When you log in, your username and password are sent in clear text over the internet.
This is unsafe:
- sniffed passwords/admin accounts can be used to configure mailwasher server
- user credentials are often the same as the domain, because of the numerous passwords everyone online has
- sniffed accounts can be used to TRY to compromise the server it is installed on
It would be good to have it on https support, at least for the login.