This deployment scans only hosts this project owns. It is here so that you can watch the instrument work and check its verdicts against your own run of it — not so that it opens connections to somebody else's server on a stranger's behalf, and the terms say so plainly. Run it yourself to scan anything else: the scan then leaves your machine, from your address, and nothing about it passes through here. What a scan sends, and what this keeps is written out in full.
Running a scan needs JavaScript, because the result is fetched and rendered in the page. The same scan is available from the command line tool in the repository, which needs nothing but Go.