🔎 CheckoutWatch · First scan free · Then £79/month · Report in 24 hours

Do you know what code runs on your checkout page?

A typical checkout page loads scripts from ten to forty different companies — analytics, chat, pixels, reviews, upsell apps. Every one of them can read what your customer types, including the card field. Most of them were added years ago by someone who has left.

We open your checkout page the way a real customer's browser does, record every script that runs, and tell you the moment one of them changes.

At a glance

CheckoutWatch is a monitoring and evidence service from OpenX24: we open your checkout page the way a customer's browser does, record every script that runs on it, and tell you when one appears or changes. The first scan is free, with a report within 24 hours; the full audit is £395, and monitoring is £79 a month or £790 a year.

Who it’s for
Online stores taking card payments that want to know which third-party scripts run on the payment page, and to show their acquirer a dated record of it.
What you get
Every script on your checkout page and every company serving it, the ones we cannot identify, and, with monitoring, an alert the day one appears or changes. It is evidence, not a compliance certificate.
Price
First scan free. Full audit £395. Monitoring £79 a month, or £790 a year.
How long
First report within 24 hours. The full audit is delivered in 3 business days.

What a real scan found on one store

A single UK store, scanned once. Nothing unusual about it.

182scripts running on the page
73served by third parties
95with no tag anywhere in the page source
16third-party addresses data was sent to

That third number is the one that matters. Those 95 scripts were pulled in by other scripts after the page opened. Reading your theme, or using View Source, would not reveal a single one of them.

Why this is worth paying attention to

Nobody has to break into your store. An attacker compromises one of your suppliers — a chat widget, an abandoned app, a marketing tag. Their script keeps loading from the same address under the same name, and now it also copies the card number as it is typed.

Nothing breaks. Orders still go through. Your site looks perfect. One skimming network exposed in January 2026 had been running since 2022 before anyone noticed. Most shop owners find out when their bank calls them.

And the rules changed under you.

Since 31 March 2025, PCI DSS requirements 6.4.3 and 11.6.1 ask merchants to keep an inventory of every script on the payment page, authorise each one, and detect unauthorised change.

If you use a hosted checkout you may think this does not apply to you. In January 2025 those two requirements were removed from SAQ A — and replaced with a condition you have to confirm instead: that your site is not susceptible to attacks from scripts. That is a sentence you sign. Most merchants have signed it without any way to show it is true.

How it works

No app to install. Nothing added to your store. Nothing that can slow your site down.

Step 1 — We scan

We open your checkout page in a real browser and record every script: where it came from, its exact fingerprint, and whether it has an integrity check.

Step 2 — You get the list

One page, in plain words. Every company with code on your checkout, and a short list of the ones we cannot identify for you to confirm or remove.

Step 3 — We keep watching

We scan again on a schedule. If a new script appears, an existing one changes, or data starts going somewhere new, you hear about it that day.

Because we read your checkout page the same way any shopper does, we need no access to your store, no admin login, no app permissions and no code on your site.

Price

The first scan is free and you keep the report either way.

First scan

Free
Report within 24 hours
  • Every script on your checkout page
  • Every company serving code to it
  • The ones we cannot identify
  • Yours to keep, no obligation
Get my free scan

Full audit

£395
One-off · delivered in 3 business days
  • Everything in the free scan
  • Every page that touches payment, not just one
  • Each script traced to the app or person that added it
  • A written list of what to remove, and why
  • Security headers checked and explained
  • A dated evidence pack you can hand to your acquirer
Book the audit

Monitoring

£79 /month
Or £790 a year — two months free
  • Automatic re-scan on a schedule
  • Alert when a script appears or changes
  • Alert when data goes somewhere new
  • Monthly dated report for your records
  • Full history kept, nothing overwritten
Start monitoring

Running more than one store? Email hello@openx24.com and we will price them together.

Questions people ask

Will this slow my store down or break anything?
No. We add nothing to your site and install nothing. We load your public checkout page from outside, exactly as a shopper does.
I am on Shopify. Is my checkout not already handled?
Shopify secures its own checkout, and that part is genuinely strong. What it does not cover is the scripts you and your apps have added to your own pages. That is the part you are responsible for, and it is the part we read.
Does this make me compliant?
No, and be careful with anyone who says it does. We give you an accurate, dated record of what runs on your page. Whether that satisfies your obligations is decided by your acquirer or your assessor — this is the evidence you give them, not a certificate.
What if you find something bad?
We tell you plainly, in the report, with the exact address of the script. If you want it removed we can quote that separately — but the finding is yours regardless, including on the free scan.
Can I cancel the monitoring?
Any time, and you keep every report we have produced.

One scan tells you what is actually there

Send your store address. The first report comes back within 24 hours and it costs nothing.

A person reads every request. The audit and monitoring are confirmed by email with a secure Stripe link.

Scope and limits. CheckoutWatch is a monitoring and evidence service operated by OpenX24. It reports the scripts observed on a page at the time of each scan. It is not a security assessment and it does not certify compliance with any standard. OpenX24 is not a Qualified Security Assessor and is not affiliated with, endorsed by, or approved by the PCI Security Standards Council. References to PCI DSS requirements are descriptive only. Your acquiring bank or assessor determines what satisfies your obligations. Findings reflect the pages scanned, at the time scanned, from one location; results can differ by page, region and visitor.