You're right. To me, it's not their use of (effectively) plaintext that is worrisome. It's that the developer characterizes base64 as "encryption", which tells me that they don't even understand the security implications. As an example of a non-worrying response, here's Pidgin's documentation on their choice not to encrypt passwords: http://developer.pidgin.im/wiki/PlainTextPasswords