Not sure if it's relevant here, but I want to point out that just because you received it in plaintext doesn't mean they store it in plaintext.
So if you change it immediately to something more secure, and it might not be a security risk after all.
So if you change it immediately to something more secure, and it might not be a security risk after all.
And on top of all that, sending it plaintext via email, itself a largely open format, means they've broadcast it to all kinds of other potentially bad actors.
Plus it indicates (to me) a questionable grasp of security, not a great sign for a VPN provider.
Its just wrong.
It'd be acceptable if it was a random password generated for email-auth reasons. Not acceptable if you're setting the password.