Well, I guess I could always store a md5 of password somewhere...
But unless you wanna have to type it in every time you access the webconsole, then I'd still have to leave it in plain somewhere. And if you actually do type it every time, then there's no use in storing it at all. *Geez*, I could also not store the ip address nor port and host a public TremWebRemoteConsole for every ServerAdmin (providing their own ip, port and rcon password) to use ! But that's not the point now, is it ?
Very worse that could happen is other users from your WebServer accessing your file. If this happens, either that server is poorly configured, or they have so much power they could shutdown your TremServer anyways.