JSWeb - its quite right what you say about not using offline payment methods as you can be open to hack, and its email option weakspot and to use payment gateways rather then this mod

however, i do have a different email address in mine, so if anyone did get access to my email, they dont have access to the email they will only get the order details. The CEON details are emailed to a completely different email address not connected with by domain.

If you are on shared hosting then i wouldn't even consider using the offline payment

Rob