> Solving this 'problem' would lose Kite money, so I don't fault them for not attempting it.
I think it really boils down to: what happens when their servers are compromised; how much liability will Kite assume for the lost IP? My guess is: None.
They don't even have a discoverable privacy policy, just a blog post! Going into the purchase pipeline, there's no service contract, just a "sign up for an account and give us your CC".
JavaScript projects tend to have more dependencies, but those tend to be smaller and will have a smaller index.
Solving this 'problem' would lose Kite money, so I don't fault them for not attempting it.