Overview
💳 PCI DSS 6.4.3 payment-page script inventory in one click. Free scan, Pro export.
PCI DSS 4.0.1 requirement 6.4.3 asks every business that takes card payments online to keep an inventory of the scripts on its payment pages, with a written justification for each, plus integrity checks. This produces that inventory from the page as your browser actually rendered it — including scripts a tag manager injected at runtime, which a server-side scan cannot see. Click Scan and it lists every script: the vendor, what it does, a **drafted business justification for you to approve**, and a SHA-256 fingerprint. Anything it doesn't recognise says so rather than guessing. Embedded payment iframes (e.g. Stripe) are named as the provider's scope, not yours. It **never states that you are compliant** — that is your assessor's judgement. It fully supports the 6.4.3 inventory; the seven-day change check of 11.6.1 it *assists* (you run it), because there is no server. Free: scan and read the full inventory. Pro: export the CSV your assessor needs, and detect changes against a saved baseline.
Details
- Version0.2.3
- UpdatedAugust 10, 2026
- FeaturesOffers in-app purchases
- Offered byshaunpeh
- Size30.45KiB
- LanguagesEnglish (United States)
- Developerthe b2b house
Email
shaunpeh@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes