Apr 20265 min read
E-COMMERCE

PCI DSS v4.0.1 asks about every script on your checkout. Most stores cannot answer

Since 31 March 2025, merchants have had to inventory, justify and monitor the scripts on their payment pages. The tag manager your marketing team loves is now a compliance question.

Card skimming moved from the till to the browser years ago. Attackers who can change one script on a checkout page can copy every card number typed into it, and the store keeps working normally while it happens. PCI DSS v4.0 responded with two requirements that became mandatory on 31 March 2025.

What 6.4.3 and 11.6.1 ask for

Requirement 6.4.3 asks that every script loaded on a payment page is inventoried, has a written justification, is authorised, and has its integrity assured. Requirement 11.6.1 asks for a mechanism to detect unauthorised changes to the page and its security-relevant headers, and to alert when they happen.

If your payment form is entirely on your provider’s domain, your obligations may be lighter — but the eligibility rules are specific, and many stores that embed payment fields in their own page are not as far out of scope as they assume. Check with your acquirer or a Qualified Security Assessor rather than guessing.

“The tag manager your marketing team loves is now a compliance question.”

What we usually find

Dozens of scripts on the checkout: analytics, reviews, live chat, A/B testing, advertising pixels. Several are loaded through a tag manager that anyone in marketing can edit, which means anyone in marketing — or anyone who phishes them — can publish code to the payment page.

Related engagement Every script on the payment page, accounted for →

How to get there

Inventory every script under real conditions, including those loaded indirectly. Remove everything the payment page does not need — usually most of them. For what remains, enforce a Content Security Policy, use integrity checks where scripts are static, and put change detection in place that actually alerts someone. Then test it, by changing a script and checking that the alert fires.

TL;DR

The short version

Skimming happens in the browser

One altered script on a checkout can copy every card typed into it.

6.4.3: inventory and authorise

Every payment-page script needs a justification, authorisation and integrity check.

11.6.1: detect change

Unauthorised changes to the page and its headers must raise an alert.

Mandatory since 31 March 2025

These were future-dated in v4.0 and are now in force under v4.0.1.

Tag managers are the usual gap

Anyone who can edit the container can publish code to the checkout.

Cut first, then control

Remove what the page does not need; enforce CSP and alerting on the rest.

Written by

The Penspy team

Testers and auditors · Penspy Cyber Security

Written by the people who do the testing and the audits, from what we actually find in the work. No vendor sponsorship, no product to sell you at the end.

Send us a note