This can be a long windy answer and I could talk all day about but in short, the only way to know is to hire a PCI compliance audit company which will audit your code be it a cart, your system..etc…
PCI is a huge touchy subject and goes into many gray areas. It does not just include your cart system, but also any computer environment that interacts with the site. For example, you’re logging in remotely from your office to check on sales. Well that would mean your office computer network would also need to be in PCI compliant.
But the bulk of it is if your database does NOT store sensitive information such as the customer’s credit card, then you’re 80% in the clear already. The rest is just trivial issues to handle.
This properly does not specifically answer your question but I hope it gives you a little insight on how complicated PCI can get.