Although the session variables are stored on the server, the only real security is the session cookie, which, if hacked, will allow any other visitor to start the same session, therefore, will be able to see the page in the same way as the original visitor .
A session cookie is just a random string generated by PHP, and is available for viewing in plain text (if you are not using SSL) for any "person in the middle", which allows you to capture the session of others.
Saving any confidential data in every way is a potential security issue, so today you need certified PCI-DSS hosting and environment to process credit card information. This is applicable even though you never βstoreβ it on your server while the flow of information through your equipment you need to meet the requirements of PCI-DSS.
The reason for this is that it will always be available at some point in the computer's memory, and the infected computer may have malicious software that could identify this data and distribute it to bad intentions.
jishi source share