@dbltoe
Yes I do understand your frustration.
Some of the codebase in Zen is quite old now. What that has meant is that code hacking has actually pretty straight forward and with a bit of php knowledge people could get modules to work. That resulted in a wide range of powerful modules that did all kinds of things and 'worked fine' . Which was a good thing. Particularly with the ethos that most modules are free.
The structure and security of these modules is not guaranteed. I know that I am as guilty as anyone of producing code that 'worked' but had its flaws.
I am not one of the developers so what I say next is just my opinion.
PCI compliance has changed the playing field. We do not need to discuss here whether that is a good or bad thing and what the flaws in the present situation are because that has been discussed elsewhere. But it is important to understand that the playing field has been changed.
It would not be all that responsible for developers of a widely used platform to continue to produce a software that facilitated people adding modules that invalidated the PCI compliance that they have worked so hard towards.
We all want to see Zen as a inherently compliant platform. We all want to see all the modules as inherently compliant. That is just part of the new world that we are operating in. Unfortunately, that does mean that there is an onus on module authors to understand a bit more about how this all works, otherwise the module may not function.
There are lots of people out there who have put in a huge amount of work trying to help with modules they know and love but did not actually write. This is one of the failings, and great strengths, of Zen, and perhaps this form of open source development. The original authors are not around any more. The management of modules has been picked up by others. So, re-writing a module is really hard work for those other people. In some cases it may just be easier to start from scratch then wade through someone else's code, which may or may not be comprehensible in the first place.
A good example of how it works when the author is still around are all Conor's mods, for instance Ceon URI rewriting. They were updated by the author and work on 1.5. Lovely.
The orphaned modules, where the original author is not around are much more problematic. And, yes, I can understand the frustration. There is one module out there that I am having a personal nightmare with. But, it really is not the developers problem that there is no-one available who really really understands the module's code well enough that updating it reasonably simple.
The problem is the level of understanding of a module's code not the changes in 1.5. Other platforms insist that an 'active' module has active 'Maintainers' ( I am using Drupal language here ) and if not then they are flagged as 'Not Actively Maintained' . I wonder how many modules in the free software add-ons section would actually have an active maintainer at the moment? Perhaps that is something that would be a good idea to implement.
Also, I have to say that this is going to change again if 2.0 is released. Modules are going to need to be re-worked again. Without any prediction about when that might happen it is hard to judge what the best line of approach is regarding 1.5.