Every script on your checkout.
Watched. Fingerprinted. Proven.
ScriptProof keeps an inventory of every script on your payment pages, records why each one is authorized, detects tampering, and turns it all into evidence you can hand to your bank — no agent install required to start.
No agent install 14-day trial Never touches card data
New unauthorized script detected on /checkout — 2 min ago
14
Scripts tracked
12
Authorized
1
Open alerts
PCI DSS v4.0.1
Supports req. 6.4.3 controls
Req. 11.6.1
Tamper & change detection
SHA-256
Every script fingerprinted
TLS encrypted
All monitoring traffic
Zero card data
Never requested or stored
Server-side
No load on your checkout
PCI controls supported (6.4.3 · 11.6.1)
fingerprint on every script
optional snippet — fails silently
cardholder data ever touched
Who it's for
Built for the people who actually get the compliance email
Whether you own the store, manage twenty of them, or wrote the checkout yourself — ScriptProof does the monitoring and the paperwork.

Small merchants
You run the store. We run the checks.
- Your acquirer sent an SAQ mentioning 6.4.3 and 11.6.1 — with no explanation of how to actually do it
- No security team and no time to hand-audit checkout scripts every week
- Verify your domain once; scans, alerts and evidence run on their own after that
- A monthly Evidence Pack you can forward to your bank instead of writing one yourself

Agencies & freelancers
Every client store, one pane of glass.
- Clients forward compliance letters from their bank and expect you to make them go away
- Dozens of storefronts, each with its own theme, apps and third-party tags
- Per-client alerts and white-label Evidence Packs turn compliance into a billable service
- CSV export and one dashboard across every site you manage

Developers
Provable diffs, not vague warnings.
- That tag you didn’t add? Marketing pasted it in six months ago — now it’s on the payment page
- Every script is fingerprinted with SHA-256, so “changed” is a fact you can verify
- Alerts carry before/after hashes and the exact header deltas, not just “something changed”
- Nothing to deploy: monitoring runs from outside, and the optional snippet is under 6 KB
The platform
Monitoring and evidence, without a security team
The controls auditors ask about — packaged for small merchants and busy agencies.
Requirement 6.4.3
Script Inventory
Every script on your checkout, fingerprinted with SHA-256, with a recorded reason each one is authorized.
Requirement 11.6.1
Tamper Detection
Content and security-header changes caught and flagged — the exact surface skimming attacks target.
Audit-ready PDF
Evidence Packs
A monthly paper trail of inventory, authorizations, change log and scan cadence to attach to your SAQ.
No account needed
Free Scanner
Point us at any checkout URL and get a one-page report of its scripts and headers in seconds.
The threat
Skimmers hide in the scripts you already trust
Since PCI DSS v4.0, requirements 6.4.3 and 11.6.1 ask merchants to maintain an authorized inventory of all payment-page scripts and to detect tampering with page content and HTTP headers at least weekly. That applies to small shops too — skimming attacks overwhelmingly target exactly the scripts these requirements cover. ScriptProof gives you the monitoring and the paper trail without hiring a security team.
- One injected script can read every card typed into your checkout
- Changes are invisible to shoppers — and to you, without monitoring
- Your acquirer can ask for proof of these controls at any time
The stakes
E-skimming turned the checkout into the front line
In a Magecart-style attack, criminals don't break into your database — they slip a few lines of JavaScript into a script your payment page already loads, often through a compromised third-party tag or plugin. The skimmer copies card details as your customer types them, sends them to a server the attacker controls, and lets the order complete normally. Nothing looks wrong to the shopper, and nothing looks wrong to you.
The card brands responded. PCI DSS v4.0 added requirements 6.4.3 and 11.6.1, which became mandatory on 31 March 2025: merchants must keep an authorized, justified inventory of all payment-page scripts, and detect tampering with page content and security headers at least weekly. Even merchants who validate with a short SAQ are increasingly asked by their acquirer to show how their payment page is protected against script attacks.
Doing that by hand means diffing scripts and headers on a schedule, keeping a written justification for every tag, and filing the results where an assessor can find them. ScriptProof automates the whole loop — and keeps the receipts.
- An inventory with recorded justifications — the core of requirement 6.4.3
- Tamper detection on scripts and headers — the mechanism 11.6.1 describes
- Dated logs and reports, so “we monitor it” comes with proof attached

What lands in your hands
From live scan to bank-ready evidence
$ scriptproof scan https://yourstore.com/checkout
✓ domain ownership verified (DNS TXT)
✓ 14 scripts discovered · fingerprinting SHA-256…
✓ 12/14 match authorized inventory
⚠ 1 script changed since last scan: analytics.shopmetrics.js
✕ 1 unknown script: static.unknown-cdn.ru/p.js — flagged
→ critical alert sent · evidence log updated
1 · Scheduled scans fingerprint every script & header
🚨 Critical: new script on /checkout
alerts@scriptproof → you · just now
static.unknown-cdn.ru/p.jsfirst seen 14:02 UTC · not in your authorized inventory
Before
13 scripts
After
14 scripts (+1)
2 · Instant alerts with before/after hashes when something changes
Evidence Pack
Monthly · PDF · PCI DSS 6.4.3 / 11.6.1
A. Script inventory & authorizations
B. Change log with hashes
C. Security header history
D. Scan cadence & coverage
sha256: 8c1f…a2e9 · signed
Ready for your SAQ
3 · Monthly Evidence Pack — the paper trail for your SAQ
How it works
Four steps to a signed, dated paper trail
Verify your site
Prove you own the domain with a DNS record or meta tag. We only ever monitor sites you control.
We watch your payment pages
Our crawler fingerprints every script and security header on your checkout, on a daily or 6-hourly schedule.
You get alerted on changes
A new or modified script triggers an immediate email with before/after hashes and a one-click review link.
Evidence, ready for your SAQ
A monthly PDF Evidence Pack documents your script inventory, authorizations, change log and scan cadence.
Everything you get
One subscription, the whole control loop
No modules to bolt on, no per-report fees. Every plan covers the full cycle from scan to evidence.
Daily scheduled scans
Your payment pages are crawled every day — every 6 hours on Pro — and each run is logged with a timestamp, comfortably inside the weekly cadence 11.6.1 asks for.
SHA-256 script inventory
Every script on your checkout is hashed and catalogued, so your inventory is always current, exportable, and provable rather than guessed.
Authorization log
Record why each script is on the page and who approved it — the written justification requirement 6.4.3 expects to see.
Security-header monitoring
CSP, HSTS and other security headers are captured on every scan and diffed against the previous run, so silent weakening gets caught.
CSP insights
See which scripts your Content-Security-Policy actually allows — and where policy and what is really loading have drifted apart.
Instant change alerts
A new or modified script triggers an immediate email with before/after fingerprints and a one-click review link.
Daily digest
Lower-severity changes are grouped into one readable daily summary, so you stay informed without alert fatigue.
Monthly Evidence Pack PDF
A dated PDF compiling inventory, authorizations, change log and scan history — formatted to attach straight to your SAQ.
Free checkout scanner
Point it at any checkout URL and get a one-page report of its scripts and headers in seconds — no account needed.
Agency white-label
Put your agency’s branding on Evidence Packs and manage every client store from a single dashboard on the Agency plan.
Assessment day
What your auditor will ask — and what you'll answer
Five questions that come up in almost every review of payment-page controls, and how ScriptProof lets you answer each one with a document instead of a shrug.
- “Can you show me an inventory of all scripts on your payment pages?”
- Yes — a live, timestamped inventory of every script on your checkout, each fingerprinted with SHA-256 and exportable for any point in time.
- “Is there a documented business justification for each script?”
- Every script carries a recorded authorization — what it does, why it’s there, and who approved it — kept alongside the inventory.
- “How would you detect tampering with page content or headers?”
- Every scan diffs script hashes and security headers against the previous run. Any unexpected change raises an alert with before/after evidence.
- “Are those checks performed at least weekly?”
- Scans run daily — or every 6 hours on Pro — and every run is logged, so the cadence is something you can demonstrate, not just claim.
- “Can you produce evidence covering the assessment period?”
- The monthly Evidence Pack compiles inventory, authorizations, change log and scan history into a dated PDF you can hand over as-is.
Watches the scripts & headers that matter
Run an agency?
Manage many client stores from one place, with white-label Evidence Packs and CSV export on the Agency plan. Zero performance hit — monitoring runs on our servers, and the optional snippet is under 6 KB and fails silently.
FAQ
Frequently asked questions
- Does ScriptProof make me PCI compliant?
- No. ScriptProof is a monitoring and evidence tool. It supports your 6.4.3 and 11.6.1 controls and produces supporting evidence, but it is not a QSA service and does not certify compliance. Your validation requirements are set by your acquirer or a QSA.
- Do I need to install anything on my site?
- No. ScriptProof monitors your pages from the outside after you verify you own the domain. There is an optional lightweight snippet on Pro and Agency plans for catching scripts injected at runtime, but it is not required to start.
- Will it slow down my checkout?
- No. Monitoring happens on our servers, not in your customers’ browsers. The optional snippet is under 6 KB and fails silently — it never blocks or breaks your page.
- What happens when a script changes?
- A new or modified script on a payment page triggers an immediate email with the before and after fingerprints and a one-click review link. Lower-severity changes are grouped into a daily digest.
- Do you ever see card data?
- Never. ScriptProof only handles URLs, script metadata and content hashes, HTTP headers, and your account details. It does not request, process, or store cardholder data.

Built for scrutiny
Evidence your bank can actually accept
The monthly Evidence Pack isn't a screenshot of a dashboard. It's a dated PDF that reads the way an assessor expects: your script inventory with fingerprints, the authorization behind each script, the full change log, and the scan history that proves your cadence. Attach it to your SAQ, forward it to your acquirer, or hand it to a QSA as-is.
And because ScriptProof watches payment pages for a living, we hold ourselves to the same bar: we never request, process, or store cardholder data — only URLs, hashes, headers, and your account details.
How we protect your dataStart protecting your checkout today
Run a free scan in seconds, or start a 14-day trial and get your first Evidence Pack this month.