Is it paranoia to have proper security practices? You should strive to be excellent in everything you do. I do not think that targeting the GP with an ad hominem attack is a valid argument.
Ok sure, but you're moving the goalposts. The OP was talking specifically with respect to using a non client side password generator. As a joke it is funny, but only a fool would use a password generator that can't be audited and that may be logged.
But being able to inspect (theoretically even audit) the source, building (if necessary) and running it locally in some container/sandbox without network connection would be minimum reqirements for me.