I think not having the logins or password resets be secured by SSL is a bit more of a security issue that should be focused on; but at least with WordPress you can be assured they’re stored as hashes in the DB. So as long as packets aren’t copied along the path…
I digress, this is all important, but meh.
Edit: Doesn’t CloudFlare provide free SSL certificates now? The site should just be secured with CloudFlare. It’s a great service.