There is a way to remove the password encryption, and show the passwords in plain text in the database
Anyway, this site honestly looks sketch as fuck and I wouldn't be surprised if this is what he did, should have at least made it look real if you wanted to do this bruh.
I realize that you can get it through the db but I thought that he meant simply going on to the Admin-CP and just get it. That's not possible. But i guess you do have a valid point.