Yeah, I'm no PCI expert, but I'm pretty sure that storing the credit card number in the DB (un-encrypted/un-masked) is a no-no and in the very least is a bad idea. But Massimo's just illustrating how to use Authorize.Net
For those who are interested in PCI-DSS https://www.pcisecuritystandards.org/security_standards/documents.php BTW, Massimo you can put GPL in as the license for the contrib/AuthorizeNet.py - The original source declared it GPL last month (and linked to your version) http://www.johnconde.net/blog/integrate-the-authorizenet-aim-api-with-python-3-2/