150,000,000+ database passwords, of which 99.9999%+ are from local development servers.
https://github.com/search?p=1&q=filename%3Awp-config.php+DB_...
Uh, the concept of localhost is not unique to Wordpress in the slightest.
Store credentials in environment variables.
If the organization is "closed" by default, i.e. it only rarely releases code to the public, this may not matter as much.
Even if it's just 0.1%, that would be still 150'000 valid passwords.