That's definitely a good thing in terms of the quality of the code now by the way, I don't see any changes that make it worse and many make it better. But it does mean comments may not refer to the source you looked at.
Too late to edit this after having slept but I think the word I wanted here was "better" not "bad" ?
The author is not rolling their own cryptography (which is good) but they are clearly using a home made cryptosystem (and not PGP, TLS, or libsodium for example). For example they forgot authenticating their encryption, and the with "password extension" getFilledSecret is more than doubvious. Rule of thumb: if you are using cryptographic primitives directly (such as AES) you are rolling out your own crypto.