TugraCyber

Description

TugraCyber keeps an inventory of every script running on your checkout page and alerts you when a script’s content changes silently, which is the signature of Magecart-style card skimming attacks.

  • Runs only on the checkout page. This is exactly the scope of PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1.
  • Script inventory. A SHA-256 hash of each script’s content is recorded, so silent changes are caught immediately.
  • Removed and returning script detection. You get an alert when a known script disappears from the page, or reappears after being marked as removed.
  • PCI DSS 6.4.3/11.6.1 report. Available from the dashboard in your TugraCyber account.

This plugin only adds the monitoring agent to your checkout page. The dashboard, alerts and reports live in your TugraCyber account. Setup requires an account and a collector address.

Requirements

  • WooCommerce must be active (monitoring runs only on the WooCommerce checkout page).
  • A TugraCyber account and a collector address.

External Services

Through the monitoring script (agent) it places on your checkout page, this plugin sends data to the Collector Endpoint address you enter on the settings page. This address is empty by default: the plugin can be installed, but no data is sent anywhere until you enter an address.

For each script loaded on the checkout page, the data sent is:

  • the script’s URL (src),
  • the SHA-256 hash of the script’s content (not the content itself; the hash is an irreversible digest),
  • the script type (inline or external) and your site ID.

Page content, customer data, payment information and card numbers are never collected or sent.

If you enter the TugraCyber hosted service at https://tugracyber.com as the Collector Endpoint, data is sent to that service and the following apply:

  • Terms of Service: https://tugracyber.com/terms
  • Privacy Policy: https://tugracyber.com/privacy

Alternatively, you can enter the address of a TugraCyber collector instance running on your own server. In that case data goes only to a server under your control and nothing is sent to any third party.

Installation

  1. Upload and activate the plugin.
  2. Go to Settings > TugraCyber.
  3. Enter the collector endpoint of your TugraCyber account and save.
  4. Visit your checkout page once. The first script inventory is sent automatically.

FAQ

Which pages does this plugin run on?

Only the WooCommerce checkout page. It does nothing on other pages.

I don’t have a TugraCyber account. Can I still install it?

Yes, but monitoring does not start until a collector address is entered.

What data does the plugin send?

Only the URL and SHA-256 content hash of the scripts on the checkout page. See the “External Services” section above. Page content and customer or payment data are never sent.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“TugraCyber” is open source software. The following people have contributed to this plugin.

Contributors

Translate “TugraCyber” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

0.1.0

  • Initial release: agent injection on the checkout page, settings page, automatic site ID and write key generation.