I love the site, but when i looked into hosting it locally, I noticed the NPM Audit reports a TON of high risk vulnerabilities in the dependencies.
The best aspects of the site is the ability to randomize stroke patterns and use the dynamic speed modifiers. I really like using it while playing games or watching videos that are unscripted, and using some macros to change the speed settings without interruption.
Are you planning on hosting it for the public as well? If not, those reports barely mean anything.
It is called risk for a reason. It is like leaving your car unlocked (with your gate keys in it) in your fenced and locked property; it is a risk, but for someone to steal it, first they have to find your property, assess it, and then steal your car. But the goal was your property, not your car.
I can not state it for sure, a 100%, that it is safe to use, but the risks are fairly low.