Why can anyone with a link to the credential add it

Hey everyone so tbh I don’t know much about blockcerts but my school used it for high school diplomas and before graduation they asked us to make accounts (or passphrases) and then add the school as issuer. I did that and noted down my phrase but i lost my cell phone and I had to log in onto the app first i tried many time with the passphrase i wrote down but it gave an error saying that it was invalid or incorrect passphrase but after checking the passphrase through the Bip39 word list and everything I got a passphrase that let me access the account but when i entered I was surprised that there was no issuer there already added but I tried to open the URL link to import my credential and it worked and i got my credentials imported then just to confirm that it was my account and i did not accidently logged into someone else’s account I got another mobile phone downloaded the app made a passphrase and without adding any issuer i added a credential directly from the URL and it went through so how is it safe like this means anyone who has the URL can add and something that is bothering me so much is how is this secure I mean if you go to Ian Coleman’s BIP39 tool and start messing around, you can literally generate working passphrases that give access to valid wallets. Sure, it’s almost always just random wallets with nothing inside, but the fact that you can technically stumble upon a real one makes it feel insecure. Another thing now I am feel very paranoid that the first account i added my credentials into was not mine and now my credentials are in some one else’s wallet/account so can you delete credentials from an account