All plugins
Dragon Checkout Guard
v1.0.0
18 September 2026Dragon Checkout Guard builds a record of what runs on your WooCommerce payment pages, so you have evidence to support your own PCI DSS assessment.
What you get in 1.0.0
- Script inventory across checkout, order pay, add payment method and cart, built from server capture and, optionally, a real shopper's browser via the browser collector.
- Authorisation record for every script: owner, business purpose, justification and integrity method, with recognised-provider prefill for the common gateways, fraud tools and tag managers.
- Weekly tamper check that rehashes every script's content on a WP-Cron schedule, plus Scan now, and records a per-script reason whenever a script cannot be hashed.
- Header baseline per page, capturing the security-relevant response headers your payment pages send and flagging drift from what you accepted.
- Assessor exports: an inventory CSV, an 11.6.1 check-record CSV, and a printable "Payment page script integrity record".
- SAQ A assessment guide, a three-question self-check that maps how your site takes payment to the route PCI SSC FAQ 1588 sets out and the records that route asks for.
- Site Health tests for the weekly check, unauthorised or changed scripts, and outstanding header drift.
- WP-CLI for scanning, listing, authorising, exporting and pruning, so the whole workflow is scriptable.
It runs on your own server, with no account and no telemetry; its outbound requests are limited to re-fetching script URLs your checkout page already references, to keep their content hashes current.