I propose that rather than supplyign the password with -p. that if -p is provided then a read command is issued instead to hide the password being typed. else this leaves the creds in plain text in the history etc..
I know you cna specify a file instead but the option for both is better