No. The numbers that are XX'd out in admin are sent to you in an email when the order is confirmed.
It looks like you have a good handle on how horribly insecure this method is, and I'm sure you've tried to educate your client.
I'm not sure if site designers would have any legal responsibility if something went wrong, but I wouldn't work on a site like this, nor would I buy from one.



