Capture leads with a protected download
The situation
A Joomla site with YOOtheme Pro wants to offer a PDF guide in exchange for an email address. Whoever designs the page does not want to touch code or open the Joomla administrator for every form. Whoever runs the site wants two things: the file must not be downloadable without going through the form, and every lead should sit in Joomla's own database, with what they agreed to and when.
How it is solved
evoLeadGate adds a "Lead magnet" element to the YOOtheme builder. That one element defines the whole form: identifier, extra fields (text, phone, dropdown, checkbox), file, delivery type, texts, consent, notification emails and analytics events. The email field is always required.
The file lives in a private folder with direct access blocked. Downloads go through a link with a random token that expires (7 days by default, configurable) and are served by PHP, so the real path is never exposed. There are two delivery modes: instant download plus an email with the link, or email only, where the first valid use of the link marks the email as verified.
Consent is two separate checkboxes: privacy, required, and marketing communications, optional and unticked. Each lead stores the exact text it accepted and the date.
Against spam the form has a honeypot field, a minimum fill time and a per-IP submission limit. A mail failure does not stop the lead being saved; it is noted in the lead's delivery status.
After a successful submission the form pushes an event to the dataLayer and, if the site has loaded those pixels, records the conversion in Google Ads and Meta with an event ID that matches the lead's.
Leads are managed under Components → evoLeadGate: a list with filters and search, a detail view with consents, origin and download history, CSV export, and single or bulk deletion. A scheduled task applies retention.
What is involved
- evoLeadGate: builder element, administration component and task plugin.
- To get started: installation and first steps.
- What is stored and for how long: data it handles.
Limits
- Blocking the private folder relies on
.htaccess. On Nginx, or on Plesk with static files served by nginx, you need to add your own rule; the "Check protection" button tests whether the block really works. - The retention task does not create itself: you have to add the scheduled task, otherwise IPs are not anonymised and expired leads are not deleted.
- Email depends on Joomla having working SMTP settings.
- The Google Ads and Meta pixels are loaded by the site itself; the form script does not read the consent state, it only detects whether those functions exist.
- evoLeadGate has no connectors to other systems. When a lead is created it fires a Joomla event that a plugin of your own can listen to.
- The IP is stored in full by default, with an option to anonymise it, and must be covered by your privacy policy. This is not legal advice; consult your adviser.