Randomness, bias, and why the size of the list is the whole answer
Most random word generators call Math.random. Browsers do not promise it is uniform, do not promise it is unpredictable, and are explicitly permitted to implement it with a fast generator whose output can be reconstructed from a handful of samples. For a party game that is fine. For anything you intend to use as a secret it is not, and the two uses sit on the same page in most tools without the difference being mentioned.
Reaching for real cryptographic randomness is necessary and not sufficient, because the usual way of turning a random number into a list index reintroduces bias. Taking a 32-bit value modulo the list length is only uniform when the length divides 2^32 exactly, which for a list of 1,278 words it does not. The remainder means the first few hundred words come up very slightly more often than the rest, forever. The fix is rejection sampling: discard the values that fall in the incomplete final block and draw again. It costs an occasional extra draw, and it makes every word genuinely equally likely.
That matters because the strength of a passphrase is arithmetic over the list, and the arithmetic is only true if the draw is fair. Each word contributes log2 of the list size in bits. Drawing from 1,278 words gives 10.32 bits per word, so eight words is 82.6 bits. Diceware, which draws from 7,776, gives 12.9 bits per word and reaches 77.5 bits in six. Eight words from a smaller curated list therefore beats six words from a larger one, which is the trade this list makes deliberately: every word is short, common and spellable from hearing, because a passphrase you cannot type is a passphrase you replace with something weak.
Words are dealt rather than rolled. Each draw removes the word from the pool, so a list of twenty contains twenty different words and a game deals its whole deck before anything repeats. A passphrase cannot contain the same word twice either, which matters because repetition would make the real entropy lower than the number being displayed.
One deliberate omission is worth explaining. Any draw here can be reproduced from a short code, so a class or a table of players can share one code and get identical words with no account and no server. The passphrase mode is structurally excluded from that: the function that generates it takes no seed parameter at all, so the sharing mechanism cannot reach it. A passphrase anyone holding a code can reproduce is not a secret, and the safest way to enforce that is to make it impossible to express rather than to remember not to do it.