{"id":349533,"date":"2026-08-10T19:54:49","date_gmt":"2026-08-10T19:54:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/checkout-script-monitor-for-woocommerce\/"},"modified":"2026-08-10T19:54:21","modified_gmt":"2026-08-10T19:54:21","slug":"cybershield-checkout-script-monitor","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/cybershield-checkout-script-monitor\/","author":23543199,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.0.3","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"CyberShield Checkout Script Monitor for WooCommerce","header_author":"CyberShield Studio (Dennis Wu, CISSP, PCIP)","header_description":"See every script on your checkout and where you stand on PCI DSS 6.4.3, in plain English. A readiness and visibility tool, not a compliance guarantee.","assets_banners_color":"444e60","last_updated":"2026-08-10 19:54:21","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/cybershieldstudio.com\/tools\/page-checker","header_author_uri":"https:\/\/cybershieldstudio.com","rating":5,"author_block_rating":0,"active_installs":0,"downloads":26,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"dennishwu","date":"2026-08-10 19:54:21"}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3641057,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3641057,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3641057,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3641057,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3641057,"resolution":"1","location":"assets","locale":"","width":1996,"height":1086},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3641057,"resolution":"2","location":"assets","locale":"","width":1996,"height":2954},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3641057,"resolution":"3","location":"assets","locale":"","width":1996,"height":802},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3641057,"resolution":"4","location":"assets","locale":"","width":1996,"height":810}},"screenshots":{"1":"First-run setup: the guided 3-step onboarding on the Checkout Scripts screen \u2014 scan your checkout, mark the scripts it finds as trusted, then turn on monitoring.","2":"Checkout Scripts: an at-a-glance count of the scripts on your checkout, then every script with its source domain, who loaded it (WordPress core, a plugin or theme, or an outside vendor), and its tamper-check (SRI) status; rows are shaded by trust once you set a trusted list.","3":"Alerts: a new or changed script that is not on your trusted list, with times seen, last seen, and a one-click \"Trust it\".","4":"Settings: the monitoring toggle (Content-Security-Policy-Report-Only) and the technical details of how it works."}},"plugin_section":[],"plugin_tags":[275069,3148,275068,25524,286],"plugin_category":[45],"plugin_contributors":[275070],"plugin_business_model":[],"class_list":["post-349533","plugin","type-plugin","status-publish","hentry","plugin_tags-card-skimming","plugin_tags-checkout","plugin_tags-ecommerce-security","plugin_tags-pci-compliance","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-dennishwu","plugin_committers-dennishwu"],"banners":{"banner":"https:\/\/ps.w.org\/cybershield-checkout-script-monitor\/assets\/banner-772x250.png?rev=3641057","banner_2x":"https:\/\/ps.w.org\/cybershield-checkout-script-monitor\/assets\/banner-1544x500.png?rev=3641057","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/cybershield-checkout-script-monitor\/assets\/icon-128x128.png?rev=3641057","icon_2x":"https:\/\/ps.w.org\/cybershield-checkout-script-monitor\/assets\/icon-256x256.png?rev=3641057","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/cybershield-checkout-script-monitor\/assets\/screenshot-1.png?rev=3641057","caption":"First-run setup: the guided 3-step onboarding on the Checkout Scripts screen \u2014 scan your checkout, mark the scripts it finds as trusted, then turn on monitoring."},{"src":"https:\/\/ps.w.org\/cybershield-checkout-script-monitor\/assets\/screenshot-2.png?rev=3641057","caption":"Checkout Scripts: an at-a-glance count of the scripts on your checkout, then every script with its source domain, who loaded it (WordPress core, a plugin or theme, or an outside vendor), and its tamper-check (SRI) status; rows are shaded by trust once you set a trusted list."},{"src":"https:\/\/ps.w.org\/cybershield-checkout-script-monitor\/assets\/screenshot-3.png?rev=3641057","caption":"Alerts: a new or changed script that is not on your trusted list, with times seen, last seen, and a one-click \"Trust it\"."},{"src":"https:\/\/ps.w.org\/cybershield-checkout-script-monitor\/assets\/screenshot-4.png?rev=3641057","caption":"Settings: the monitoring toggle (Content-Security-Policy-Report-Only) and the technical details of how it works."}],"raw_content":"<!--section=description-->\n<p>Card-skimming attacks (also called e-skimming or Magecart) work by slipping a malicious script onto your checkout, where it quietly copies your customers' card details as they type. The hard part for a store owner is easy to miss: you cannot watch what you cannot see. A typical WooCommerce checkout loads a dozen or more scripts from plugins, themes, and third parties, and nothing normally tells you when that list changes.<\/p>\n\n<p>CyberShield Checkout Script Monitor gives you that visibility. It scans your own store pages and shows you every script loading on them, so you can see what runs on your checkout and where you stand on PCI DSS Requirement 6.4.3. <strong>It is a readiness and visibility aid. It does not make you PCI compliant, it does not block anything, and it is not affiliated with or endorsed by the PCI Security Standards Council.<\/strong> The compliance decision stays yours.<\/p>\n\n<p>What it does:<\/p>\n\n<ul>\n<li><strong>Script inventory across your storefront.<\/strong> Scans your home, shop, cart, and checkout pages and lists every script they load from a URL, your own and third-party alike, named by source (the WordPress plugin, theme, or core component for your own scripts, or the outside vendor for external ones), with its integrity (SRI) status. The scan casts this wider net for visibility; live monitoring (below) focuses on the payment path.<\/li>\n<li><strong>Plain-English PCI 6.4.3 readout.<\/strong> An at-a-glance line counts the scripts on your checkout and how many lack an integrity (SRI) check, and a built-in explainer covers what Requirement 6.4.3 asks and what to do, in merchant language.<\/li>\n<li><strong>Drift monitoring (optional, off by default).<\/strong> Emits a <code>Content-Security-Policy-Report-Only<\/code> header on the cart and checkout (your payment path, the pages Requirement 6.4.3 is about), built from a baseline of the scripts already on <strong>your own<\/strong> site. It never blocks anything. When a new or changed script appears, your browser reports it, so you can catch drift, the early signal of a skimmer, a rogue plugin update, or an unexpected third party.<\/li>\n<\/ul>\n\n<p>How the baseline works, and why it is safe:<\/p>\n\n<p>CyberShield Checkout Script Monitor does not ship a list of \"trusted\" sources. That would mean deciding on your behalf which third parties are safe, which is exactly the risk you want to avoid (a trusted provider getting compromised is a real attack path). Instead, the baseline is the scripts already present on your own site on the day you set it. Report-Only then flags anything that later differs from that baseline. Honest note: the baseline is \"what is here now,\" not a clean bill of health, so review your inventory and remove anything unwanted before you set it.<\/p>\n\n<p>Who it is for:<\/p>\n\n<p>WooCommerce store owners who want to see what runs on their payment page and be told when it changes, and the developers and agencies who support them. The 6.4.3 readout maps directly to the script-inventory requirement (mandatory for SAQ A-EP and D) and gives SAQ A merchants the evidence to make the \"not susceptible to scripts\" self-attestation from what they can see, not from hope.<\/p>\n\n<p>Privacy: the plugin makes no outbound connections except scanning your own site's pages when you click \"Scan my checkout.\" CSP reports are received and stored on your own WordPress site; the visitor IP address and referrer are dropped and never stored.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin uses no external or third-party services. It sends no data anywhere.<\/p>\n\n<p>The only HTTP requests it makes are to your own site's URLs (home, shop, cart, checkout) when you click \"Scan my checkout\", to read your own pages' HTML. Monitoring reports are posted by your visitors' browsers to a REST endpoint on your own site and stored in your own database.<\/p>\n\n<p>The vendor domain names that appear in the plugin's source code (Google Tag Manager, Stripe, PayPal, Meta, cdnjs, unpkg, and similar) are a recognition list only: they are used to put a readable label on scripts already present on your own pages. The plugin never loads files from, embeds, or connects to any of those domains.<\/p>\n\n<h3>About the author<\/h3>\n\n<p>CyberShield Checkout Script Monitor is built by CyberShield Studio, a founder-led PCI compliance practice for e-commerce merchants. Its maker, Dennis Wu, holds the CISSP and PCIP certifications and has 30+ years in security. The plugin is open source (GPLv2), so you can read every line yourself.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin to <code>\/wp-content\/plugins\/cybershield-checkout-script-monitor<\/code>, or install it from the Plugins screen.<\/li>\n<li>Activate it. A <strong>CyberShield Checkout Script Monitor<\/strong> menu appears in your admin sidebar.<\/li>\n<li>Open <strong>CyberShield Checkout Script Monitor &gt; Checkout Scripts<\/strong> and follow the short 3-step setup: scan your checkout, mark the scripts it finds as trusted, and (optionally) turn on monitoring.<\/li>\n<li>With monitoring on, any new or changed script on your checkout appears under <strong>Alerts<\/strong> for you to review. Trust it if you recognize it, or remove it from your store if you do not.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20stop%20card%20skimming%20or%20magecart%3F\"><h3>Does this stop card skimming or Magecart?<\/h3><\/dt>\n<dd><p>No, and be wary of any plugin that says it does. CyberShield Checkout Script Monitor is a visibility and monitoring tool: it shows you every script on your checkout and alerts you when one changes, which is how you catch a skimmer early. It is Report-Only and never blocks. Deciding what belongs on your payment page, and removing what does not, stays your call.<\/p><\/dd>\n<dt id=\"is%20this%20a%20woocommerce%20security%20plugin%3F\"><h3>Is this a WooCommerce security plugin?<\/h3><\/dt>\n<dd><p>It is a focused one. Rather than a broad firewall or malware scanner, it does one job well: inventory the scripts on your checkout and payment pages and alert you to changes, mapped to PCI DSS Requirement 6.4.3. It complements a general security plugin; it does not replace one.<\/p><\/dd>\n<dt id=\"does%20this%20make%20my%20store%20pci%20compliant%3F\"><h3>Does this make my store PCI compliant?<\/h3><\/dt>\n<dd><p>No. It gives you visibility and a starting point for Requirement 6.4.3. Compliance is your responsibility and, depending on your setup, may involve your acquirer or a QSA.<\/p><\/dd>\n<dt id=\"will%20turning%20on%20monitoring%20break%20my%20checkout%3F\"><h3>Will turning on monitoring break my checkout?<\/h3><\/dt>\n<dd><p>No. CyberShield Checkout Script Monitor only uses <code>Content-Security-Policy-Report-Only<\/code>, which reports but never blocks. Your customers see and experience no change.<\/p><\/dd>\n<dt id=\"why%20do%20some%20scripts%20not%20show%20up%3F\"><h3>Why do some scripts not show up?<\/h3><\/dt>\n<dd><p>The scan reads scripts written into the page HTML. Scripts injected later by other scripts (for example by a tag manager) may not appear. A full external scan can catch those.<\/p><\/dd>\n<dt id=\"where%20do%20my%20alerts%20go%3F\"><h3>Where do my alerts go?<\/h3><\/dt>\n<dd><p>To your own WordPress site's database. Nothing is sent to a third party. A future opt-in version may offer a hosted collector, disclosed separately.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First public release: checkout script inventory with a plain-English PCI DSS 6.4.3 readout, and optional Content-Security-Policy Report-Only drift monitoring for your cart and checkout.<\/li>\n<\/ul>","raw_excerpt":"Monitor the scripts on your WooCommerce checkout, spot card-skimming risk, and get alerted when one changes. Visibility, not a compliance guarantee.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/349533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=349533"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dennishwu"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=349533"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=349533"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=349533"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=349533"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=349533"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=349533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}