Unknown author · Developer Tools
5 items
Build a justified inventory of payment-page scripts, verify integrity, and diff against your approved baseline. Script Inventory builds the payment-page script inventory PCI DSS v4.0 requirement 6.4.3 asks for: every script, who injected it, whether its integrity is verified, and a written justification you record once and keep. Built for PCI consultants, QSAs, security teams and the e-commerce engineers who have to answer "which scripts run on your checkout, and why?" ━━━ READ THIS FIRST: WHAT THIS IS NOT ━━━ This does NOT make you compliant with 11.6.1, and no browser extension can. Requirement 11.6.1 asks for a mechanism that DETECTS AND ALERTS ON change — which means it has to be watching when nobody is looking. An extension only runs when a person opens the page. Any extension that tells you otherwise is setting you up to fail an assessment. What this does is the survey work: build the inventory, record the justifications, check integrity, and diff against a baseline. That is most of the manual effort in 6.4.3. The continuous control still needs a server-side or synthetic monitor. We would rather tell you that up front than have you find out from your assessor. ━━━ WHAT IT DOES ━━━ ▸ DISCOVERY — everything that actually runs Scripts in the page source, scripts injected at runtime, and scripts that arrive seconds later from a tag manager. Inline blocks are hashed with SHA-256 so a change is detectable on the next run. ▸ ATTRIBUTION — who loaded whom Each runtime-injected script is attributed to the domain that appears to have injected it. A trusted vendor loading an unreviewed one is the Magecart pattern in a single line — and it is invisible if you inventory by reading the HTML source. ▸ INTEGRITY — SRI, or the lack of it External third-party scripts without an integrity attribute are flagged. Without SRI, a change at the vendor's CDN executes on your checkout with no signal at all. Known payment gateways are exempted from the noise, not from the inventory. ▸ JUSTIFICATION — written once, and kept 6.4.3 asks for "a written justification as to why each is necessary". You type it once; it stays attached to that script on that site. The next scan only asks about what is new. ▸ BASELINE — approve, then diff Approve a clean inventory. Every later scan reports exactly what was added or removed. ▸ CSP — whether your policy is actually a control Detects a Content-Security-Policy meta tag and flags one so permissive it authorises nothing. ▸ SCOPE — is this page even in scope? Detects fields that look like card inputs, by NAME only, to tell you whether 6.4.3 and 11.6.1 apply to this page at all. ▸ EVIDENCE — a document, not a screenshot Export the full inventory with justifications, integrity status and the baseline diff, as a self-contained HTML file that prints to PDF and states its own scope and limits. ━━━ PRICE ━━━ Free. All of it, permanently. No account, no sign-up, no licence, no paid tier, no trial that expires. There is nothing to upgrade to, because there is no paid version. Everything the extension does, it does for everyone. It also has no server: it makes no network requests of its own, so there is nothing behind it that can be shut down or start charging later. ━━━ PRIVACY ━━━ Everything stays in your browser. No account, no server, nothing transmitted. It records script URLs, load method, integrity attributes and a SHA-256 hash of inline contents. From forms it records only the NAMES and autocomplete attributes of card-like fields — never their values, and never anything anyone types. Host access is requested ONE DOMAIN AT A TIME when you start a scan. This extension never asks for access to all sites. ━━━ LIMITS, STATED PLAINLY ━━━ • One page load, one browser, one location, one set of geo and consent conditions. • Scripts inside third-party iframes are not visible — a client-side observer cannot see into another origin. If your card fields live inside a gateway iframe, that is generally good for your scope, and also outside what this can report. • Server-side tag containers are not visible to any browser tool. • Injection attribution is a heuristic read from the call stack. Treat a specific attribution as a lead to verify, not as proof. ━━━ FAQ ━━━ Q: Does it work on a staging checkout? A: Yes. Grant permission for that origin like any other site. Q: Will it break the page? A: No. It only observes; every hook delegates to the original implementation. Q: Can I export for my GRC tool? A: Yes, raw JSON with the full inventory, justifications and baseline. Same button as the HTML export, and free like everything else. Not affiliated with the PCI Security Standards Council or any card brand. PCI DSS is a trademark of the PCI Security Standards Council. Nothing here is compliance advice.
Sep 8, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.