Thank you for your kind reply. I’ll call GoDaddy tomorrow to confirm whether the vulnerability is specific to the Contact Form or the Widget, as well as the URL confirmation. If you prefer, I can paste(into this blog) a portion of the cross scripting test that GoDaddy performed. However, I do not know the etiquette for placing that kind of information here. I do not want do something inappropriate… (I’m new to this). So I would rather wait for your direction. Would it be better if I emailed the GoDaddy test to you directly in an attachment? Thank you for your patience with me.