Articles

Plain-English explainers on PCI DSS v4.0, SAQ A-EP, Magecart, and client-side script monitoring. Written for the person running the store.

  1. May 4, 2026

    PCI 6.4.3 for Stripe Elements Merchants: Exactly What You Owe

    Stripe Elements puts the card form in an iframe — but PCI 6.4.3 still applies to the page around it. The exact split of responsibility, the controls Stripe covers vs the controls that are on you, and the fastest path to satisfying both.

    • pci-dss
    • 6.4.3
    • stripe
    • stripe-elements
  2. April 29, 2026

    Magecart Explained: How Card Skimmers Hide in Your Third-Party Scripts

    What Magecart actually is, how the attack chain works, and why the most expensive card-skimmer breaches in the last decade went undetected for months. With three real-world incidents you can use to explain the threat to a non-technical owner.

    • magecart
    • client-side-security
    • magento
    • card-skimming