it would be as easy to hack, as JavaScript is run locally and the scripts are easily readable. You can use Ajax to create a LogIn System, which would be as secure as you have to run external scripts with a plugin too.
I think the best way at the moment is to host your App on a secure Host using https and either use a PHP Backend with Ajax or a system like clay.io