Oh, a website that asks for passwords to see if your passwords have been stolen, what a nice idea!
What are they going to do with it? Knowing a password is useless if you don't know what it's the password to.
Stolen passwords can be added to ‘“password dictionaries” of known passwords. Such dictionaries are traded on darknet to hackers who use them for dictionary attacks.
Imagine you are a victim of infamous LastPass leak, and your vault with all your passwords to your banks, to websites that have your personal information (your shipping address at Amazon, your mobile phone number, your SSN, your W-2s from your employer’s payroll provider, … ) is now in hands of hundreds of hacker teams ranging from bored school kids to Russian military. They bought your vault on darknet, and all that stops them from taking a full advantage of passwords stored in the stolen LastPass vault is your master password that was used to encrypt the vault. You can either use your own imagination to picture what could happen to you if the hackers succeed in guessing the master password, or read fiction books and watch popular movies to get artistic picture.
Now, LastPass uses pretty strong AES-256 algorithm, and if you followed LastPasses advice carefully and had a very long random master password - you are relatively safe.
Your laptop most likely has hardware AES-256 acceleration. Modern Intel and AMD CPUs can decrypt AES-256 at speeds of order of magnitude of 10 GB/s. Serious hacker can have access to hardware that is several orders of magnitude faster than a modern laptop.
If your vault was 100KB long (thousands of passwords), hackers can apply brutal force, testing 100,000 passwords per second using a laptop, and maybe 10 million passwords per second using a farm of 100 servers.
If your memorized master password was 20 characters long, contained upper and lower caps, digits and special characters (96 ANSII characters), the attacker would have to try about 10e40 passwords before breaking the vault. This would take 10e33 seconds - longer than the age of the Universe.
However, if your master password ends up in the “password dictionary”, the job would become much easier. Huge dictionary of 1 billion passwords can be checked in few minutes, or even faster, because they probably do not have to decrypt the entire 100KB vault to test validity of each password ( depends on vault’s data structure).
You should not trust your passwords to anyone. Definitely not to some “reputable” password checking website. You do not know who is behind it, and even if you know the owner personally - the website can be hacked tomorrow, JavaScript altered, etc. You should not trust moderators of this forum - you probably do not even know their real names. With all respect, you should not even trust Dave when it comes to your cyber security.
In my opinion, the advice that was given by the OP was unprofessional. What’s even worse, the mistake was not corrected despite people pointed out the obvious risk of checking passwords online.