Unsure why this guy keeps posting FUD.
Here are his "3 claims"...
#1 .. "you store passwords in plain text"
Answer: No. We do not store passwords unencrypted. That would be stupid. We send a temporary system generated password to the user on signup (and store that encrypted). The user will need to change the temporary password when logging in for the first time. (This helps us to validate that users who login can get our emails)
# 2 .. "you allow bitcoin deposits before they get 1 confirm"
Answer: No. Our minimum confirms for BTC is 3 confirmations. No idea where he got this idea from, he provided no further details. Most of the other coins we list require more than 3 confirms.
# 3 .. "hackers can know you are using PHP"
Answer: This isn't a security issue. Most websites these days are either PHP or NodeJS. Just knowing the main programming language doesn't really give hackers much of an edge.
In any case, thanks for the attention!

- Mike