If you use a  content-security-policy, you’ll need to add some elements to it if you want to use goodforms.com:


Header set Content-Security-Policy "script-src 'self' 'unsafe-inline' 'unsafe-eval' api.goodforms.com http://cdn.goodforms.com;"