Finally, the remote_password being blank is by design, passwordless keys are less of a security threat than any weak user supplied password. They serve their purpose in the real world amongst private networks.
EDIT for 'and in the command line.': Reviewing the command history doesn't show the libssh2 or php5 commands being executed on either BSD or debian.
EDIT for your comment 'in the config file': If your suggesting that the software is insecure by the fact that the user leaves the config file after usage, then perhaps that user should be allowed in the environment to begin with.