1. No! Everybody can't see it.. Only if somebody do a man in the middle attack they possible can.
Also SMF also do some encryption before sending it so that should not be an issue..
Also the password is not stored in the forum system. only a hash of it.
2. That is a false positive. If you got the executable from my site.
It is called AV Hell, AV software these day create lot of havoc and report more false reports then real. And there is nothing small developers can do about that.
So often when something is reported you need to go to
https://www.virustotal.com/ and check. and if not a lots of the AV there are reporting it, It should be safe.
The problem is that you can not trust the reports of a single AV software because it is so easy to get flagged even for clean apps.