Security issue-Visible passwords in Dashboard needs immediate attention
Coming from different managed hosting, I just joined cloudways, only to be surprised that sufficient security for protecting passwords is not in place. I can see the passwords are visible to me but also to the support agents that have access to the same area and hence openly visible to them. They can see Wordpress password ( which is not issue, as they told me it is default one and if changed in wordpress admin, will not be reflected here). My biggest concern is the sensitive passwords for SQL database and application credentials. The eye icon placed next to passwords can reveal them to me but also to the support agents. I don't want to doubt anyone good intentions but the best practice is to keep them invisible even to me. If I forget the password, I will go to the same area to update them without being able to see them ( and a password change should notify me as well). The current way is not a fool proof security and can be a potential risk to the cloudways customers. I think the cloudways should take an immediate notice of this as being a security conscious company.....
