Yup, it's run by one of the Monero developers. I also heard (but can't verify) that only you can access your funds when you use them.
Fluffypony runs the site - he's one of the leading XMR devs. Sure, many thousands of dollars have been stolen using MITM attacks due to crappy vpns and poor openssl updates... A user here named
Birr lost a LOT of money there, so be wary, i'm quite sure he will chime in.
Edit - Shameless plug for physical original Monero coins here -
https://bt.irlbtc.com/view/1828463.msg18204098#msg18204098Thanks!
A bit over 7k xmr, worth about ninety three thousand dollars at the time of theft.
Your humble correspondent is bloodied but unbowed, as the expression goes.
Been using command line daemon and wallet on linux ever since.
At least one other person lost a significant amount, but I don't remember how much.
Fluffy would have done well to require 2FA on that site, instead he had a laser focus on being user friendly to promote monero use and make it easy for newbs to get in... well, newbs make mistakes. Mistakes like
using Fluffy's web wallet.