Give us the address of your checkout page. We load it once, from our own network, and tell you how it is being served.
Free. No sign-up. Nothing is published. Fifteen checks, plus the scripts written into your page.
An invented example, not a real result, so you can see the shape of it before you run one.
Twelve more rows like those, then the scripts written into the page, with the ones served from a domain other than yours marked as such.
This is not a pass or a fail, and it is not an ASV scan. Our ASV accreditation covers external vulnerability scanning, which is a separate service with its own report. What you get here is a free look at how one page is served.
Whether HTTPS is enforced, whether HSTS is set and how it is scoped, and the protocol, issuer and expiry date of the certificate.
Whether a Content Security Policy is present, how it is delivered, and whether it reports violations.
Framing, referrer policy, content type sniffing and permissions policy.
A checkout is where card details are typed, so it is the page an attacker most wants to reach. These headers are how a browser is told to refuse what an attack needs: an unencrypted connection, a script from an address you never approved, or your page loaded inside somebody else's.
PCI DSS requirement 6.4.3 asks you to know every script on that page and write down why each one is there. The script list is a starting point for that inventory. What a script inventory involves.
It describes one page at one moment. The thing that costs a merchant their card data is not how the page is configured today. It is the script that appears on it overnight, from an account nobody was watching, and stays there taking card numbers until somebody notices.
Monitoring is an option on the PCI scanning subscription rather than a separate product, so one price covers the quarterly scan and the daily check of every payment page on your domain.