The maven's configuration allows for servers to include encrypted passwords as part of the config. http://maven.apache.org/settings.html#Servers We should update the plugin to read the encrypted profile data, to adhere to PCI and HIPAA rules, as well as just good operational practice.