Not if you are using their cloud version instead of the open source self hosted server.
The code they are running does have to be the code they are publishing.
And if someone compromises their cloud servers, they could also modify it to log the passwords entered.