- Standard
- PCI DSS 4.0.1 requirement 6.4.3 — payment-page scripts
- Target
- https://shop.example/checkout
- Actionable items
- 2
Observed inventory
Facts carried by the canonical artifact, before remediation judgment.
- https://js.payment.example/v3/
- Host
- js.payment.example
- Authorization
- declared authorized in this synthetic example
- Integrity
- non-empty attribute observed
- https://analytics.vendor.example/checkout.js
- Host
- analytics.vendor.example
- Authorization
- not present in the synthetic authorized list
- Integrity
- no non-empty attribute observed
Remediation course
Each item carries the observed fact downstream through risk, fix, and closure evidence.
UNAUTHORIZED_DOMAIN
high
Observation
https://analytics.vendor.example/checkout.js
Risk
The synthetic script host is not present in the authorization inventory supplied for this example.
Fix
Maintain an authorized-script inventory (6.4.3). Remove this script or add its domain to the approved list with a documented business justification, then apply and test the chosen integrity-assurance method.
Validation
Re-run with the approved host inventory and confirm the host is either absent or listed with an owner, business justification, and integrity-control decision.
SRI_MISSING
medium
Observation
https://analytics.vendor.example/checkout.js
Risk
No non-empty integrity attribute was observed on this synthetic cross-origin script tag.
Fix
Document the integrity-assurance method used for this script. If no method exists and SRI fits the delivery model, compute and pin a reviewed hash with an integrity attribute and crossorigin setting; otherwise document and test the alternative control.
Validation
Retain evidence of the chosen integrity-assurance method after testing the provider's update behavior. If SRI is appropriate, confirm the reviewed integrity value and crossorigin mode; otherwise document and test the alternative control. Exercise the full payment flow before closing the item.
Use this in qualified review
- Retain the canonical JSON. Keep it unchanged as the machine-readable artifact; this synthetic file shows the paid format but is not customer evidence.
- Attach the review view. Print or save this view and attach it, together with the JSON, to the applicable change record.
- Collect validation evidence. Complete the Validation step listed for every item before a qualified reviewer decides whether to close that item.
Scope and reliance
This payment-page pack inspects supplied or fetched HTML only. It does not execute JavaScript, inspect script bodies or HTTP response headers, or observe scripts added at runtime. An absent script in this inventory is not evidence that the browser never loads it. Collect browser evidence across the full payment flow separately. The pack provides written guidance; it does not implement fixes, validate your changes, or provide ongoing monitoring. Retain this scope explanation with the canonical JSON; the JSON alone may not contain these limits. This is software-generated remediation guidance for qualified human review. It does not determine PCI DSS compliance, replace a Qualified Security Assessor, or certify that an implementation is secure. Validate every change in a safe environment before deploying it.
The downloaded JSON is the stable, machine-readable artifact used by this presentation. Save it with your change record.