The page loads jquery from google cdn, so at least google could inject js in the page and read the message before it gets encrypted.<p>I know, for a contact form this is very unlikely, but just from a security point of view, if I would write something like this, I would host js loaded by the page on my own server.