I have heard Nicholas say that iFrames are not a good idea for displaying forms on a website. I am working on a client website and their forms provider JotForms told her that iFrames are a perfectly secure way for displaying form data on a website if that site is protected with an SSL certificate.
I would hate to go through all the trouble I have gone trough setting up Admin Tools just to add a vulnerability through some third party widget. She is a lawyer and her site deals in patients medical record, so her site needs to be HIPPA compliant which she can't afford, JotForms is HIPPA compliant, so she has to display their forms on her site through iFrames.is that a good idea or would she be better off in the long run getting a dedicated server so that she can make that server HIPPA and PCI compliant? Or should she just display a link to the form on the JotForms site?