And what percentage would – like me – delete their account as soon as you send them a plaintext temp password?
You're living in the past if you think this is an acceptable practice. I don't care how trivial your web service is, if you're throwing my password around willy-nilly, I don't want you.