You shouldn't have any problem removing mcrypt and still have your data encrypted/decrypted the same as before so long as your Blesta system key remains the same.
Is there a reason it has to be a dropdown and not an input tagged as numeric and validated? If there aren't technical limitations to arbitrary lengths why limit it? Just default the number to something reasonable (30 days maybe).