PCI DSS v4.0.1 · Req. 6.4.3 & 11.6.1

Every script on your checkout.
Watched. Fingerprinted. Proven.

ScriptProof keeps an inventory of every script on your payment pages, records why each one is authorized, detects tampering, and turns it all into evidence you can hand to your bank — no agent install required to start.

No agent install 14-day trial Never touches card data

app.scriptproof — script inventorymonitoring live

New unauthorized script detected on /checkout — 2 min ago

14

Scripts tracked

12

Authorized

1

Open alerts

ScriptStatus
js.stripe.com/v3authorized
checkout.jsauthorized
cdn.tagmanager.io/gtm.jsauthorized
static.unknown-cdn.ru/p.jsflagged
analytics.shopmetrics.jsreview

PCI DSS v4.0.1

Supports req. 6.4.3 controls

Req. 11.6.1

Tamper & change detection

SHA-256

Every script fingerprinted

TLS encrypted

All monitoring traffic

Zero card data

Never requested or stored

Server-side

No load on your checkout

0

PCI controls supported (6.4.3 · 11.6.1)

SHA-0

fingerprint on every script

0 KB

optional snippet — fails silently

0

cardholder data ever touched

Who it's for

Built for the people who actually get the compliance email

Whether you own the store, manage twenty of them, or wrote the checkout yourself — ScriptProof does the monitoring and the paperwork.

Small online shop owner preparing orders

Small merchants

You run the store. We run the checks.

  • Your acquirer sent an SAQ mentioning 6.4.3 and 11.6.1 — with no explanation of how to actually do it
  • No security team and no time to hand-audit checkout scripts every week
  • Verify your domain once; scans, alerts and evidence run on their own after that
  • A monthly Evidence Pack you can forward to your bank instead of writing one yourself
Agency team collaborating around a table

Agencies & freelancers

Every client store, one pane of glass.

  • Clients forward compliance letters from their bank and expect you to make them go away
  • Dozens of storefronts, each with its own theme, apps and third-party tags
  • Per-client alerts and white-label Evidence Packs turn compliance into a billable service
  • CSV export and one dashboard across every site you manage
Developer reviewing code on screen

Developers

Provable diffs, not vague warnings.

  • That tag you didn’t add? Marketing pasted it in six months ago — now it’s on the payment page
  • Every script is fingerprinted with SHA-256, so “changed” is a fact you can verify
  • Alerts carry before/after hashes and the exact header deltas, not just “something changed”
  • Nothing to deploy: monitoring runs from outside, and the optional snippet is under 6 KB

The platform

Monitoring and evidence, without a security team

The controls auditors ask about — packaged for small merchants and busy agencies.

Requirement 6.4.3

Script Inventory

Every script on your checkout, fingerprinted with SHA-256, with a recorded reason each one is authorized.

Requirement 11.6.1

Tamper Detection

Content and security-header changes caught and flagged — the exact surface skimming attacks target.

Audit-ready PDF

Evidence Packs

A monthly paper trail of inventory, authorizations, change log and scan cadence to attach to your SAQ.

No account needed

Free Scanner

Point us at any checkout URL and get a one-page report of its scripts and headers in seconds.

Your checkoutcard number ••••stripe.js ✓checkout.js ✓gtm.js ✓skimmer.js ✕ScriptProoffingerprints every script⚠ email alert

The threat

Skimmers hide in the scripts you already trust

Since PCI DSS v4.0, requirements 6.4.3 and 11.6.1 ask merchants to maintain an authorized inventory of all payment-page scripts and to detect tampering with page content and HTTP headers at least weekly. That applies to small shops too — skimming attacks overwhelmingly target exactly the scripts these requirements cover. ScriptProof gives you the monitoring and the paper trail without hiring a security team.

  • One injected script can read every card typed into your checkout
  • Changes are invisible to shoppers — and to you, without monitoring
  • Your acquirer can ask for proof of these controls at any time

The stakes

E-skimming turned the checkout into the front line

In a Magecart-style attack, criminals don't break into your database — they slip a few lines of JavaScript into a script your payment page already loads, often through a compromised third-party tag or plugin. The skimmer copies card details as your customer types them, sends them to a server the attacker controls, and lets the order complete normally. Nothing looks wrong to the shopper, and nothing looks wrong to you.

The card brands responded. PCI DSS v4.0 added requirements 6.4.3 and 11.6.1, which became mandatory on 31 March 2025: merchants must keep an authorized, justified inventory of all payment-page scripts, and detect tampering with page content and security headers at least weekly. Even merchants who validate with a short SAQ are increasingly asked by their acquirer to show how their payment page is protected against script attacks.

Doing that by hand means diffing scripts and headers on a schedule, keeping a written justification for every tag, and filing the results where an assessor can find them. ScriptProof automates the whole loop — and keeps the receipts.

  • An inventory with recorded justifications — the core of requirement 6.4.3
  • Tamper detection on scripts and headers — the mechanism 11.6.1 describes
  • Dated logs and reports, so “we monitor it” comes with proof attached
Padlock resting on a laptop keyboard, symbolizing payment page security

What lands in your hands

From live scan to bank-ready evidence

scriptproof — scan

$ scriptproof scan https://yourstore.com/checkout

✓ domain ownership verified (DNS TXT)

✓ 14 scripts discovered · fingerprinting SHA-256…

✓ 12/14 match authorized inventory

⚠ 1 script changed since last scan: analytics.shopmetrics.js

✕ 1 unknown script: static.unknown-cdn.ru/p.js — flagged

→ critical alert sent · evidence log updated

1 · Scheduled scans fingerprint every script & header

🚨 Critical: new script on /checkout

alerts@scriptproof → you · just now

critical

static.unknown-cdn.ru/p.jsfirst seen 14:02 UTC · not in your authorized inventory

Before

13 scripts

After

14 scripts (+1)

Review & authorize

2 · Instant alerts with before/after hashes when something changes

Evidence Pack

Monthly · PDF · PCI DSS 6.4.3 / 11.6.1

Generated

A. Script inventory & authorizations

B. Change log with hashes

C. Security header history

D. Scan cadence & coverage

sha256: 8c1f…a2e9 · signed

Ready for your SAQ

3 · Monthly Evidence Pack — the paper trail for your SAQ

How it works

Four steps to a signed, dated paper trail

01

Verify your site

Prove you own the domain with a DNS record or meta tag. We only ever monitor sites you control.

02

We watch your payment pages

Our crawler fingerprints every script and security header on your checkout, on a daily or 6-hourly schedule.

03

You get alerted on changes

A new or modified script triggers an immediate email with before/after hashes and a one-click review link.

04

Evidence, ready for your SAQ

A monthly PDF Evidence Pack documents your script inventory, authorizations, change log and scan cadence.

Everything you get

One subscription, the whole control loop

No modules to bolt on, no per-report fees. Every plan covers the full cycle from scan to evidence.

Daily scheduled scans

Your payment pages are crawled every day — every 6 hours on Pro — and each run is logged with a timestamp, comfortably inside the weekly cadence 11.6.1 asks for.

SHA-256 script inventory

Every script on your checkout is hashed and catalogued, so your inventory is always current, exportable, and provable rather than guessed.

Authorization log

Record why each script is on the page and who approved it — the written justification requirement 6.4.3 expects to see.

Security-header monitoring

CSP, HSTS and other security headers are captured on every scan and diffed against the previous run, so silent weakening gets caught.

CSP insights

See which scripts your Content-Security-Policy actually allows — and where policy and what is really loading have drifted apart.

Instant change alerts

A new or modified script triggers an immediate email with before/after fingerprints and a one-click review link.

Daily digest

Lower-severity changes are grouped into one readable daily summary, so you stay informed without alert fatigue.

Monthly Evidence Pack PDF

A dated PDF compiling inventory, authorizations, change log and scan history — formatted to attach straight to your SAQ.

Free checkout scanner

Point it at any checkout URL and get a one-page report of its scripts and headers in seconds — no account needed.

Agency white-label

Put your agency’s branding on Evidence Packs and manage every client store from a single dashboard on the Agency plan.

Assessment day

What your auditor will ask — and what you'll answer

Five questions that come up in almost every review of payment-page controls, and how ScriptProof lets you answer each one with a document instead of a shrug.

“Can you show me an inventory of all scripts on your payment pages?”
Yes — a live, timestamped inventory of every script on your checkout, each fingerprinted with SHA-256 and exportable for any point in time.
“Is there a documented business justification for each script?”
Every script carries a recorded authorization — what it does, why it’s there, and who approved it — kept alongside the inventory.
“How would you detect tampering with page content or headers?”
Every scan diffs script hashes and security headers against the previous run. Any unexpected change raises an alert with before/after evidence.
“Are those checks performed at least weekly?”
Scans run daily — or every 6 hours on Pro — and every run is logged, so the cadence is something you can demonstrate, not just claim.
“Can you produce evidence covering the assessment period?”
The monthly Evidence Pack compiles inventory, authorizations, change log and scan history into a dated PDF you can hand over as-is.

Watches the scripts & headers that matter

Stripe.jsPayPal SDKGoogle PayApple PayCheckout scriptsAnalytics tagsCSP headersSRI hashesThird-party pixelsInline scripts

Run an agency?

Manage many client stores from one place, with white-label Evidence Packs and CSV export on the Agency plan. Zero performance hit — monitoring runs on our servers, and the optional snippet is under 6 KB and fails silently.

Agency plan

FAQ

Frequently asked questions

Does ScriptProof make me PCI compliant?
No. ScriptProof is a monitoring and evidence tool. It supports your 6.4.3 and 11.6.1 controls and produces supporting evidence, but it is not a QSA service and does not certify compliance. Your validation requirements are set by your acquirer or a QSA.
Do I need to install anything on my site?
No. ScriptProof monitors your pages from the outside after you verify you own the domain. There is an optional lightweight snippet on Pro and Agency plans for catching scripts injected at runtime, but it is not required to start.
Will it slow down my checkout?
No. Monitoring happens on our servers, not in your customers’ browsers. The optional snippet is under 6 KB and fails silently — it never blocks or breaks your page.
What happens when a script changes?
A new or modified script on a payment page triggers an immediate email with the before and after fingerprints and a one-click review link. Lower-severity changes are grouped into a daily digest.
Do you ever see card data?
Never. ScriptProof only handles URLs, script metadata and content hashes, HTTP headers, and your account details. It does not request, process, or store cardholder data.
Two professionals shaking hands over a signed agreement

Built for scrutiny

Evidence your bank can actually accept

The monthly Evidence Pack isn't a screenshot of a dashboard. It's a dated PDF that reads the way an assessor expects: your script inventory with fingerprints, the authorization behind each script, the full change log, and the scan history that proves your cadence. Attach it to your SAQ, forward it to your acquirer, or hand it to a QSA as-is.

And because ScriptProof watches payment pages for a living, we hold ourselves to the same bar: we never request, process, or store cardholder data — only URLs, hashes, headers, and your account details.

How we protect your data

Start protecting your checkout today

Run a free scan in seconds, or start a 14-day trial and get your first Evidence Pack this month.