PCI DSS 4.0 · REQUIREMENT 6.4.3 AND 11.6
Which scripts run on your payment page?
The median cart page in our scan of 187 United States stores loads 23 third-party hosts. The heaviest, spanx.com, loads 107. Requirement 6.4.3 asks you to list every one of them and write down why it is there. Paste the address and get that list.
No account, no card, nothing installed on your site. Open allbirds.com/cart or nomatic.com/cart to see the output first.
What comes back
A table. One row per third-party host, ordered so that anything the page executes sits at the top, and each row carries the host itself, what the vendor says it does, how many of our 187 scanned stores also load it, and a sentence you can adapt for the justification column your assessor will read. The result also carries a fingerprint of the script surface, which is the part requirement 11.6 cares about: it changes when the set of hosts changes, and it does not change when prices or stock levels do.
Of the 448 hosts in the directory, 165 publish no description on their own website. Those deserve your afternoon. A host that nobody in the company can name, sitting on the page where cards are typed, is the exact case requirement 6.4.3 was written for, and it is also the one that takes longest to resolve because the answer usually lives with whoever installed an app eighteen months ago.
One row of the real output.
What it does not do
Three limits, stated on purpose.
if you are a level 1 merchant with a QSA on retainer, or if you already run client-side monitoring such as a content-security-policy reporting pipeline. This is built for the SAQ A and SAQ A-EP merchant who fills the questionnaire in personally and has no list at all today.
Where the reference numbers come from
On 30 August 2026 we fetched the cart page of 187 United States online stores and recorded every third-party host in the delivered HTML. That scan is the only source of the prevalence figures on this site. Nothing was purchased and nothing was estimated. The method, the store list and the limits are written out on the method page, and the resulting directory of 448 hosts is browsable.
Roadmap
2 working · 4 planned
Rows marked planned do not work today. They are listed so you can judge whether the finished product would be worth paying for, not to suggest that it already exists.