Per the well-known article "Javascript Cryptography Considered Harmful", it is quite hard to call any encryption tool on the web safe when the server can just update it. while keeping static pages secure is a reasonable ask, a TOFU mode would be quit...