The title should probably read "Why relying only on client-side verification is bad".
I don't think the author is suggesting that doing client-side verification is a bad thing in itself.
"Why client-side verification is bad.."
(rather than the title you suggest)
"to my surprise discovered that it did client-side verification of the words"
(rather than "...that it didn't do server side verification")
However, in support of your position; in his opening paragraph, he does say "you can't rely on it to do authentication", rather than "you shouldn't use it to do authentication".
"It's not wrong to use client-side methods to do initial validation, but it's wrong to trust that validation on the server side."
"I probably wasn't very clear on my feelings though."