I've only encountered Stripe as a customer, and only once, so it may just be that the merchant (Browserling) was implementing it wrong. But the merchant asked me for my credit card number on its own domain, without SSL. I trusted the site enough to believe it really used Stripe (the only verification was text saying so), and that it was secure, but there was nothing there to prove it to me.
So maybe Stripe is secure, but they might want to work on appearing more trustworthy.
When I've used PayPal as a customer, it asked for my credit card on its own domain, not the merchant's. Doesn't that insulate the merchant from handling credit card details at least as well as Stripe's API does?