I’ve also added a warning regarding cards’ JS, following your comment here. Can you comment on whether returning to the Deck screen is enough to purge unwarranted JS from the webview? It seems to work this way on Desktop, according to my tests, and on AnkiDroid, it shouldn’t be the issue in the first place, as the current reviewer resets the webview on each card flip, afaik. However, I don’t know anything about how this is treated in Anki Mobile.
That might be, but as described in this comment, a password manager by itself is not a perfect solution either. There are also cases when retrieving the information quickly is important, and nothing can beat having it directly in your memory.