Response
Script Threat Signals (Page Shield)
A script slipped into your checkout page carries card details out before you notice — that is how Magecart attacks work. Specula flags the third-party scripts your site loads that appear on threat lists.
Flagged scripts come first
The data is read from Cloudflare's Page Shield; scripts appearing on threat lists are pulled to the top, the rest are listed with their source domain.
Domain reputation on every plan
The reputation of the domain a script loads from is evaluated even on the free plan; inspecting the script's code requires Cloudflare's paid tier.
The scope sentence sits next to the list
Which tier is active — and therefore what was not inspected — is stated on the same screen as the list.
cdn.trackr-xyz.io/a.min.js
www.googletagmanager.com/gtm.js
js.stripe.com/v3
On the free plan script code is not inspected — this list is not a clean report.
1 flagged script · scope stated alongside
Its limits
This feature works only on domains connected through Cloudflare.
No flag does not mean clean, and the screen never says clean: on the free plan the script's code is not inspected at all. Page Shield must be enabled in the customer's Cloudflare dashboard.
Other features
Run this check on your own domain.
Add a domain and Specula finishes the first scan within minutes. No credit card needed.