
For the passport input field:
Well , in 2019 there is a tricky way .. you can generate forms with JavaScript / jQuery over a div and you can put them on READ ONLY. If the attacker will disable JavaScript then the gen code will not work then will not be any form at well...
Basic security for mr. Hacker
i already check this on xampp /windows 10 with firefox and changing with the inspector from type="password" to type="text" the script will "repair" again the things
in EDGE works buggy : when with Inspector i modify that stuff then all form is strip then inserted above html document