| 开发者 | dennishwu |
|---|---|
| 更新时间 | 2026年8月11日 03:54 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
Content-Security-Policy-Report-Only header on the cart and checkout (your payment path, the pages Requirement 6.4.3 is about), built from a baseline of the scripts already on your own site. It never blocks anything. When a new or changed script appears, your browser reports it, so you can catch drift, the early signal of a skimmer, a rogue plugin update, or an unexpected third party./wp-content/plugins/cybershield-checkout-script-monitor, or install it from the Plugins screen.No, and be wary of any plugin that says it does. CyberShield Checkout Script Monitor is a visibility and monitoring tool: it shows you every script on your checkout and alerts you when one changes, which is how you catch a skimmer early. It is Report-Only and never blocks. Deciding what belongs on your payment page, and removing what does not, stays your call.
It is a focused one. Rather than a broad firewall or malware scanner, it does one job well: inventory the scripts on your checkout and payment pages and alert you to changes, mapped to PCI DSS Requirement 6.4.3. It complements a general security plugin; it does not replace one.
No. It gives you visibility and a starting point for Requirement 6.4.3. Compliance is your responsibility and, depending on your setup, may involve your acquirer or a QSA.
No. CyberShield Checkout Script Monitor only uses Content-Security-Policy-Report-Only, which reports but never blocks. Your customers see and experience no change.
The scan reads scripts written into the page HTML. Scripts injected later by other scripts (for example by a tag manager) may not appear. A full external scan can catch those.
To your own WordPress site's database. Nothing is sent to a third party. A future opt-in version may offer a hosted collector, disclosed separately.