TesseraEvidence follows evidence
Synthetic sample

PCI 4.0.1 payment-page remediation

Synthetic example: one script host needs an authorization decision and one integrity-control decision needs to be documented.

Synthetic sample — every target, observation, and record on this page is invented and uses reserved example domains. It contains no customer data, is not evidence of a real evaluation, and is not a certification or compliance determination. This payment-page pack inspects supplied or fetched HTML only. It does not execute JavaScript, inspect script bodies or HTTP response headers, or observe scripts added at runtime. An absent script in this inventory is not evidence that the browser never loads it. Collect browser evidence across the full payment flow separately. The pack provides written guidance; it does not implement fixes, validate your changes, or provide ongoing monitoring. Retain this scope explanation with the canonical JSON; the JSON alone may not contain these limits.
Run the matching free payment-page check
$299 one-time pack, offered only after an actionable in-scope resultOne written remediation pack for the submitted target. Eligible orders are automatically refunded if no complete initial delivery arrives within 48 hours.
Standard
PCI DSS 4.0.1 requirement 6.4.3 — payment-page scripts
Target
https://shop.example/checkout
Actionable items
2

Observed inventory

Facts carried by the canonical artifact, before remediation judgment.

  • https://js.payment.example/v3/
    Host
    js.payment.example
    Authorization
    declared authorized in this synthetic example
    Integrity
    non-empty attribute observed
  • https://analytics.vendor.example/checkout.js
    Host
    analytics.vendor.example
    Authorization
    not present in the synthetic authorized list
    Integrity
    no non-empty attribute observed

Remediation course

Each item carries the observed fact downstream through risk, fix, and closure evidence.

UNAUTHORIZED_DOMAIN

high

Observation

https://analytics.vendor.example/checkout.js

Risk

The synthetic script host is not present in the authorization inventory supplied for this example.

Fix

Maintain an authorized-script inventory (6.4.3). Remove this script or add its domain to the approved list with a documented business justification, then apply and test the chosen integrity-assurance method.

Validation

Re-run with the approved host inventory and confirm the host is either absent or listed with an owner, business justification, and integrity-control decision.

SRI_MISSING

medium

Observation

https://analytics.vendor.example/checkout.js

Risk

No non-empty integrity attribute was observed on this synthetic cross-origin script tag.

Fix

Document the integrity-assurance method used for this script. If no method exists and SRI fits the delivery model, compute and pin a reviewed hash with an integrity attribute and crossorigin setting; otherwise document and test the alternative control.

Validation

Retain evidence of the chosen integrity-assurance method after testing the provider's update behavior. If SRI is appropriate, confirm the reviewed integrity value and crossorigin mode; otherwise document and test the alternative control. Exercise the full payment flow before closing the item.

Use this in qualified review

  1. Retain the canonical JSON. Keep it unchanged as the machine-readable artifact; this synthetic file shows the paid format but is not customer evidence.
  2. Attach the review view. Print or save this view and attach it, together with the JSON, to the applicable change record.
  3. Collect validation evidence. Complete the Validation step listed for every item before a qualified reviewer decides whether to close that item.

Scope and reliance

This payment-page pack inspects supplied or fetched HTML only. It does not execute JavaScript, inspect script bodies or HTTP response headers, or observe scripts added at runtime. An absent script in this inventory is not evidence that the browser never loads it. Collect browser evidence across the full payment flow separately. The pack provides written guidance; it does not implement fixes, validate your changes, or provide ongoing monitoring. Retain this scope explanation with the canonical JSON; the JSON alone may not contain these limits. This is software-generated remediation guidance for qualified human review. It does not determine PCI DSS compliance, replace a Qualified Security Assessor, or certify that an implementation is secure. Validate every change in a safe environment before deploying it.

The downloaded JSON is the stable, machine-readable artifact used by this presentation. Save it with your change record.