So SMTP isn't the only possible vulnerability. As a general rule, the less often passwords are disclosed the better. The only password that should ever be sent via email is one that you expect to change after the first use.

Yes, I'm being knee-jerk paranoid man. But experience keeps showing that when it comes to security it's better to assume the worst until someone can prove otherwise.

I'm not saying I'm going to unsubscribe because of it. I'd just prefer it weren't sent out if that's an option.