Here are some common JavaScript vulnerabilities:
!Snip!
I haven't heard about those vulnerabilities before but after reading your posts I also somehow got the feeling that Thormixer might have considered user's privacy and anonymity as well and that's why they haven't added JS. However, I still believe that main reason to disable JS was to improve the performance of the site.
Vulnerability are usually not bulletproof to solutions, and as such, it's important we know that all vulnerabilities as it relates to writting codes sure have a way they can be avoided or bypassed.
So, I really do not think that any of such vulnerabilities is the reason why Thormixer has or did not use or include js in their code base, but it's just as you have said, they possibly just want to keep everything simple and easy for their users, which actually is very good if you ask me.
Mixers do not provide any other kind of special service aside mixing bitcoin, so there is actually no need for some kind of complicated designs and functionalities, the guys behind Thormixer probably understands this very well, which is why they possibly have choosen to keep things as simple as it can be.