If you email is hacked, that can be used to reset the password, so it's no less secure unless another factor is required to then change your password (which most services do not). You do have a point about it potentially exposing your email password to a keylogger though.
However, you also need to consider how most people use passwords. Often they have the same password (or very similar password) for many services. Other people essentially use the password recovery flow as their login mechanism. This is more secure and usable than that.