The time seems right to propose another change.
No password is required to change the email address of your
perlmonks account. This is an invitation for CSRF. The only
field in the form which makes it a *bit* safer is the userid field.
Could the form be changed so that you have to type in your password if you are changing the email address?