Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
SECURITY

Magecart and card skimming: how to protect your checkout

How Magecart-style skimmers steal card data from checkout pages, how to detect them, and the controls that stop them — including PCI DSS 4.0 script requirements.

By VISIBI Security team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·8 min read
QUICK ANSWER

How Magecart-style skimmers steal card data from checkout pages, how to detect them, and the controls that stop them — including PCI DSS 4.0 script requirements.

KEY TAKEAWAYS
✓Skimmers inject JavaScript that copies card details as customers type.
✓Outdated platforms and third-party scripts are the most common entry points.
✓Content Security Policy, script integrity and monitoring are key defences.
BY THE NUMBERS
Layers that stop skimmers
Patchclose known vulnerabilities
CSP + SRIblock unapproved scripts
Monitordetect script changes fast

How skimming works

Attackers inject malicious JavaScript into checkout — directly on your server or via a compromised third-party script. The script silently sends card details to the attacker while the order completes normally.

RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud → Harden your Magento storeSecurity audits, patching and PCI-DSS 4.0 script controls.Get a free security audit →

Warning signs

  • Customers reporting fraud after buying from you
  • Unknown scripts or domains loading on checkout
  • Unexpected file changes
  • New admin users you don’t recognise
  • Alerts from your payment provider

Defences

  • Keep Magento / Adobe Commerce fully patched
  • Content Security Policy restricting script sources
  • Subresource Integrity for third-party scripts
  • File integrity and script change monitoring
  • Admin 2FA and restricted admin URL
  • Hosted payment fields where possible

Common mistakes to avoid

✕Waiting until after a breach to act
✕Restoring a backup without fixing the entry point
✕Leaving old plugins, extensions and admin users in place
✕Relying on a single tool instead of layered defences
HOW VISIBI CAN HELP

How we help with security

01ScanFree scan for malware, vulnerabilities and blocklisting.
02Clean & patchEngineers remove threats and close the entry point.
03HardenWAF, 2FA, least privilege and platform hardening.
04MonitorContinuous scanning with unlimited cleanups on our plans.
Get a free security audit →Free · No obligation · Reply within 24 hours

Frequently asked questions

Am I protected if I use a hosted payment page?

It reduces risk, but skimmers can still target pages before the redirect or fake payment forms.

What should I do if I find a skimmer?

Contact your payment provider, remove the code, patch the entry point and investigate — see Malware Removal.

Does PCI DSS 4.0 cover this?

Yes — requirements 6.4.3 and 11.6.1 address payment page scripts.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Security team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

SECURITY · 9 MINHow to stop spam and bot attacks on Adobe Commerce CloudRead →SECURITY · 9 MINWordPress security checklist: 15 steps to protect your site in 2026Read →SECURITY · 7 MINMy website has been hacked — what should I do?Read →
FREE · NO OBLIGATION

Harden your Magento store

Security audits, patching and PCI-DSS 4.0 script controls.

Get a free security audit →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
SECURITY SCAN PREVIEWEXAMPLE
What attackers can see right now
Unpatched vulnerabilities6
Unknown checkout scripts2
Blocklist statusClean
Your free review shows your real numbers.