Check · Payment-page integrity · default severity high
Payment-page script integrity
What Kavach checks
The inventory of scripts that can run on your checkout/payment pages, compared against the baseline you authorised.
Why it matters
E-skimming (Magecart-style) attacks inject or alter a script on the payment page to steal card data. PCI DSS 6.4.3 / 11.6.1 address exactly this: authorise, integrity-check and monitor payment-page scripts. (Kavach provides evidence for that control; it does not certify PCI compliance.)
How an attacker uses it
- Attacker adds one small script to your checkout page.
- It reads card numbers as customers type them.
- Months pass before anyone notices.
How to fix it
Review the changed/added scripts, remove anything unauthorised, add SRI, and re-baseline. Investigate unexpected additions as a possible compromise.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.