Item logo image for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit

Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit

ExtensionDeveloper Tools
Item media 5 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 1 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 2 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 3 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 4 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 5 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 1 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 1 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 2 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 3 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 4 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit
Item media 5 (screenshot) for Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit

Overview

Build a justified inventory of payment-page scripts, verify integrity, and diff against your approved baseline.

Script Inventory builds the payment-page script inventory PCI DSS v4.0 requirement 6.4.3 asks for: every script, who injected it, whether its integrity is verified, and a written justification you record once and keep. Built for PCI consultants, QSAs, security teams and the e-commerce engineers who have to answer "which scripts run on your checkout, and why?" ━━━ READ THIS FIRST: WHAT THIS IS NOT ━━━ This does NOT make you compliant with 11.6.1, and no browser extension can. Requirement 11.6.1 asks for a mechanism that DETECTS AND ALERTS ON change — which means it has to be watching when nobody is looking. An extension only runs when a person opens the page. Any extension that tells you otherwise is setting you up to fail an assessment. What this does is the survey work: build the inventory, record the justifications, check integrity, and diff against a baseline. That is most of the manual effort in 6.4.3. The continuous control still needs a server-side or synthetic monitor. We would rather tell you that up front than have you find out from your assessor. ━━━ WHAT IT DOES ━━━ ▸ DISCOVERY — everything that actually runs Scripts in the page source, scripts injected at runtime, and scripts that arrive seconds later from a tag manager. Inline blocks are hashed with SHA-256 so a change is detectable on the next run. ▸ ATTRIBUTION — who loaded whom Each runtime-injected script is attributed to the domain that appears to have injected it. A trusted vendor loading an unreviewed one is the Magecart pattern in a single line — and it is invisible if you inventory by reading the HTML source. ▸ INTEGRITY — SRI, or the lack of it External third-party scripts without an integrity attribute are flagged. Without SRI, a change at the vendor's CDN executes on your checkout with no signal at all. Known payment gateways are exempted from the noise, not from the inventory. ▸ JUSTIFICATION — written once, and kept 6.4.3 asks for "a written justification as to why each is necessary". You type it once; it stays attached to that script on that site. The next scan only asks about what is new. ▸ BASELINE — approve, then diff Approve a clean inventory. Every later scan reports exactly what was added or removed. ▸ CSP — whether your policy is actually a control Detects a Content-Security-Policy meta tag and flags one so permissive it authorises nothing. ▸ SCOPE — is this page even in scope? Detects fields that look like card inputs, by NAME only, to tell you whether 6.4.3 and 11.6.1 apply to this page at all. ▸ EVIDENCE — a document, not a screenshot Export the full inventory with justifications, integrity status and the baseline diff, as a self-contained HTML file that prints to PDF and states its own scope and limits. ━━━ PRICE ━━━ Free. All of it, permanently. No account, no sign-up, no licence, no paid tier, no trial that expires. There is nothing to upgrade to, because there is no paid version. Everything the extension does, it does for everyone. It also has no server: it makes no network requests of its own, so there is nothing behind it that can be shut down or start charging later. ━━━ PRIVACY ━━━ Everything stays in your browser. No account, no server, nothing transmitted. It records script URLs, load method, integrity attributes and a SHA-256 hash of inline contents. From forms it records only the NAMES and autocomplete attributes of card-like fields — never their values, and never anything anyone types. Host access is requested ONE DOMAIN AT A TIME when you start a scan. This extension never asks for access to all sites. ━━━ LIMITS, STATED PLAINLY ━━━ • One page load, one browser, one location, one set of geo and consent conditions. • Scripts inside third-party iframes are not visible — a client-side observer cannot see into another origin. If your card fields live inside a gateway iframe, that is generally good for your scope, and also outside what this can report. • Server-side tag containers are not visible to any browser tool. • Injection attribution is a heuristic read from the call stack. Treat a specific attribution as a lead to verify, not as proof. ━━━ FAQ ━━━ Q: Does it work on a staging checkout? A: Yes. Grant permission for that origin like any other site. Q: Will it break the page? A: No. It only observes; every hook delegates to the original implementation. Q: Can I export for my GRC tool? A: Yes, raw JSON with the full inventory, justifications and baseline. Same button as the HTML export, and free like everything else. Not affiliated with the PCI Security Standards Council or any card brand. PCI DSS is a trademark of the PCI Security Standards Council. Nothing here is compliance advice.

Details

  • Version
    1.1.0
  • Updated
    September 8, 2026
  • Offered by
    faustino20161
  • Size
    37.21KiB
  • Languages
    English
  • Developer
    Email
    faustino20161@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

Script Inventory: PCI DSS 6.4.3 & 11.6.1 audit handles the following:

Web history
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps