Earlier quoted context omitted.
> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…
They "clearly aren't up to the responsibility"? Paypal has one of the larger application security teams in SFBA. You've decided they're not qualified because someone reported a self-XSS and Paypal didn't freak out? Did you read downthread about the actual "2FA" feature this team "bypassed"?
It's not the size that matters, but how you use it that counts.