Results 1 to 6 of 6

Hybrid View

  1. #1
    Join Date
    Aug 2011
    Posts
    4
    Plugin Contributions
    0

    help question PayPal Express vs Standard on nonSSL site?

    I’m trying to get a payment method going, and I’ve definitely seen the notices everywhere on ZenCart and in DrByte’s posts that make it very clear that Express is good and Standard is bad. However, I’m concerned about the “confirm order” page that customers arrive at after going through PayPal Express. The added expense of a static IP & SSL certificate is a bit more than my very small business can afford right now starting up, but I feel like having the customer’s name and address displayed on my site is something that really should have an https connection (I removed the login/register links from my site to stop the other opportunities for secure data to be entered/displayed).

    I just got off the phone with a support person from my (very excellent and honest) hosting service, who strongly recommended I not waste my money buying an SSL certificate from them at this point and instead just go with a PayPal solution that keeps all the sensitive data off my site and operates entirely on PayPal’s end. That solution appears to be Standard, not Express.

    So now I’m not sure what to do - I’m told here that Standard is just the evil twin of Express that I should stay away from, but are there any circumstances, like not wanting an SSL, where using Standard might be a better decision? Is a nonsecure order confirmation page not something I should be worrying about in the first place? I’ve been staring at this forum for hours all week and some things just get more confusing the more I read..

    Thank you in advance for any advice you can offer!

  2. #2
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: PayPal Express vs Standard on nonSSL site?

    Standard has no benefits over Express in terms of any of the issues you've mentioned. Express is by far the more reliable approach.

    What exactly is your concern about the information on your "non secure confirmation page"? What sensitive data are you specifically concerned about?
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Aug 2011
    Posts
    4
    Plugin Contributions
    0

    Default Re: PayPal Express vs Standard on nonSSL site?

    Thank you for responding. By "sensitive data" I mean the customer's full name and billing/shipping address that appear at the top of the Step 3 page - is this data not vulnerable when displayed like that on a nonsecure site?

  4. #4
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: PayPal Express vs Standard on nonSSL site?

    No more vulnerable than when the customer types it into the login or create-account screen themselves earlier in checkout.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Aug 2011
    Posts
    4
    Plugin Contributions
    0

    Default Re: PayPal Express vs Standard on nonSSL site?

    I mentioned in my original post that I did away with the login/registration features on my site so that there would be no entering of data by the customer except when they are on PayPal..Anyway, thank you for your help, I'm sure I'll figure something out.

  6. #6
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: PayPal Express vs Standard on nonSSL site?

    Quote Originally Posted by cozyfolk View Post
    I did away with the login/registration features on my site so that there would be no entering of data by the customer ...
    So you could just delete the output from the confirmation screen too if that's a major concern to you.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. v139h Paypal Websites Payment standard IPN VS Paypal Express Checkout
    By WiccanWitch420 in forum General Questions
    Replies: 1
    Last Post: 3 Dec 2013, 09:22 PM
  2. Change from PayPal Standard to PayPal Express
    By Forum5 in forum PayPal Express Checkout support
    Replies: 1
    Last Post: 14 Apr 2011, 06:52 AM
  3. Paypal IPN Standard vs. Paypal Express
    By Berserker in forum Built-in Shipping and Payment Modules
    Replies: 3
    Last Post: 30 Nov 2009, 06:23 PM
  4. PayPal Standard vs PayPal Express Checkout
    By incircolo in forum Built-in Shipping and Payment Modules
    Replies: 3
    Last Post: 13 Aug 2009, 12:55 PM
  5. Change from Paypal Express to Paypal Standard
    By Bikerdave in forum PayPal Express Checkout support
    Replies: 1
    Last Post: 13 Jul 2008, 04:01 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg