I assume that you're doing client side encryption here right?
To try and guarantee that the Javascript you are delivering is from your server and not MITMed 'by the man', doesn't everything need to be over TLS/SSL and certificate pinning needs to be in place?
I'm no security expert, but there are plenty around who can confirm or deny that.
Edit: The password is being sent in a POST without any encryption to protect that request, or am I missing something?