) { clearTimeout(timer); release(false); return; }
if (n > 200) { clearTimeout(timer); release(true); return; } // ~10s (200*50ms)
setTimeout(function () { awaitStamp(n + 1); }, 50);
})(0);
});
}
// GWP-507 finding-4 (CF7 phase): WHY capture phase works. Our gate listener is
// registered in CAPTURE phase (3rd arg `true`), so it runs BEFORE CF7's own
// bubble-phase 'submit' handler on the same form. When we call
// e.stopImmediatePropagation() in the capture listener, the DOM spec stops ALL
// further listeners for that event on the target — including the later
// bubble-phase CF7 handler — so CF7's AJAX POST never fires until we re-dispatch
// with a fresh token. This capture-phase interception is the only documented
// pre-POST seam: CF7 exposes no pre-POST JS hook (wpcf7submit fires AFTER the
// AJAX POST). See contactform7.com/dom-events.
document.querySelectorAll('form.wpcf7-form').forEach(function (form) {
form.addEventListener('submit', gmxSubmitGate, true);
var btn = form.querySelector('.wpcf7-submit, input[type="submit"], button[type="submit"]');
if (btn) { btn.addEventListener('click', gmxSubmitGate, true); }
});
})();
(function(){
var loaded = false;
function loadUserWay() {
if (loaded) return;
loaded = true;
var el = document.createElement('script');
el.setAttribute('data-account', "UX40fo0Ctw");
el.setAttribute('data-language', "en");
el.setAttribute('src', 'https://cdn.userway.org/widget.js');
document.body.appendChild(el);
events.forEach(function(e){ window.removeEventListener(e, loadUserWay, {passive: true}); });
}
var events = ['scroll', 'mousemove', 'touchstart', 'click', 'keydown'];
events.forEach(function(e){ window.addEventListener(e, loadUserWay, {passive: true}); });
})();