I'd also like to note that it is not just this admin that has been doing this. Every day people contact me because their accounts are compromised and I have to spend time fixing things.
In every bux type script the password is not hashed and is clearly visible to anyone with administrator or hosting access. So I urge everyone to please use unique passwords for sites they are going to be spending time or money on.
You can add a "warning" in the registration form ("use unique and different pass" or something like that)