As one of the developers on the NMS project I can say that every effort has been made to make the program totally secure. The development team are all professional software developers with many accumulated years in the internet industry and are fully aware of all the security risks that beset a CGI program such as FormMail.
If you have any further questions about NMS FormMail (or any other NMS programs) then you might want to use our mail list at nms-cgi-support@lists.sourceforge.net.
Hope that helps