Kavach

Check · Payment-page integrity · default severity high

Payment-page script integrity

What Kavach checks

The inventory of scripts that can run on your checkout/payment pages, compared against the baseline you authorised.

Why it matters

E-skimming (Magecart-style) attacks inject or alter a script on the payment page to steal card data. PCI DSS 6.4.3 / 11.6.1 address exactly this: authorise, integrity-check and monitor payment-page scripts. (Kavach provides evidence for that control; it does not certify PCI compliance.)

How an attacker uses it

  1. Attacker adds one small script to your checkout page.
  2. It reads card numbers as customers type them.
  3. Months pass before anyone notices.

How to fix it

Review the changed/added scripts, remove anything unauthorised, add SRI, and re-baseline. Investigate unexpected additions as a possible compromise.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.

Scan your site free → Monitor it continuously