Stop hosting 3rd party libs
Just for the love of god stop it already
Sportswear brand FILA is the latest outfit to fall victim to card-stealing JavaScript of the kind that menaced British Airways and Ticketmaster last year. Russian security house Group-IB said it discovered and reported to FILA UK malware known as GMO that was active on the fashion brand's website for the past four months – and …
Four separate Bootstrap libraries, 3 captcha libraries and just about 2 of every other library. Someone really does not know about uglification or compression of scripts. FYI Fila https://bytutorial.com/blogs/javascript/how-to-minify-js-and-css-files-using-gulp is a good tutorial on how to minify CSS or JS.
“One-line card stealing code downloads a JavaScript Sniffer once a customer lands on a checkout page, which intercepts credit card data and sends it to local storage.”
Demonstrating yet again the unsuitability of using Credit Card numbers for online financial transactions.