Either way, like the OP states, sending passwords in the clear is just plain bad policy. And it's a clear indication of sloppiness on part of the website creator.
Standard policy for most websites if you forget your password is they send a reset link or a temporary password to your email. Both methods require you logging on to the website and entering a new password immediately.
If you're really worried about (in)security,
just refer to the master. His blog makes interesting reading (or uncomfortable reading if you're one of those who has any illusions about the competance of TSA).