Well, passwords sent in cleartext over a unsecure connection is always an concern. Whether its a problem for you can only you answer, but luckily its very easy fix. Ie. in the IIS manager you can specify that all requests to /composite/* should be over https.
↧