Comment by zmmmmm
The whole site is fundamentally a security trainwreck, so the fact its database is exposed is really just a technical detail.
The problem with this is really the fact it gives anybody the impression there is ANY safe way to implement something like this. You could fix every technical flaw and it would still be a security disaster.