The level of liability that a store owner opens themselves up to by storing credit card numbers is huge. Of course storing CC numbers and passwords anywhere that are not encrypted is a huge security hole.
To be frank, I strongly recommend against this practice, especially if you are using open source code. You can easily issue credits through payment gateway providers such as Authorize.net, Versign, and TransAction Central....



Joined: 08/12/2007