Earlier quoted context omitted.
>throwing PCI compliance and SSL encryption out the window If they were using Stripe or similar, then they don't have access to your credit cards. Only the last four digits and expiration.
Yet without HTTPS anyone changing or entering new credit card info is at risk on this site. There's also personal information like where to find spare keys and stuff; it should be a lot more secure than this.
Not defending the rest of the site. Just pointing out what I felt was not a problem. There are plenty of problems to go around, though.