> If you don’t trust partial-password.github.io consider to save the page locally and run it from there
This doesn’t really make it safe per se, there still can be a script running that triggers an AJAX call in the background, sending the password to some web URL.