Report URI

Report URI Client-side security to control what code actually runs on your website.

ClickFix tricks users into compromising their own machines and hides its payload on a blockchain.But the attack still be...
04/08/2026

ClickFix tricks users into compromising their own machines and hides its payload on a blockchain.

But the attack still begins the same way: a website runs JavaScript it was never meant to run.

That’s where we could have stopped it.

A customer forwarded us something last week that has stuck with me. It was a live attack campaign — a good one, in the professional-admiration sense — along with a detailed public write-up dissecting exactly how it worked. The analysis was genuinely impressive. It traced the whole thing from the

Stripe just made CSP a compliance requirement.Merchants completing their annual PCI assessment are now asked to attest t...
28/07/2026

Stripe just made CSP a compliance requirement.

Merchants completing their annual PCI assessment are now asked to attest that they’ve deployed a Content Security Policy.

That’s a major shift from “you should deploy CSP” to “confirm that you have.”

Here’s what changed and why it matters:

Stripe's PCI assessment now has a mandatory checkbox: confirm you've deployed a Content Security Policy. Here's what you're attesting to, and how to do it.

Onboarding just got a whole lot easier! 🤖Using Claude, ChatGPT, Gemini, or another AI agent?Login, click "Copy Prompt", ...
23/07/2026

Onboarding just got a whole lot easier! 🤖

Using Claude, ChatGPT, Gemini, or another AI agent?

Login, click "Copy Prompt", paste it into your AI, and it'll configure CSP reporting for you.

Get up and running in minutes 😎
https://report-uri.com/

We’ve open-sourced passkeys-php, the WebAuthn library we use at Report URI, to help the community deploy passkeys more e...
20/05/2026

We’ve open-sourced passkeys-php, the WebAuthn library we use at Report URI, to help the community deploy passkeys more easily and safely.

Small. Auditable. MIT licensed. Built for real-world PHP apps.

Our founder, Scott Helme, shared the details today:

We've open-sourced passkeys-php, the WebAuthn server library we use at Report URI to protect logins with passkeys, security keys, and platform authenticators like Touch ID, Face ID, and Windows Hello. It started as a set of local security fixes for our own production passkeys implementation. Now, ra...

Great research from our founder, Scott Helme, on one of the hidden risks of passkeys.Passkeys reduce phishing risk, but ...
19/05/2026

Great research from our founder, Scott Helme, on one of the hidden risks of passkeys.

Passkeys reduce phishing risk, but malicious JavaScript in the browser can still abuse registration flows and create persistent account takeover risk.

Client-side visibility matters.

A single XSS vulnerability can turn passkeys from a phishing-resistant login mechanism into a persistent account takeover backdoor. If malicious JavaScript can run on your page, it may be able to register an attacker-controlled passkey against the victim’s account. The user sees nothing, the websi...

Passkeys are becoming a major part of how we secure accounts online, but there’s still a lot of confusion about what the...
18/05/2026

Passkeys are becoming a major part of how we secure accounts online, but there’s still a lot of confusion about what they are, how they work, and what risks remain.

Our founder, Scott Helme, has written a short introduction to Passkeys to set the scene before we publish some deeper technical posts this week.

A simple starting point before we get into the details.

Passwords have been the weak point in online authentication for decades. They can be reused, guessed, stolen, phished, leaked, sprayed, stuffed, and captured by malware. Passkeys are one of the first mainstream authentication technologies that remove many of those problems entirely, and any website....

A checkout page can look secure, work normally, and still be stealing customer payment data.In this post, Scott Helme br...
15/05/2026

A checkout page can look secure, work normally, and still be stealing customer payment data.

In this post, Scott Helme breaks down a real-world JavaScript compromise where attackers modified a trusted file to skim card data directly from the browser — and why organisations need visibility into the code running in the browser.

Read the post:

One malicious change to a trusted JavaScript file can turn your checkout page into a silent credit-card skimmer, siphoning customer data off to criminals while the website looks secure and continues to work as normal. That creates serious organisational risk: PCI exposure, regulatory consequences, r...

The NCSC is right to push passkeys.They’re a huge step forward for authentication: phishing-resistant, no shared secret ...
22/04/2026

The NCSC is right to push passkeys.

They’re a huge step forward for authentication: phishing-resistant, no shared secret on the server, far better than passwords in many ways.

But passkeys don’t make your application trustworthy after login. You still need to deal with session abuse, XSS, CSRF, malicious passkey registration, and transaction manipulation.

Our founder Scott Helme wrote about the security considerations teams need to think about when rolling out passkeys and published a white paper:

Passkeys are awesome and that's why we implemented them on Report URI! You can read about our implementation here and get the basics on how Passkeys work and why you want them. In this post, we're going to focus on what security considerations you should have once you start using

Good morning Glasgow! 🏴󠁧󠁢󠁳󠁣󠁴󠁿Come and find us at CyberUK booth G13 and see how we can show you exactly what code is runn...
22/04/2026

Good morning Glasgow! 🏴󠁧󠁢󠁳󠁣󠁴󠁿

Come and find us at CyberUK booth G13 and see how we can show you exactly what code is running on your website. 👨‍💻

The Report URI refresh is live! 💙🧡New homepage, refreshed product + case study pages, all-new social cards across the si...
20/04/2026

The Report URI refresh is live! 💙🧡

New homepage, refreshed product + case study pages, all-new social cards across the site, and more.

Same mission: catching the third-party code your website is running that you don't control.

➡️ https://report-uri.com

Address

35 - 47 Bethnal Green Road
London
E1 6LA

Alerts

Be the first to know and let us send you an email when Report URI posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Report URI:

Shortcuts

Share