"Q.md5 - to one-way-encode passwords etc. in insecure websites before sending to the server"
This is a very bad advice which leads to a false sense of security:
1. A fast hash function is not desired for hashing passwords. (Bruteforce)
2. There are TBs of rainbowtables for unsalted md5.
3. If you use a salt, you would have to expose it clientsided.