Payment-page scripts · Purchase-path accessibility · WooCommerce, Shopify, BigCommerce

Know what runs on your checkout. And who can't use it.

One scan does both. It inventories every script on your payment page, and it tests the whole purchase path against WCAG 2.1 AA. Each half keeps its own dated record, and each one is something you will be asked for.

We scan it by hand and reply personally within two business days. No signup form, no account to create.

Script inventory northfield-outfitters.example / checkout
  • 21 script families
  • 17 authorized
  • 1 awaiting authorization
  • 1 rejected
  • 13 third-party hosts
Scripts on the payment page, with status, justification and approver
ScriptStatusJustification · approver · date
js.stripe.com/v3 Approved Stripe.js — required by our payment processor to serve the card fields.D. Whitfield · 2025-10-01
www.googletagmanager.com/gtm.js Approved Tag manager. Container publishing is limited to two named users.D. Whitfield · 2025-10-01
bat.bing.com/bat.js Unreviewed Awaiting authorization. First seen 2026-09-03.
js.hs-scripts.com/* Rejected Added to the tag-manager container by mistake. Not needed on checkout; removed.D. Whitfield · 2026-02-11
pay.google.com/gp/p/js/pay.js Conditional Loads on some visits only.D. Whitfield · 2025-10-01
Accessibility findings northfield-outfitters.example / purchase path
  • 8 open findings
  • 1 critical
  • 6 serious
  • 4 resolved this year
  • 5 pages tested
Open accessibility findings, with impact, page and WCAG success criterion
RuleImpactPageWhat it means for a shopper
select-name Critical Checkout The state dropdown has no name a screen reader can read out.WCAG 4.1.2 · open since 2026-08-14
label Serious Checkout Three address fields have no label attached to them.WCAG 4.1.2 · open since 2026-08-14
color-contrast Serious Product The price sits at 2.9:1 against its background; AA asks for 4.5:1.WCAG 1.4.3 · open since 2026-06-02
image-alt Serious Category Nine product images have no alt text, so their listings are unreadable aloud.WCAG 1.1.1 · open since 2026-09-03
button-name Resolved Cart The remove-item button was unnamed. Fixed and confirmed by the next scan.Resolved 2026-03-05

The problem

Two records your store is asked for. Almost no store keeps either.

One comes from the card brands. One comes from accessibility law and the shoppers it exists for. Both want the same thing, evidence kept over time, and neither is realistic to keep by hand.

Payment-page scripts

PCI DSS v4.0.1 · Requirements 6.4.3 and 11.6.1 · in force since 31 March 2025

What the rule asks
An inventory of every script on the payment page, each with a written justification and someone's authorization. Then a check, at least weekly, that none of those scripts or the page's security headers changed without you knowing.
Why nobody has it
Scripts arrive through tag managers, plugins and theme updates. Nobody is watching the checkout on a Tuesday night when a vendor ships a new build.
What StoreSweep records
Every script family, who approved it, the reason and the date. Every change since, confirmed by a second scan, with what you decided about it.

Accessibility of the purchase path

WCAG 2.1 · Level A and AA · home, category, product, cart, checkout

What the standard asks
That a shopper using a keyboard, a screen reader or low vision can find a product, put it in a cart and pay. WCAG 2.1 AA is the benchmark courts, agencies and procurement teams reference.
Why nobody has it
A one-time audit goes stale the day a theme updates. Most stores have never had one at all, and have no way to show what they fixed.
What StoreSweep records
Findings by rule and page with fix guidance, dated. Fixes recorded as resolved. Risks you accept recorded with your reason. A monitoring trail, not a snapshot.

How it works

A scan is a shopper who reads carefully and buys nothing.

  1. Step 01

    Shops your store like a customer

    Home page, a category, a product. One item into the cart with your own button. Then the checkout.

  2. Step 02

    Inventories every script and audits every page

    Every script family and host on the payment page, every security header, and an axe-core pass on each page of the path.

  3. Step 03

    Confirms with a second scan before it says anything

    A difference is re-scanned within the hour. It is reported only if the second scan shows it too.

  4. Step 04

    Records the decision, sends the alert, builds the pack

    Your approve, reject or accept-risk is the dated record. Alerts go out by email. The evidence pack assembles itself.

The scanner never enters personal or payment information, never places an order, identifies itself as StoreSweepBot on every request, and honours your robots.txt. How the bot behaves, in full.

Two halves, equal weight

One scan. Two records your store is asked for.

PCI DSS v4.0.1 · 6.4.3 · 11.6.1

Payment-page script monitoring

What it watches

  • Every script tag and script family on the payment page, including ones the browser did not load
  • Every outside domain that serves code to the page
  • The content of your first-party scripts, by hash
  • Security headers: Content-Security-Policy, HSTS, X-Frame-Options, Referrer-Policy and the rest
  • How card entry is served: iframe, redirect or on-page fields

What it records

  • The 6.4.3 inventory: script, justification, approver, date
  • Every confirmed change with your disposition
  • Header status and history
  • A pre-filled 12.3.1 targeted-risk-analysis template for the check frequency

WCAG 2.1 · Level A and AA · axe-core

Accessibility monitoring

What it watches

  • Home, a category, a product, the cart and the checkout, on every scan
  • Form labels, names of controls, alt text, contrast, focus order, landmarks and the other criteria automated testing can detect
  • New critical failures on cart or checkout, which alert immediately

What it records

  • Findings by impact and by WCAG success criterion, with the page and the fix guidance
  • Fixes recorded as resolved on the date the scan stopped seeing them
  • Risks you accept, recorded with your reason
  • Items that need a manual review, listed so a consultant can start there

What you get

An alert when it matters. A dashboard when you look. A pack when someone asks.

Immediate alerts by email for a confirmed change on the payment page or a new critical failure on cart or checkout. A weekly digest for everything else, and it leads with what got fixed.

Accessibility traildashboard
  • 8 open findings
  • 1 critical
  • 6 serious
  • 4 resolved this year
RuleImpactPageWCAG
select-nameCriticalProduct4.1.2
color-contrastSeriousCategory1.4.3
labelResolvedCheckout4.1.2

label resolved 2026-03-05 — “Labels added to the three address fields.”

Monitoring Evidence Pack
northfield-outfitters.example
Period
Sep 25, 2025 – Sep 17, 2026
Pack
EP-20260917-15B661
Platform
WooCommerce · Stripe (iframe)
Prepared for
Northfield Outfitters

Section 1 Payment-page scripts — inventory, change log, headers, 12.3.1 template

Section 2 Accessibility — findings by impact and criterion, trend, resolved and accepted-risk log

This report documents monitoring and authorization records supporting PCI DSS v4.0.1 Requirements 6.4.3 and 11.6.1. It is not a compliance certification or attestation.

Automated WCAG 2.1 AA testing detects a subset of accessibility criteria. This report documents monitoring activity and detected issues. It is not a certification of compliance and does not assess or guarantee legal exposure.

The evidence pack

The document you hand over when someone asks what you have.

A PDF assembled from the records the monitor kept. Your SAQ, your processor, a QSA or an accessibility consultant can read it without a login.

Section 1 — Payment-page scripts

  1. Script inventory with every justification, approver and timestamp
  2. Change log with dispositions, unconfirmed changes marked as such
  3. Security header status and history
  4. Pre-filled PCI DSS 12.3.1 targeted-risk-analysis template with signature lines

Section 2 — Accessibility

  1. Findings by impact and by WCAG 2.1 success criterion
  2. The trend over the period
  3. New, resolved and accepted-risk log with reasons
  4. Items needing manual review

Delivered

  • On demand, from the dashboard
  • Automatically, two weeks before your SAQ anniversary
  • Quarterly on Pro and Agency tiers
  • White-labelled for agencies

Two scope notes appear on every page of every pack:

Scope · Section 1

This report documents monitoring and authorization records supporting PCI DSS v4.0.1 Requirements 6.4.3 and 11.6.1. It is not a compliance certification or attestation.

Scope · Section 2

Automated WCAG 2.1 AA testing detects a subset of accessibility criteria. This report documents monitoring activity and detected issues. It is not a certification of compliance and does not assess or guarantee legal exposure.

See a sample evidence pack (PDF)

How the bot behaves

It reads what's there and leaves.

Every request from the scanner carries the User-Agent StoreSweepBot/0.1 (+https://storesweep.app/bot). If you see it in your logs, that page explains everything it did and how to opt out.

  • Loads home, a category, a product, the cart and the checkout
  • Adds one item to the cart with your own add-to-cart control
  • Obeys any robots.txt group addressed to StoreSweepBot, and a site-wide Disallow: /
  • Never types into a field, never creates an account, never places an order
  • Never solves a CAPTCHA, never disguises itself

Read the full page for site owners and developers

To opt out entirely, add this to your robots.txt:

User-agent: StoreSweepBot
Disallow: /

Or email hello@storesweep.app and the store is excluded within one business day, permanently.

Pricing

One store, both halves, weekly: $79 a month.

We are onboarding by hand right now. Every plan starts the same way: we scan your checkout, and reply personally within two business days.

Annual is two months free.
  • Free

    A first look at one store.

    $0
    no card, no expiry
    Sites
    1
    Scan cadence
    Monthly
    • Script inventory of the payment page
    • Top accessibility findings
    • No history, no alerts
    Get a free scan of your checkout
  • Single module

    One half only: payment-page scripts or accessibility.

    $490/ year
    two months free against monthly
    Sites
    1
    Scan cadence
    Weekly
    • PCI or accessibility monitoring
    • Immediate alerts and weekly digest
    • Evidence pack for that half
    Get a free scan of your checkout
  • The default

    Starter

    One store, both halves, on 11.6.1's weekly line.

    $790/ year
    two months free against monthly
    Sites
    1
    Scan cadence
    Weekly
    • Payment-page scripts and accessibility
    • Immediate alerts, weekly digest
    • Dashboard with inventory and trail
    • Evidence pack, both sections
    Get a free scan of your checkout
  • Pro

    Up to five stores, scanned daily.

    $1,790/ year
    two months free against monthly
    Sites
    5
    Scan cadence
    Daily
    • Everything in Starter
    • Full history
    • Quarterly evidence packs
    Get a free scan of your checkout
  • Agency 25

    A portfolio of client stores under your name.

    $5,490/ year
    two months free against monthly
    Sites
    25
    Scan cadence
    Set per site
    • Everything in Pro
    • White-label evidence packs
    • $15 per site over 25
    Talk to us
  • Agency 100

    Larger portfolios, priority handling.

    $14,990/ year
    two months free against monthly
    Sites
    100
    Scan cadence
    Set per site
    • Everything in Agency 25
    • White-label, priority support
    • $12 per site over 100
    Talk to us

PCI DSS 11.6.1's default cadence is at least once every seven days. Free is below that line on purpose; Starter is on it.

Questions

Honest answers.

Does this make my store meet PCI DSS?

No. StoreSweep keeps the records Requirements 6.4.3 and 11.6.1 ask for: the script inventory with authorizations, and the dated change-detection trail. Your SAQ is still yours and your processor's, and the other requirements are still your responsibility.

Does this make my store accessible?

No, and be wary of anyone who says otherwise. Automated testing against WCAG 2.1 AA finds a real portion of accessibility problems, not all of them. What StoreSweep gives you is the machine-checkable part, checked every week, with a dated record of what was found, what got fixed and what you decided to accept and why. An audit by a specialist and testing with real assistive technology are still worth doing. This is what keeps the ground from moving under them.

Which accessibility problems can you actually find?

Form fields with no label, controls with no name a screen reader can announce, images with no alt text, colour contrast below AA, focus order, landmarks, and the other criteria automated tools detect reliably. We run axe-core on all five pages of the purchase path, not just the home page, because the checkout is where a barrier costs you the sale.

Whether alt text is meaningful, or whether a flow makes sense to someone using a screen reader, needs a person. Those are listed separately in your pack as items for manual review, so a consultant knows where to start.

Which SAQ am I?

We report what we observe about how card entry is served on your checkout: an iframe from your processor, a redirect, or fields on your own page. The SAQ determination itself is made by you and your acquirer. The evidence pack records the observation so that conversation is shorter.

We already had an accessibility audit. Why would we need this?

Because an audit is a photograph and a store is a film. A theme update, a new plugin, a seasonal banner or a checkout change can reintroduce a barrier the week after the report lands, and nobody finds out until a shopper gives up. Monitoring is what turns that audit into something you can still stand behind a year later, with the dates to show it.

Do you place orders?

Never. The scanner adds one item to the cart with your own add-to-cart control and loads the checkout page. It types nothing into any field and never submits a form. The cart it creates is abandoned like any other.

What if my store blocks bots?

Then we can't monitor it, and we say so. The scanner identifies itself and never tries to look like a person, so a bot wall or a CAPTCHA on the checkout stops it. Most stores can allow a named User-Agent through their bot protection; we tell you exactly what to allow.

Which platforms do you support?

WooCommerce, Shopify and BigCommerce, and most custom carts. If a shopper can reach your checkout by clicking, the scanner can too. The free scan is how we find out for your store.

Will I get alerts every day?

No. Nothing alerts off one scan. A difference is re-scanned within the hour and reported only if the second scan shows it too. Confirmed changes on the payment page and new critical failures on cart or checkout alert immediately. Everything else waits for the weekly digest.

Can my agency use this for clients?

Yes. Agency tiers cover 25 or 100 sites with a per-site cadence, and the evidence packs are white-labelled with your name and logo. Each client's records stay separate and can be exported to them if they leave you.

Can I cancel?

Any time. Monitoring stops at the end of the period you paid for. Your records are exported to you, and we keep them available for 90 days after the account closes in case you need a pack.

Find out what's on your checkout, and who can't get through it.

We scan it by hand, write up both halves of what we found and reply personally within two business days. No signup form, no account to create.

Get a free scan of your checkout

Opens an email to hello@storesweep.app. Include your store's address.