Engagements  /  PSY-PCI-0297

Every script on the payment page, accounted for

An online retailer discovered that the March 2025 PCI DSS deadline applied to the tag manager its marketing team had been running for six years.

Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.

Sector
E-commerce and retail
Engagement
PCI DSS v4.0.1 readiness
Frameworks
PCI DSS v4.0.1, OWASP Top 10:2025
Duration
4 weeks

A direct-to-consumer retailer.

The retailer took card payments through a hosted payment field embedded in its own checkout page. It believed the payment provider’s compliance covered it entirely.

Its checkout page loaded thirty-one scripts — analytics, reviews, chat, A/B testing and three advertising pixels, several through a tag manager anyone in marketing could edit.

What we did

Inventory, justify, monitor.

Inventory every script

We crawled the checkout under real conditions, logged every script and where it came from, and traced which were loaded by which tag-manager rule.

Cut what the page does not need

Each script needed a written business justification. Nineteen had none on the payment page and were removed from it entirely.

Detect change, not just block it

For the twelve that remained, we helped implement integrity controls and change detection meeting requirements 6.4.3 and 11.6.1, and tested that a modified script actually raised an alert.

What we found

What the payment page was carrying.

SeverityFindingMaps toStatus at retest
HighTag manager allowed any marketing user to publish arbitrary JavaScript to the checkout.PCI DSS 6.4.3 · A08:2025Closed
HighNo mechanism to detect unauthorised changes to payment-page scripts or headers.PCI DSS 11.6.1Closed
MediumContent Security Policy present but in report-only mode with wildcard sources.PCI DSS 6.4.3 · ASVS V3Closed
MediumGift-card balance endpoint had no rate limit, allowing card-number enumeration.A06:2025 · API6:2023Closed
MediumThird-party review widget pinned to a library version with a known XSS flaw.A03:2025 · CVE-listedClosed

What changed.

The checkout now loads twelve justified scripts under an enforced Content Security Policy, with alerting on any change. Marketing kept its tools everywhere except the payment page.

The retailer completed its self-assessment questionnaire with evidence for every requirement, and checkout load time dropped by over a second as a side effect.

Next engagement

Want this for your application?

Tell us what you ship and who is asking for proof. We will come back with a scope and a range.