Do you know what code runs on your checkout page?
A typical checkout page loads scripts from ten to forty different companies — analytics, chat, pixels, reviews, upsell apps. Every one of them can read what your customer types, including the card field. Most of them were added years ago by someone who has left.
We open your checkout page the way a real customer's browser does, record every script that runs, and tell you the moment one of them changes.
At a glance
CheckoutWatch is a monitoring and evidence service from OpenX24: we open your checkout page the way a customer's browser does, record every script that runs on it, and tell you when one appears or changes. The first scan is free, with a report within 24 hours; the full audit is £395, and monitoring is £79 a month or £790 a year.
- Who it’s for
- Online stores taking card payments that want to know which third-party scripts run on the payment page, and to show their acquirer a dated record of it.
- What you get
- Every script on your checkout page and every company serving it, the ones we cannot identify, and, with monitoring, an alert the day one appears or changes. It is evidence, not a compliance certificate.
- Price
- First scan free. Full audit £395. Monitoring £79 a month, or £790 a year.
- How long
- First report within 24 hours. The full audit is delivered in 3 business days.
What a real scan found on one store
A single UK store, scanned once. Nothing unusual about it.
That third number is the one that matters. Those 95 scripts were pulled in by other scripts after the page opened. Reading your theme, or using View Source, would not reveal a single one of them.
Why this is worth paying attention to
Nobody has to break into your store. An attacker compromises one of your suppliers — a chat widget, an abandoned app, a marketing tag. Their script keeps loading from the same address under the same name, and now it also copies the card number as it is typed.
Nothing breaks. Orders still go through. Your site looks perfect. One skimming network exposed in January 2026 had been running since 2022 before anyone noticed. Most shop owners find out when their bank calls them.
And the rules changed under you.
Since 31 March 2025, PCI DSS requirements 6.4.3 and 11.6.1 ask merchants to keep an inventory of every script on the payment page, authorise each one, and detect unauthorised change.
If you use a hosted checkout you may think this does not apply to you. In January 2025 those two requirements were removed from SAQ A — and replaced with a condition you have to confirm instead: that your site is not susceptible to attacks from scripts. That is a sentence you sign. Most merchants have signed it without any way to show it is true.
How it works
No app to install. Nothing added to your store. Nothing that can slow your site down.
We open your checkout page in a real browser and record every script: where it came from, its exact fingerprint, and whether it has an integrity check.
One page, in plain words. Every company with code on your checkout, and a short list of the ones we cannot identify for you to confirm or remove.
We scan again on a schedule. If a new script appears, an existing one changes, or data starts going somewhere new, you hear about it that day.
Because we read your checkout page the same way any shopper does, we need no access to your store, no admin login, no app permissions and no code on your site.
Price
The first scan is free and you keep the report either way.
First scan
- Every script on your checkout page
- Every company serving code to it
- The ones we cannot identify
- Yours to keep, no obligation
Full audit
- Everything in the free scan
- Every page that touches payment, not just one
- Each script traced to the app or person that added it
- A written list of what to remove, and why
- Security headers checked and explained
- A dated evidence pack you can hand to your acquirer
Monitoring
- Automatic re-scan on a schedule
- Alert when a script appears or changes
- Alert when data goes somewhere new
- Monthly dated report for your records
- Full history kept, nothing overwritten
Running more than one store? Email hello@openx24.com and we will price them together.
Questions people ask
One scan tells you what is actually there
Send your store address. The first report comes back within 24 hours and it costs nothing.
Scope and limits. CheckoutWatch is a monitoring and evidence service operated by OpenX24. It reports the scripts observed on a page at the time of each scan. It is not a security assessment and it does not certify compliance with any standard. OpenX24 is not a Qualified Security Assessor and is not affiliated with, endorsed by, or approved by the PCI Security Standards Council. References to PCI DSS requirements are descriptive only. Your acquiring bank or assessor determines what satisfies your obligations. Findings reflect the pages scanned, at the time scanned, from one location; results can differ by page, region and visitor.