Build an inventory from the rendered checkout
Have the authorized maintainer inspect the browser’s existing request and diagnostic information while loading the affected real checkout page. No card entry or payment submission is needed to record a warning already present on page load. If it occurs later in an actual buyer journey, preserve the existing report and stage rather than asking the buyer to pay again to reproduce it.
For each observed insecure request, record the resource category, a sanitized address, the page on which it appeared and the browser’s reported result. Distinguish a request the browser reports as blocked from one it reports as loaded; do not infer either outcome from the address alone. Keep the original diagnostic evidence within authorized systems when it contains private information.
Trace the reference back to the component that introduced it. A resource can be included by page content, a theme, an extension or another integration. These are places to investigate, not established causes. Record the source file, setting or vendor confirmation that supports the ownership assignment. The host serving the resource and the component requesting it can have different owners.
Sanitize before copying evidence. Keep the scheme and only the host and path detail necessary to identify the resource. Remove credentials, query values, private payment-link tokens and customer-specific path segments. Do not attach raw network exports, cookies, request bodies or authorization headers to a public inquiry.