Know every script on your checkout.
Card-skimming code hides in scripts the browser loads on the payment page: a compromised plugin, a tag added through Tag Manager, a third-party library that changed overnight. We list what runs, remove what should not, and watch for changes.
From $99/mo
Checkout script monitoring tracks every script that runs on your payment pages and alerts you when a script or security header changes. PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 call for this kind of inventory, authorization and change detection, because injected scripts can skim card details in the browser. FIMM builds the inventory, hardens checkout with Content Security Policy and Subresource Integrity, and monitors it from $99 a month. This is technical work; it is not a QSA assessment.
What we build.
Payment-page script inventory
A list of every script on your payment pages, where it comes from, who approved it and why it is needed. It is kept current as the record requirement 6.4.3 asks for.
Content Security Policy
A CSP that allows only the scripts and sources your checkout needs, rolled out in report-only mode first so nothing breaks for paying customers.
Subresource Integrity
Integrity hashes on static third-party scripts, so the browser refuses a file that has been altered after you approved it.
Checkout clean-up
Tag Manager containers, marketing pixels and chat widgets removed from payment pages where they do not belong, which shrinks what needs watching.
Change and tamper detection
Payment-page scripts and HTTP security headers are checked at least weekly, the minimum requirement 11.6.1 sets. Anything added, removed or modified raises an alert for review.
Evidence for your assessor
Monthly records of the inventory, approvals and alerts, ready to hand to your QSA, your acquirer or whoever completes your self-assessment questionnaire.
How checkout monitoring runs.
Monitoring starts once the checkout is cleaned up and hardened, so scripts that never belonged are already gone and each alert points to a real change.
Check
We load your checkout and list the scripts and headers it serves today, including the ones nobody remembers adding.
Harden
Unneeded scripts removed, CSP and Subresource Integrity added, and each remaining script recorded with a business reason.
Monitor
Automated checks run at least weekly and raise an alert for review when a script or header changes.
Review
Each alert is reviewed, then approved or rolled back, and the record is kept for your next assessment.
Common questions.
What do PCI DSS requirements 6.4.3 and 11.6.1 ask for?
Is this a PCI compliance assessment?
We use a hosted payment page or iframe. Do we still need this?
What happens when a monitoring alert fires?
Which e-commerce platforms do you support?
How much does checkout script monitoring cost?
Can this stop every card-skimming attack?
Explore what else we build.
AI Automation
Support agents, lead qualification, and back-office workflows that run themselves, with guardrails and human escalation.
Explore →Web & SaaS
SaaS products and MVPs with accounts, billing and dashboards, built to launch fast and scale cleanly.
Explore →Mobile Apps
Native-feeling iOS and Android products, from prototype to store, backend included.
Explore →Let's build
something.
// A 30-minute call · one problem worth solving · a straight answer on fit
Request a checkout script check →