I just started testing my Paypal Direct Checkout process last night and I noticed that there is no verification being done for the CVV2 code, nor that the Billing Address is even correct. PayPal's APIs provide these verifications and when I go to the PayPal site to view the transactions, PayPal states that the CVV2 and the Address were wrong, however, the PayPal Direct plugin doesn't appear to do anything with this info when it's received.
This is a MAJOR concern as we can not launch the site until I have resolved this issue (I can't have nop marking something as paid when the correct info wasn't even used). Has anyone else noticed this? I'm going to take a look at the code later tonight, but if someone else has already solved the problem, then I'd love it if you could share your results. Otherwise, I'll post back here again once I've fixed it myself.
https://cms.paypal.com/uk/cgi-bin/?cmd=_render-content&content_ID=developer/UK_Website_Payments_Pro_UK_DP
Thanks!
Dan