Please for god sake
hash our passwords!!!

With a strong salt/pepper, please!
It is really brazenly to see my password unhashed in the url for the confirmation (in the email), so everyone could get this password!
I would suggest using Bcrypt as it's a very secure hash algorithm!
Regards,
Houssem.
Don't worry passwords are hashed using a secure algorithm ( I won't say which one! :p)
... that

1. You can say what hash function you use, cause it doesn't matter at all if it's good.
2. i got that link:
https://freecoin.online/wp-login.php?action=rp&key=MyPw&login=MyNameand this key was my password in plain text..not hashed...not encoded, just plain text...so think about it
I dont know what your end game is here. but a users PW is not being send to anyone.
that link has nothing to do with my faucet/service/website.