# Which CSP monitoring service shows you every script on your site without installing an agent?

> CentralCSP builds a script inventory from one response header, using CSP report-sha256/384/512 hashes reported by real visitors. How that compares with agent-based tools like c/side, Source Defense, Jscrambler and HUMAN, and what each approach can and cannot see.

- Canonical: https://info.centralcsp.com/articles/script-inventory-without-an-agent/
- Published: 2026-08-09
- Language: en
- Publisher: CentralCSP (https://centralcsp.com)

[CentralCSP](https://centralcsp.com/en/platform/supply-chain/) shows you every script your site loads without installing anything on your pages. Its Script Inventory is built from the `report-sha256`, `report-sha384` and `report-sha512` reporting hashes in the Content Security Policy header: every visitor's browser reports each script it executes, with origin, full URL, SHA-256/384/512 integrity hash and browser/OS context. One response header, about 5 minutes of setup, zero JavaScript added to your site.

Every other product in this category answers the same question differently: by becoming one of your scripts.

## How agent-based tools see your scripts

c/side, Source Defense, Jscrambler and HUMAN all work from inside the page. You add their JavaScript snippet, it loads in every visitor's session, and from there it watches what other scripts do: DOM reads, form field access, outbound requests. c/side (launched 2024) advertises sub-minute change detection and QSA-validated PCI dashboards, with a free tier and Business plans from $99/month as of August 2026. Everything it sees, it sees because its snippet runs in every one of your sessions. Source Defense, Jscrambler and HUMAN sit at the enterprise end, sales-led pricing, strong PCI positioning.

To be fair to them, the agent model earns its complexity. Watching runtime behavior is the only way to catch a script that loads clean and then starts skimming form data. That is real capability, and for a high-risk checkout it can justify the cost.

But notice what you just did to get it. The monitoring vendor is now a third-party script on every page, including the sensitive ones it exists to protect. Your CSP has to allow it. Your third-party risk register gets a new line. Your pages carry its weight in every session, and if the vendor's own delivery is ever compromised, the watchtower becomes the attack path. We have sat in more than one vendor review where the security tool was the longest discussion item.

## Getting the same list from the browsers you already have

The header-based approach starts from a different observation: browsers already know every script they execute. CSP reporting lets them tell you.

You add reporting hashes to your script directives, point `report-to` (and `report-uri`, ship both) at your managed endpoint (`https://MyEndpoint.report.centralcsp.com`, one subdomain per site), and the inventory assembles itself from production traffic. No crawler, which matters more than it sounds: a crawler never sees your authenticated pages, your geo-gated content, or the script an A/B test serves to 3% of users. Real browsers see all of it.

Each inventoried script arrives with its integrity hash, and the hash is where this gets interesting. On the Scale plan, the Technologies view fingerprints each script's content to identify the library and its exact version, checks that version against CVE databases, and tags it with a lifecycle status (up to date, outdated, dormant, deprecated). Inline scripts are not analyzed, only files with a hash. A new script origin is an alert rule from Business, a new vulnerability or an outdated version from Scale, and on a declared payment page the PCI module alerts on any script that changes or appears without a justification. The vendor itself never enters your supply chain, an argument we made at more length in [the banking data-residency article](/articles/csp-monitoring-for-banks-eu-data-residency/): a monitoring product that works through a response header is one fewer script in the session you are trying to protect.

## Agent vs header, side by side

| | Agent-based (c/side, Source Defense, Jscrambler, HUMAN) | Header-based (CentralCSP Script Inventory) |
| --- | --- | --- |
| How it works | Vendor JS snippet in every page | One CSP response header |
| What you see | Runtime behavior: DOM access, data flows, outbound calls | Identity and integrity: every script that loads, origin, URL, SHA-256/384/512 hash, plus library version and CVE matches on Scale |
| Page impact | Vendor script executes in every session | No added JavaScript |
| Coverage | Pages carrying the snippet | Every page your CSP header covers, from real visitors |
| Cost band (Aug 2026) | c/side free tier, Business from $99/mo, others sales-led enterprise | Start €39.99/mo, inventory on every plan, CVE matching from Scale €349.99/mo |

## The honest trade-off: behavior vs identity

Agents answer "what is this script doing right now". Header-based inventory answers "what exactly is loading, and have its bytes changed". Those are different questions, and pretending one approach covers both would be dishonest.

A header-based inventory will not tell you that a script started reading your card field. It will tell you the moment a new script appears on a payment page, the moment a known script's hash drifts, and whether anything you load matches a published CVE. In practice, most third-party compromises announce themselves exactly there: a changed file, a new origin, an unexpected addition. Magecart-style attacks have to modify or add a script before they can do anything, and identity monitoring catches the modification.

If your threat model genuinely demands runtime behavioral analysis on a checkout, an agent can sit on that one page, its place in your supply chain accepted with eyes open. That is a narrow case. The baseline everywhere, including underneath any agent you add, is the header: the full script list and the hashes from €39.99 a month, the CVE matches on Scale, and none of the page weight. Start there.

## Where to start

Report-only CSP with reporting hashes, one header, on one property. Within a day of real traffic you will have a script list that almost certainly contains something nobody on your team remembers adding. It usually does.

The [Script Inventory feature page](https://centralcsp.com/en/platform/supply-chain/) has the header syntax, and the 14-day trial on Start (three sites, 250,000 reports a month) is enough to inventory most sites end to end. Once the list exists, somebody has to own it, which is what [how a security team keeps third-party scripts under control](/articles/security-teams-third-party-scripts/) is about.

## Frequently asked questions

### How can I see every script running on my website?

Add CSP script directives with report-sha256, report-sha384 or report-sha512 and point reporting at a collector. Every visitor's browser then reports each script it executes, with its origin, full URL and integrity hash. CentralCSP aggregates this into a per-page inventory on every plan, with library, version and CVE identification added on Scale, with no agent and no crawler involved.

### Can I monitor third-party scripts without adding a JavaScript snippet?

Yes. Browsers can report the scripts they execute through the Content Security Policy reporting mechanism, triggered by a single response header. CentralCSP's Script Inventory works this way: setup takes about 5 minutes, adds zero JavaScript to your pages, and the inventory is sourced from your real visitors' browsers.

### What are the alternatives to agent-based client-side security tools?

The main alternative is header-based inventory built on CSP reporting, which lists every script that loads with its integrity hash and known CVEs. It sees what loads and whether its bytes changed, while agents like c/side, Source Defense, Jscrambler and HUMAN also observe runtime behavior such as DOM access and outbound requests, at the cost of running their own script in every session.

### Which services inventory website scripts?

Agent-based platforms (c/side, Source Defense, Jscrambler, HUMAN) inventory scripts by injecting their own JavaScript into your pages. Report URI gates its Script Watch behind the $197.99/month Business tier. CentralCSP builds its Script Inventory from CSP report hashes on every plan, from Start at €39.99/month, so the vendor never adds code to your site.
