Actually, this is not that great of a problem. All you'd need to resolve for is spam attempts: captcha, etc.
I'll probably still go with the hidden form method, as this keeps the built-in triggers logged.