Here's the commit in question: https://github.com/mixpanel/mixpanel-js/commit/98a1845c5c55f... - as referenced here: https://github.com/mixpanel/mixpanel-js/issues/164 .
The meat of it is that the check of the type of the <input> node to ensure it's not "password" or "hidden," now wraps the iteration over attributes as well as inclusion of the value.
That heuristic, though, is far from perfect: see, for instance, https://www.troyhunt.com/bypassing-browser-security-warnings... . And even if you're not doing something funky like that, you're not out of the woods. For instance, it's highly likely that a site collecting "secret answers" in plaintext input fields (for password resets) would leak that information to Mixpanel if Autotrack were turned on. This commit does nothing to change that scenario. And while Autotrack is now opt-in, it can be done entirely by a business team with zero interactions with engineering, if (for example) a tag management solution is set up: see https://mixpanel.com/blog/2015/03/27/community-tip-implement... and https://help.mixpanel.com/hc/en-us/articles/115004613366-Wha...
SaaS analytics companies, especially those able to slurp up everything into a managed data lake and provide perfect retroactive analysis capabilities, provide a great experience compared to self-hosted solutions, but it's inevitable that you'll end up giving them more information than you'd originally planned. For many businesses, that's the right decision, but it should be one made with eyes wide open.