ServicesGrowthWorkBlogAboutContactRequest a call
Home/Services/Checkout Script Monitoring (PCI DSS 4.0)
Checkout Script Monitoring

Know every script on your checkout.

Card-skimming code hides in scripts the browser loads on the payment page: a compromised plugin, a tag added through Tag Manager, a third-party library that changed overnight. We list what runs, remove what should not, and watch for changes.

From $99/mo

In short

Checkout script monitoring tracks every script that runs on your payment pages and alerts you when a script or security header changes. PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 call for this kind of inventory, authorization and change detection, because injected scripts can skim card details in the browser. FIMM builds the inventory, hardens checkout with Content Security Policy and Subresource Integrity, and monitors it from $99 a month. This is technical work; it is not a QSA assessment.

PCI DSS 4.0.1 Req. 6.4.3 Req. 11.6.1 Content Security Policy Subresource Integrity Change detection
What we build

What we build.

A

Payment-page script inventory

A list of every script on your payment pages, where it comes from, who approved it and why it is needed. It is kept current as the record requirement 6.4.3 asks for.

B

Content Security Policy

A CSP that allows only the scripts and sources your checkout needs, rolled out in report-only mode first so nothing breaks for paying customers.

C

Subresource Integrity

Integrity hashes on static third-party scripts, so the browser refuses a file that has been altered after you approved it.

D

Checkout clean-up

Tag Manager containers, marketing pixels and chat widgets removed from payment pages where they do not belong, which shrinks what needs watching.

E

Change and tamper detection

Payment-page scripts and HTTP security headers are checked at least weekly, the minimum requirement 11.6.1 sets. Anything added, removed or modified raises an alert for review.

F

Evidence for your assessor

Monthly records of the inventory, approvals and alerts, ready to hand to your QSA, your acquirer or whoever completes your self-assessment questionnaire.

How it ships

How checkout monitoring runs.

Monitoring starts once the checkout is cleaned up and hardened, so scripts that never belonged are already gone and each alert points to a real change.

01

Check

We load your checkout and list the scripts and headers it serves today, including the ones nobody remembers adding.

02

Harden

Unneeded scripts removed, CSP and Subresource Integrity added, and each remaining script recorded with a business reason.

03

Monitor

Automated checks run at least weekly and raise an alert for review when a script or header changes.

04

Review

Each alert is reviewed, then approved or rolled back, and the record is kept for your next assessment.

Frequently asked

Common questions.

What do PCI DSS requirements 6.4.3 and 11.6.1 ask for?
Requirement 6.4.3 asks you to keep an inventory of the scripts on payment pages, authorize each one and confirm its integrity. Requirement 11.6.1 asks for a mechanism that detects unauthorized changes to payment-page scripts and security headers and alerts you. Both are now mandatory under PCI DSS 4.0.1 for the payment pages they apply to.
Is this a PCI compliance assessment?
No. This is not a QSA assessment, and FIMM does not issue Reports on Compliance or attestations. We do the technical work and keep the evidence; your QSA, acquirer or internal team decides whether requirements are met. FIMM provides technical implementation and is not a law firm, so we give no legal advice.
We use a hosted payment page or iframe. Do we still need this?
Possibly less of it. Merchants who rely on a payment provider's hosted page or iframe may use SAQ A, which asks them to confirm their site is not susceptible to script attacks that could affect the payment process. We can review and harden the pages around your payment iframe; your acquirer or assessor confirms which questionnaire applies.
What happens when a monitoring alert fires?
Checks run at least weekly, and every change raises an alert for review. We check whether it was expected, such as a payment provider updating its own script; expected changes are approved and recorded. Unexpected ones go to you with a recommendation to roll back or block the script.
Which e-commerce platforms do you support?
Laravel and custom PHP checkouts, WooCommerce, Magento, and headless or React storefronts. Where the payment provider fully hosts the payment page, there is less to change on it, and we will tell you if monitoring adds little for your setup.
How much does checkout script monitoring cost?
Monitoring starts at $99 a month for one checkout, month-to-month, and you can cancel anytime. It covers the weekly-or-better checks, alert review and the evidence records.
Can this stop every card-skimming attack?
No control can promise that. A short approved script list, a strict CSP, integrity checks and change alerts make skimming much harder to pull off and much faster to notice. That is the purpose of these requirements, and it is what we build.

Let's build
something.

// A 30-minute call · one problem worth solving · a straight answer on fit

Request a checkout script check →