Lints checkout and payment pages against PCI DSS v4.0.1 Requirements 6.4.3 and 11.6.1 — script authorization, SRI integrity, written justification and tamper detection. Mandatory since 2025-03-31. Runs entirely in your browser — nothing is uploaded.
$29 once · one licence key per person or team seat · 7-day full refund. QSA assessment time bills at roughly $200 an hour.
Free here: Check the payment page open in your editor against all 14 checks, every finding, no key. In the editor: Sweep the whole workspace and write the dated 6.4.3 script inventory as a file you keep — that part asks for a licence key.Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
Lints a checkout page against PCI DSS v4.0.1 Requirements 6.4.3 and 11.6.1 — script authorization, SRI integrity, written justification, tamper detection.
QSA assessment time bills at roughly $200 an hour; this is $29 once.
Buy the full version — $29It reads a checkout or payment page and reports it against PCI DSS v4.0.1 Requirements 6.4.3 and 11.6.1. Fourteen checks: missing subresource-integrity hashes, integrity without crossorigin, unversioned vendor SDKs, tag managers on the payment page, unsafe-inline and wildcard hosts in script-src, unnonced inline blocks, missing written justifications, and no declared tamper detection.
Developers and agencies who build custom checkout pages on Stripe, Braintree, Adyen, Square or Checkout.com rather than redirecting to a hosted page, and who have to sign an SAQ A-EP or SAQ D. If your payment page is a page you wrote, 6.4.3 and 11.6.1 are yours to answer.
An SRI hash generator gives you one hash. A CSP evaluator grades one header. Neither knows that Requirement 6.4.3.3 also wants a written business or technical justification stored per script, that a tag manager on the payment page voids the allowlist, or that an integrity attribute without crossorigin is skipped by the browser.
Checking the payment page open in your editor is free and complete: all fourteen checks, every finding, every requirement number, no key, no watermark, no counter. Paid is scope and ownership — sweeping the whole workspace and writing the dated script inventory to a file you keep in the repo.
QSA assessment time bills at roughly $200 an hour, and building a script inventory with justifications is a per-page exercise repeated at every release. This extension is $29 once, with a 7-day full refund. It does not replace an assessment; it stops you arriving at one with findings you could have read yourself.
One question, answered by the person who built it. Your email only if you want the answer sent.