Every script on a page that takes card payments must be inventoried, justified, and authorized.
Client-side security scanner
Point Glasswatch at a URL — yours or a vendor’s — and see every script, third-party destination, tracker, cookie, and security header it loads, with a transparent A–F risk grade. Nothing to install.
Tag-based tools only see the sites you control. Glasswatch looks at any page from the outside — the way a real visitor’s browser does.
Every script on a page reaches out to somewhere. Glasswatch maps each destination, flags the trackers in amber, and shows the request chain a visitor’s browser actually follows. (illustrative — run a scan for your real map)
If your checkout takes a card, two requirements now apply to the scripts running in your customers’ browsers. A firewall can’t see them — they execute client-side. This is the demand that isn’t optional.
Every script on a page that takes card payments must be inventoried, justified, and authorized.
Payment-page scripts and security headers must be monitored for tampering and changes — at least every 7 days. Active since 31 March 2025.
Run a scan and Glasswatch maps every finding to 6.4.3 and 11.6.1 — so the gap is named in the language your QSA uses.
The free scan is the entry point. The same outside-in pipeline powers monitoring, authorization workflows, and QSA-ready exports.
Point-in-time outside-in risk report with an A–F grade.
Inventory every payment-page script with an approve/deny workflow (PCI 6.4.3).
Re-scan on a cadence, diff, and alert on changes (PCI 11.6.1).
Third-party map, where requests go, known-vuln libraries, header grading over time.
Scan and continuously monitor any vendor's site — no install, no permission needed.
One-click PCI 6.4.3 / 11.6.1 evidence export, QSA-ready.
The paid product re-scans on a cadence, diffs every capture, and alerts the moment a payment page changes — exactly what PCI 11.6.1 demands.
Grade trend over a week: a silent third-party change drops the grade on Thursday, fires an alert, and is logged as evidence once resolved.
The point-in-time scan is free, forever. Continuous monitoring, authorization, and evidence export are where the recurring value lives.
Point-in-time, one site
PCI 6.4.3 / 11.6.1 for one brand
For a security team
TPRM & scale
Outside-in · nothing installed
Run a free scan now, or book a walkthrough of continuous monitoring and PCI evidence export.