Forum Moderators: coopster
In the event that your host (if you host yourself this paragraph can be ignored) has uninstalled PHP or modified configuration that PHP is not parsed, then you'd have a problem. Although during that time, the script wouldn't work, and you could always change the p/w in the file afterwards.
The only way they'd be able to read the source was if they had access to the server itself, at which point, a password in a script is the least of your worries.