Sorry ... I don't trust it. Make the tool work without my ED login/pass and I'll use it.
You do recognize that the reason he sent you there is that it's open source, and has been vetted by many other coders playing ED, right? You can look over his entire codebase, and if you don't trust that installer gives you the same thing, you can grab the source yourself!
Sorry if this sounds a little combative, but in my experience, someone who is security conscious like yourself is also either a developer or can at least understand code to a degree.
And if your paranoid about having to read through every line of code, I'll bet it's worth it in the end. EDMC is just so much more accurate and effective than every other method, not to mention being the only way to get info on modules.
Also, there will never be something like you describe that doesn't need your user/pass unless Frontier enable log dumps of market and other data that we've been asking for. Otherwise nobody would need to use this app cuz EDDN could just grab all the data on all the markets on its own.
Sorry for the double post.