I posted to this older thread to make two points:
1 – I never received any response to what I considered a very important message I sent to that address. I e-mailed them because securitymetrics.com refused to declare one of our sites compliant as long as comments were active. Our solution was to turn comments off, and with that done, the site passed compliance. I think that might be important enough to warrant some sort of response – perhaps you or the security team disagree.
2 – I have a site that currently will not pass PCI complicance because https://www.securitymetrics.com told me tonight that (according to them) a vulnerability has been detected in the current version, and that the site will not be cleared until that vulnerability is resolved. Based on not receiving a reply from the security e-mail, as stated above, I thought I would try again here.
Can you tell me if there are ANY issue is being worked on that is related to PCI compliance? I need something more concrete to tell my client other than the fact that securitymetrics.com claims that WP is not PCI compliant, thus making their site non-compliant.
I appreciate your feedback.