Find scripts on your payment page that still need review
Inventory the script elements present in served HTML and, when you supply your authorized-domain list, highlight observed hosts absent from it. This bounded static check does not inspect HTTP response headers, fetch referenced script bodies, or execute JavaScript, so runtime-injected scripts may be invisible. Only you can decide whether a script is authorized. Requirements 6.4.3 and 11.6.1 apply only where in scope; SAQ A uses a separate eligibility criterion. Confirm scope with your acquirer or QSA. This is evidence for qualified review, not a PCI DSS compliance determination or replacement for a QSA assessment.
- No account or card details
- Raw results are not retained in a result database
- Observation stays separate from human judgment
- Every blind spot remains visible in the result
Each observation keeps its source and its limit.
This specimen is synthetic and sends no request. A real check replaces it with observations from the request snapshot.
processor.test/sdk.jssource host · integrity observed/assets/checkout.jssame origin · integrity not observed1 inline script blockauthorization not assessed
Inspect the artifact. Keep the exact price visible.
Samples are synthetic and contain the same evidence sections as delivery. A checkout link appears only in an eligible fresh result while fulfillment is healthy.
PCI DSS 6.4.3 remediation pack
Finding-by-finding observation, risk, fix, and validation guidance.
Preview the synthetic 6.4.3 packPCI DSS 11.6.1 evidence ledger
A 72-hour cadence, hash-chained history, and private status for your alerting system to poll; Tessera does not notify personnel.
Preview the synthetic 11.6.1 ledgerQuestions: qi@toledotechnologies.com. Enforced refund policy.