Calendly form events have a security vulnerability if you use their boilerplate JS
Ugh, same mistake HubSpot made. And unlike HS, I really like Calendly. Lesson: never trust “sample code” in the developer docs. It’s often cut down to make things look easier than they are, or it wasn’t written by an experienced dev. →