I don't see how this tests the security of a setup if it is relying on a user submitting the password themselves. There is no way to protect against your own or the stupidity of others.
A reasonable use case would be demonstrating the weakness of a naive setup to a business that wanted to charge for access.
I've never seen a password protected paid-wifi set up. Using arp and spoofing your Mac address is often enough to pretend you are an authenticated client to most of these systems.
Where does it say that this is testing the security of a setup?
When something calls itself a security tool it's usually assumed (if not explicitly stated) that it serves some purpose for assessing the security of something. Otherwise it is just a tool made for making attacks easier to perform, which is pretty frowned upon.
It's a proof-of-concept to illustrate that users will put their passwords anywhere they are asked to and click through any warnings that may appear on their screen.