How sending clear login and passwords to a third party website is ever a good idea?
For example, "password" hashes to "5DAA6", and the resulting bucket[1] lists secure hashes of several dozen passwords.
The client then generates another hash of the password (eg. "1E4C9B93F3F0682250B6CF8331B7EE68FD8"), and checks if that secure hash is in the bucket (it is, "password" has been compromised at least 3,730,471 known times).
Why would it need to send the passwords?
Could it not download a list of a every site that has ever been hacked along with their domain list and the date of the hacking, then warn you if you have a saved password for one of those domains that was saved before the domain was hacked?
Because that's what it does.