My organization has five sites with eleven DCs. I ran some independent tests with Howard and his code is solid. Machine account password age information didn't seem valid for some machines because they aren't changing passwords for many reasons:
RAS Workstations
VPN Workstations
Wireless Workstations
VLAN Changes
Site Changes

Thank you Howard!