> For one, the client is downloading the crypto JS implementation (almost) every time they are using the app
Not in the case of browsers' extensions or Electron/NW.js apps.
> XSS vuln on your website? crypto.js is useless since attacker will just exfiltrate your private key / password through XSS.
It's not like buffer overread and other vulns don't exist in the non-browser world. Also, a huge amount of XSS vulns can be avoided by having a good CSP config.
Now I'm not supporting javascript crypto. Just responding to some of your points. Inb4 some crypto SJW quotes me on that.