TugraCyber keeps an inventory of every script running on your checkout page and alerts you when a script's content changes silently, which is the signature of Magecart-style card skimming attacks.
- Runs only on the checkout page. This is exactly the scope of PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1.
- Script inventory. A SHA-256 hash of each script's content is recorded, so silent changes are caught immediately.
- Removed and returning script detection. You get an alert when a known script disappears from the page, or reappears after being marked as removed.
- Late-added script detection. Scripts that are added to the checkout page after it has loaded are also inventoried.
- Outbound address monitoring. You get an alert when the checkout page starts sending requests to a new external domain, which is where skimmed card data is typically sent.
- PCI DSS 6.4.3/11.6.1 report. Available from the dashboard in your TugraCyber account.
This plugin only adds the monitoring agent to your checkout page. The dashboard, alerts and reports live in your
TugraCyber account. Setup requires an account and a collector address.
Requirements
- WooCommerce must be active (monitoring runs only on the WooCommerce checkout page).
- A TugraCyber account and a collector address.