Tessera
Synthetic sample

PCI 4.0.1 payment-page remediation

Synthetic example: one script host needs an authorization decision and one integrity-control decision needs to be documented.

Synthetic sample โ€” every target, observation, and record on this page is invented and uses reserved example domains. It contains no customer data, is not evidence of a real evaluation, and is not a certification or compliance determination.
Run the matching free payment-page check
$299 one-time pack, offered only after an actionable in-scope resultOne written remediation pack for the submitted target. Eligible orders are automatically refunded if no complete initial delivery arrives within 48 hours.
Standard
PCI DSS 4.0.1 requirement 6.4.3 โ€” payment-page scripts
Target
https://shop.example/checkout
Actionable items
2

Observed inventory

Facts carried by the canonical artifact, before remediation judgment.

  • https://js.payment.example/v3/
    Host
    js.payment.example
    Authorization
    declared authorized in this synthetic example
    Integrity
    non-empty attribute observed
  • https://analytics.vendor.example/checkout.js
    Host
    analytics.vendor.example
    Authorization
    not present in the synthetic authorized list
    Integrity
    no non-empty attribute observed

Remediation plan

Each item preserves the observed fact, explains the risk, and names a closure test.

1. UNAUTHORIZED_DOMAIN

high

Observation

https://analytics.vendor.example/checkout.js

Risk

The synthetic script host is not present in the authorization inventory supplied for this example.

Fix

Maintain an authorized-script inventory (6.4.3). Remove this script or add its domain to the approved list with a documented business justification, then apply and test the chosen integrity-assurance method.

Validation

Re-run with the approved host inventory and confirm the host is either absent or listed with an owner, business justification, and integrity-control decision.

2. SRI_MISSING

medium

Observation

https://analytics.vendor.example/checkout.js

Risk

No non-empty integrity attribute was observed on this synthetic cross-origin script tag.

Fix

Document the integrity-assurance method used for this script. If no method exists and SRI fits the delivery model, compute and pin a reviewed hash with an integrity attribute and crossorigin setting; otherwise document and test the alternative control.

Validation

Retain evidence of the chosen integrity-assurance method after testing the provider's update behavior. If SRI is appropriate, confirm the reviewed integrity value and crossorigin mode; otherwise document and test the alternative control. Exercise the full payment flow before closing the item.

Use this in qualified review

  1. Retain the canonical JSON. Download it and keep it unchanged as the machine-readable artifact; this synthetic file shows the paid format but is not customer evidence.
  2. Attach the review view. Print or save this view and attach it, together with the JSON, to the applicable change record.
  3. Collect validation evidence. Complete the Validation step listed for every item and retain the records it names before a qualified reviewer decides whether to close that item.

Scope and reliance

This is software-generated remediation guidance for qualified human review. It does not determine PCI DSS compliance, replace a Qualified Security Assessor, or certify that an implementation is secure. Validate every change in a safe environment before deploying it.

The downloaded JSON is the stable, machine-readable artifact used by this presentation. Save it with your change record.