It also does work over https: https://www.getsafeonline.org/themes/passwrdcheck/index.html
So I'm pretty sure this is just the fact they failed to setup the redirect. Rather than mocking them on Hacker News, we should just tell them they broke that part of their setup at some point and should fix it?
EDIT:
Tried to contact them, got a "The form you submitted contained the following errors
Missing Data.(DIFFERENT_IP)"
error which has nothing to do with the form I submitted. XD
Could someone contact them by their contact us page to get this fixed?