xp2023-pix.s3.amazonaws.com in a checkout page script inventory
xp2023-pix.s3.amazonaws.com appeared on 12 of the 187 United States store cart pages we read on 30 August 2026, which is 6% of them, and on 2 it was loaded by a script or iframe tag, meaning it executed in the page.
What it is
Vendor site returned no description; identity not confirmed by this scan.
Source: the title and description published at amazonaws.com, read on 30 August 2026. Quoted there as “Cloud Computing Services - Amazon Web Services (AWS)”.
What to write in the justification column
Verify hosted asset type and access controls prior to classification.
This is a starting sentence, not an assessment. Requirement 6.4.3 wants your reason, written by someone at your company who can defend it.
Stores where we saw it
10 of 12
Up to ten examples from our scan. These are public storefronts and the observation is only that the host appeared in the HTML of their cart page on 30 August 2026.
Where to look next
Other hosts on amazonaws.com
Other unclassified hosts
All 448 hosts in the directory · Scan your own checkout page
Categories in this directory: Payment, Tag manager, Fraud and security, Consent, Analytics, Advertising, Email and SMS, Personalisation, Reviews, Chat and support, Loyalty, Subscriptions, Shipping and returns, Media and social, Fonts and CDN, Merchant-owned, Unclassified.