Ecommerce software home
Shopping Cart Software Forum for Ecommerce Templates
 
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

Find us on Facebook Follow us on Twitter View our YouTube channel
Search our site
Forum Search
Google Site Search
 All Forums
 Technical
 PHP (Unix / Linux / Apache) versions
 PayPal Advanced Checkout and PCI Compliance
Author « Topic »  

pauld
Ecommerce Template Expert

USA
567 Posts

Posted - 12/22/2025 :  09:33:19  
There are several previous threads - and some apparent confusion - about PCI requirements and the need for expensive, ongoing third-party penetration testing for stores that use the PayPal Advanced Checkout option in the cart’s PayPal Settings.

I am very skeptical of the recurring "VikingCloud" emails with the subject "Your PCI compliance status requires attention". These read like PayPal partner spam intended to extract recurring fees from merchants, rather than legitimate compliance notices.

PayPal’s current documentation (https://developer.paypal.com/studio/checkout/advanced) uses the term "Advanced Checkout" in the URL, while the page itself refers to "PayPal Expanded Checkout".

That page says:

"PayPal Card Fields is a PCI DSS service provider. Use the Card Fields integration to comply with PCI compliance when collecting card information from buyers."

So my questions are:

1 - Is the "PayPal Expanded Checkout" described on that page the integration currently used by the latest PayPal implementation in ECT?

2 - If so, doesn’t PayPal’s documentation indicate that PCI exposure for the store owner should be minimal, and effectively handled by PayPal?

I am trying to reconcile PayPal’s published guidance with those persistent "VikingCloud" emails I have ignored so far, which claim that recurring PCI audits and expensive third-party scanning are required.

Edited by - pauld on 12/22/2025 10:07:20

Vince
Administrator

43213 Posts

Posted - 12/23/2025 :  00:26:56  
Hi Paul
I believe that PayPal Expanded Checkout is just PayPal Checkout and yes, my understanding is that PCI exposure should be minimal. At the same time all the payment processors are kind of vague about this and I think this will be to avoid any legal comeback in case something does go wrong.

Vince

Click Here for Shopping Cart Software
Click Here to sign up for our newsletter
Click Here for the latest updater

pauld
Ecommerce Template Expert

USA
567 Posts

Posted - 12/23/2025 :  05:57:40  
Thanks for this, Vince.

We've been very happy with PayPal, but it's bit frustrating that their online documentation indicates that our ECT integration does "... comply with PCI compliance when collecting card information from buyers" yet we keep getting those VikingCloud "Your PCI compliance status requires attention" emails.

Edited by - pauld on 12/23/2025 06:07:10
  « Topic »  
Jump To:
Shopping Cart Software Forum for Ecommerce Templates © 2002-2022 ecommercetemplates.com
This page was generated in 0.02 seconds. Snitz Forums 2000