<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GetWPress &#187; E-commerce</title>
	<atom:link href="http://www.getwpress.com/e-commerce/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.getwpress.com</link>
	<description>Just another WordPress site</description>
	<lastBuildDate>Thu, 03 May 2012 20:27:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>WordPress Shopping Cart PCI Compliance</title>
		<link>http://www.getwpress.com/e-commerce/wordpress-cart-pci-compliance/</link>
		<comments>http://www.getwpress.com/e-commerce/wordpress-cart-pci-compliance/#comments</comments>
		<pubDate>Mon, 24 May 2010 17:14:20 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[E-commerce]]></category>

		<guid isPermaLink="false">http://getwpress.com/?p=149</guid>
		<description><![CDATA[<p>There&#8217;s a set of requirements called the Payment Card Industry Data Security Standard (or &#8220;PCI DSS&#8221;) and it was developed by the PCISSC &#8211; (the Payment Card Industry Security Standards Council) These requirements are designed to provide a standardized set of consistent security measures for merchants to follow that are handling credit card transactions. The [...]</p><p>The original post is titled <a href="http://www.getwpress.com/e-commerce/wordpress-cart-pci-compliance/">WordPress Shopping Cart PCI Compliance</a> , and it came from <a href="http://www.getwpress.com">GetWPress</a> . </p>]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a set of requirements called the Payment Card Industry Data Security Standard (or &#8220;PCI DSS&#8221;) and it was developed by the PCISSC &#8211; (the Payment Card Industry Security Standards Council)</p>
<p>These requirements are designed to provide a standardized set of consistent security measures for merchants to follow that are handling credit card transactions.</p>
<p>The standard includes 12 requirements for maintaining a secure operation:</p>
<p><strong>Build and Maintain a Secure Network</strong></p>
<ul>
<li> Requirement 1: Install and maintain a firewall configuration to protect cardholder data</li>
<li> Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters</li>
<li> Protect Cardholder Data</li>
<li> Requirement 3: Protect stored cardholder data</li>
<li> Requirement 4: Encrypt transmission of cardholder data across open, public networks</li>
</ul>
<p><strong>Maintain a Vulnerability Management Program</strong></p>
<ul>
<li> Requirement 5: Use and regularly update anti-virus software</li>
<li> Requirement 6: Develop and maintain secure systems and applications</li>
</ul>
<p><strong>Implement Strong Access Control Measures</strong></p>
<ul>
<li> Requirement 7: Restrict access to cardholder data by business need-to-know</li>
<li> Requirement 8: Assign a unique ID to each person with computer access</li>
<li> Requirement 9: Restrict physical access to cardholder data</li>
<li> Regularly Monitor and Test Networks</li>
<li> Requirement 10: Track and monitor all access to network resources and cardholder data</li>
<li> Requirement 11: Regularly test security systems and processes</li>
<li> Maintain an Information Security Policy</li>
<li> Requirement 12: Maintain a policy that addresses information security</li>
</ul>
<p>For WordPress your E-commerce options are limited, and for a PCI Compliant shopping cart, they&#8217;re limited even further.</p>
<p>There is no way in a million years you should consider developing a new site using ANY shopping cart that is not willing to be compliant or in my (non legal) opinion, you&#8217;re setting yourself up for a lawsuit.</p>
<p>This list of WP shopping carts and their PCI compliance info will grow over time&#8230;</p>
<ol>
<li><a href="http://docs.shopplugin.net/" target="_blank"><strong>Shopp</strong></a> &#8211; The are compliant, and they are <a href="http://docs.shopplugin.net/PCI_DSS_Compliance" target="_blank">willing to say so</a>, which is why they are our current platform of choice.</li>
<li><strong><a href="http://www.phpurchase.com/" target="_blank">PHP Purchase</a> &#8211; </strong>We&#8217;ve never used them but they say they&#8217;re compliant right on their home page.</li>
<li><strong><a href="http://www.cart32.com/solutions.asp" target="_blank">Cart 32</a></strong> &#8211; We&#8217;ve never used them, but they do claim compliance.</li>
<li><strong><a href="http://vevocart.com/" target="_blank">Vevo Cart</a> &#8211; </strong>They DO claim to be compliant</li>
</ol>
<p><strong>These carts are either Non Compliant or simply not addressed on their sites:</strong></p>
<ol>
<li><a href="http://www.instinct.co.nz/e-commerce/" target="_blank"><strong>WP Ecommerce</strong></a> &#8211; Although we HAVE <a href="http://getwpress.com/software/pci-compliant-cart-wp-ecommerce/" target="_blank">tested their compliance once before</a> and found no issues,  they now seem to fail test &#8211;  They refuse to offer any statement about compliance here &#8211; <a href="http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:http://www.markettheme.com/+PCI#hl=en&amp;q=site%3Ahttp%3A%2F%2Fwww.instinct.co.nz%2F+pci&amp;aq=&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=&amp;pbx=1&amp;fp=f36d3c22a357aa92" target="_self">Check</a> although there are lots of interesting discussions though <a href="http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:http://getshopped.org#hl=en&amp;q=site%3Ahttp%3A%2F%2Fgetshopped.org+pci+compliance&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=&amp;pbx=1&amp;fp=f36d3c22a357aa92" target="_blank">here</a></li>
<li><strong><a href="http://www.wpauctions.com/" target="_blank">WP Auctions</a></strong> &#8211;  No mention of PCI Compliance &#8211; <a href="http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:http://www.markettheme.com/+PCI#hl=en&amp;q=site%3Ahttp%3A%2F%2Fwww.wpauctions.com%2F+pci&amp;aq=&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=&amp;pbx=1&amp;fp=f36d3c22a357aa92" target="_blank">check</a>.</li>
<li><strong><a href="http://www.tipsandtricks-hq.com/wordpress-estore-plugin-complete-solution-to-sell-digital-products-from-your-wordpress-blog-securely-1059" target="_blank">WP eStore</a> &#8211; </strong>No mention of PCI but they use something called instant digital product delivery &#8211; <a href="http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:http://www.markettheme.com/+PCI#hl=en&amp;q=site%3Ahttp%3A%2F%2Fwww.tipsandtricks-hq.com%2F+pci&amp;aq=&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=&amp;pbx=1&amp;fp=f36d3c22a357aa92" target="_blank">check</a></li>
<li><strong><a href="http://www.shopperpress.com/" target="_blank">Shopper Press</a> &#8211; </strong>Has more than 20+ payment   gateways, but not PCI compliant?  <a href="http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:http://www.markettheme.com/+PCI#hl=en&amp;q=site%3Ahttp%3A%2F%2Fwww.shopperpress.com%2F+pci&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=site%3Ahttp%3A%2F%2Fwww.shopperpress.com%2F+pci&amp;gs_rfai=&amp;pbx=1&amp;fp=f36d3c22a357aa92" target="_blank">check</a></li>
<li><strong><a href="http://www.markettheme.com/ " target="_blank">Market Theme</a> &#8211; </strong>No mention of PCI Compliance &#8211; <a href="http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:http://www.markettheme.com/+PCI#hl=en&amp;q=site%3Ahttp%3A%2F%2Fwww.markettheme.com%2F+pci&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=&amp;pbx=1&amp;fp=f36d3c22a357aa92" target="_blank">check</a>.</li>
<li><strong><a href="http://tribulant.com/products/view/10/wordpress-shopping-cart-plugin" target="_blank">Word Press Shopping Cart Plug-in</a> &#8211; </strong>No mention of PCI compliance &#8211; <a href="http://www.google.com/search?sourceid=chrome&amp;ie=UTF-8&amp;q=site:http://www.markettheme.com/+PCI#hl=en&amp;q=site%3Ahttp%3A%2F%2Ftribulant.com%2F+pci&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=&amp;pbx=1&amp;fp=f36d3c22a357aa92" target="_blank">check</a>.</li>
</ol>
<p>In the comments below, please leave any links to compliance info for anyone you come across, and I&#8217;ll update this list. Likewise, if you have information about anyone that&#8217;s NOT compliant, that would be helpful too.</p>
<p><a href="http://instinct.co.uk" target="_blank">WP Ecommerce</a></p>
<p>The original post is titled <a href="http://www.getwpress.com/e-commerce/wordpress-cart-pci-compliance/">WordPress Shopping Cart PCI Compliance</a> , and it came from <a href="http://www.getwpress.com">GetWPress</a> . </p>]]></content:encoded>
			<wfw:commentRss>http://www.getwpress.com/e-commerce/wordpress-cart-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>PCI Compliant Cart for WP e-commerce</title>
		<link>http://www.getwpress.com/software/pci-compliant-cart-wp-ecommerce/</link>
		<comments>http://www.getwpress.com/software/pci-compliant-cart-wp-ecommerce/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 14:16:56 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[E-commerce]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://getwpress.com/?p=85</guid>
		<description><![CDATA[<p>We are happy users of the WP e-commerce shoppping cart not only for our own site but we use it often for clients as well. Recently, one of our customers told us that they were being required by their credit card company to pass a certification test verifying that their website was PCI compliant and [...]</p><p>The original post is titled <a href="http://www.getwpress.com/software/pci-compliant-cart-wp-ecommerce/">PCI Compliant Cart for WP e-commerce</a> , and it came from <a href="http://www.getwpress.com">GetWPress</a> . </p>]]></description>
			<content:encoded><![CDATA[<p>We are happy users of the <a href="http://www.instinct.co.nz/e-commerce/" target="_blank">WP e-commerce</a> shoppping cart not only for our own site but we use it often for clients as well.</p>
<p>Recently,  one of our customers told us that they were being required by their credit card company to pass a certification test verifying that their website was PCI compliant and wanted us to attend to it.</p>
<p>The company doing the compliance check was called <a rel="nofollow" href="https://www.trustkeeper.net/esp/Login.public?cookiets=1232719765216" target="_blank">Trustkeeper</a>, and I&#8217;m very proud to report that right out of the box, with no changes on our part related to their cart, <a href="http://www.instinct.co.nz/e-commerce/" target="_blank">WP e-commerce</a> passed the PCI compliance test with flying colors.</p>
<p>I don&#8217;t pretend to be an expert on PCI compliance, but I can tell you that we had no problem passing the test using the WP e-commerce software. We did have some server configuration changes, but those were unrelated to the WP or the cart plugin.</p>
<p>If you&#8217;re a WordPress lover and you&#8217;re in need of a shopping cart too, this one will meet your needs&#8230;   Please tell them that Scott sent ya!</p>
<p>The original post is titled <a href="http://www.getwpress.com/software/pci-compliant-cart-wp-ecommerce/">PCI Compliant Cart for WP e-commerce</a> , and it came from <a href="http://www.getwpress.com">GetWPress</a> . </p>]]></content:encoded>
			<wfw:commentRss>http://www.getwpress.com/software/pci-compliant-cart-wp-ecommerce/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

