PCI DSS 6.4.3 Payment Page Script Lint

Lints checkout and payment pages against PCI DSS v4.0.1 Requirements 6.4.3 and 11.6.1 — script authorization, SRI integrity, written justification and tamper detection. Mandatory since 2025-03-31. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Lints a checkout page against PCI DSS v4.0.1 Requirements 6.4.3 and 11.6.1 — script authorization, SRI integrity, written justification, tamper detection.

QSA assessment time bills at roughly $200 an hour; this is $29 once.

Buy the full version — $29

Questions people ask

What does this actually do?

It reads a checkout or payment page and reports it against PCI DSS v4.0.1 Requirements 6.4.3 and 11.6.1. Fourteen checks: missing subresource-integrity hashes, integrity without crossorigin, unversioned vendor SDKs, tag managers on the payment page, unsafe-inline and wildcard hosts in script-src, unnonced inline blocks, missing written justifications, and no declared tamper detection.

Who is it for?

Developers and agencies who build custom checkout pages on Stripe, Braintree, Adyen, Square or Checkout.com rather than redirecting to a hosted page, and who have to sign an SAQ A-EP or SAQ D. If your payment page is a page you wrote, 6.4.3 and 11.6.1 are yours to answer.

Why is a free tool not enough?

An SRI hash generator gives you one hash. A CSP evaluator grades one header. Neither knows that Requirement 6.4.3.3 also wants a written business or technical justification stored per script, that a tag manager on the payment page voids the allowlist, or that an integrity attribute without crossorigin is skipped by the browser.

What is free and what costs money?

Checking the payment page open in your editor is free and complete: all fourteen checks, every finding, every requirement number, no key, no watermark, no counter. Paid is scope and ownership — sweeping the whole workspace and writing the dated script inventory to a file you keep in the repo.

What would this cost with a person?

QSA assessment time bills at roughly $200 an hour, and building a script inventory with justifications is a per-page exercise repeated at every release. This extension is $29 once, with a 7-day full refund. It does not replace an assessment; it stops you arriving at one with findings you could have read yourself.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool