Right, that's what GP said in the comment you replied to: that he probably should not use that VPS provider.

And yes, password-reset emails may also be a concern (not as severe, though, if reset emails are single-use and have short TTL).

