CheckoutScripts6.4.3 · 11.6

PCI DSS 4.0 · REQUIREMENT 6.4.3 AND 11.6

Which scripts run on your payment page?

The median cart page in our scan of 187 United States stores loads 23 third-party hosts. The heaviest, spanx.com, loads 107. Requirement 6.4.3 asks you to list every one of them and write down why it is there. Paste the address and get that list.

No account, no card, nothing installed on your site. Open allbirds.com/cart or nomatic.com/cart to see the output first.

01

What comes back

A table. One row per third-party host, ordered so that anything the page executes sits at the top, and each row carries the host itself, what the vendor says it does, how many of our 187 scanned stores also load it, and a sentence you can adapt for the justification column your assessor will read. The result also carries a fingerprint of the script surface, which is the part requirement 11.6 cares about: it changes when the set of hosts changes, and it does not change when prices or stock levels do.

Of the 448 hosts in the directory, 165 publish no description on their own website. Those deserve your afternoon. A host that nobody in the company can name, sitting on the page where cards are typed, is the exact case requirement 6.4.3 was written for, and it is also the one that takes longest to resolve because the answer usually lives with whoever installed an app eighteen months ago.

Host
Category
Justification line
Seen on
static.klaviyo.com
EXECUTES
Email and SMS
Confirm subscriber list handling procedures and verify data encryption during transmission.
82/187

One row of the real output.

02

What it does not do

Three limits, stated on purpose.

01
It reads the HTML your server delivers. Scripts that a tag manager injects afterwards are not in that HTML, so they are not in the list. 101 of our 187 stores run a Google Tag Manager container and 6 run more than one, so the gap is real. It is the first item on the roadmap below.
02
It is not an ASV scan and not a QSA opinion. It produces an inventory. Your acquirer still decides whether your questionnaire is accepted.
03
It reads pages that are publicly reachable. A checkout behind a login, or one sitting behind a bot challenge, returns the challenge page instead, and the result says so on its face.
Not for you

if you are a level 1 merchant with a QSA on retainer, or if you already run client-side monitoring such as a content-security-policy reporting pipeline. This is built for the SAQ A and SAQ A-EP merchant who fills the questionnaire in personally and has no list at all today.

03

Where the reference numbers come from

On 30 August 2026 we fetched the cart page of 187 United States online stores and recorded every third-party host in the delivered HTML. That scan is the only source of the prevalence figures on this site. Nothing was purchased and nothing was estimated. The method, the store list and the limits are written out on the method page, and the resulting directory of 448 hosts is browsable.

187
stores read
448
hosts in the directory
165
publish no description
137
executed somewhere
04

Roadmap

2 working · 4 planned

Rows marked planned do not work today. They are listed so you can judge whether the finished product would be worth paying for, not to suggest that it already exists.

working
Third-party hosts in the delivered HTML
The inventory 6.4.3 asks for, minus tag-manager children.
working
Script-surface fingerprint
The value 11.6 compares between checks.
planned
Browser-rendered scan, including tags fired by a container
Closes the gap described above. The largest single gap today.
planned
Scheduled re-check with an email when the surface changes
11.6 asks for detection over time, not a single look.
planned
Subresource-integrity hash for each external file
Detects a changed file sitting at an unchanged address.
planned
Spreadsheet export of the inventory
The form the attachment actually reaches the acquirer in.