Inventory every script
We crawled the checkout under real conditions, logged every script and where it came from, and traced which were loaded by which tag-manager rule.
Penspy is an independent security firm, testing web applications and auditing against the frameworks you answer to.
An online retailer discovered that the March 2025 PCI DSS deadline applied to the tag manager its marketing team had been running for six years.
Representative engagement. Client names, figures and identifying details are changed or combined; no client findings are published in identifiable form.
A direct-to-consumer retailer.
The retailer took card payments through a hosted payment field embedded in its own checkout page. It believed the payment provider’s compliance covered it entirely.
Its checkout page loaded thirty-one scripts — analytics, reviews, chat, A/B testing and three advertising pixels, several through a tag manager anyone in marketing could edit.
We crawled the checkout under real conditions, logged every script and where it came from, and traced which were loaded by which tag-manager rule.
Each script needed a written business justification. Nineteen had none on the payment page and were removed from it entirely.
For the twelve that remained, we helped implement integrity controls and change detection meeting requirements 6.4.3 and 11.6.1, and tested that a modified script actually raised an alert.
| Severity | Finding | Maps to | Status at retest |
|---|---|---|---|
| High | Tag manager allowed any marketing user to publish arbitrary JavaScript to the checkout. | PCI DSS 6.4.3 · A08:2025 | Closed |
| High | No mechanism to detect unauthorised changes to payment-page scripts or headers. | PCI DSS 11.6.1 | Closed |
| Medium | Content Security Policy present but in report-only mode with wildcard sources. | PCI DSS 6.4.3 · ASVS V3 | Closed |
| Medium | Gift-card balance endpoint had no rate limit, allowing card-number enumeration. | A06:2025 · API6:2023 | Closed |
| Medium | Third-party review widget pinned to a library version with a known XSS flaw. | A03:2025 · CVE-listed | Closed |
What changed.
The checkout now loads twelve justified scripts under an enforced Content Security Policy, with alerting on any change. Marketing kept its tools everywhere except the payment page.
The retailer completed its self-assessment questionnaire with evidence for every requirement, and checkout load time dropped by over a second as a side effect.
Tell us what you ship and who is asking for proof. We will come back with a scope and a range.