I would hope you are at least required to perform PCI level security testing on the page, to ensure it doesn't contain any dodgy Javascript and the like (<script src="some-js-I-didn't-audit-which-steals-stripejs-card-data"...).
Likewise, as there's a webserver serving the page, presumably it must have some level of testing, to ensure it is unlikely to be serving compromised web pages?
As I understand the form in the example, if the user's browser has Javascript disabled, then the form submits the credit card number to the server - putting it in PCI scope(?)
<form action="/plans/browserling_developer" method="POST" id="payment-form">...<input type="text" size="30" autocomplete="off" class="card-number"/>...</form>
It would be interesting to know the PCI process for such a setup.