Eric,
Basically, if the bad guys have root access to your server then they already own it, and it really doesn't matter that they can then get easy access to your Plesk admin password. Even if that wasn't possible they would be able to change it to anything they wanted and would therefore know it.
Or even if all of that was prevented, they could cause a password reminder/reset email to be sent. And if that was just a link (no plaintext password) they could intercept the email, even if it was to an external address, and follow the link.
There's no way to win here. If they have root they have everything.