I am currently having some problems with form SPAM. Although the form is save and does not allow cross site scripting or even the execution of injected JavaScript it is still a pain in the as to have to delete SPAM from whatever web based database (guestbook , feedback, trouble-ticket, ...).