What’s Running in the Background of Your eCommerce Store?

Search through blog
Table of Contents
The eCom Ops Podcast featuring Simon Wijckmans, CEO at CSIDE, discussing what is running in the background of your eCommerce Web Site.

Most eCommerce teams think about performance, UX, and conversion rates. Very few think about what’s actually running in their customers’ browsers.

In this episode of the Ecom Ops Podcast, Simon Wijckmans, CEO of  C/SIDE (CSIDE), explains why the browser has become one of the biggest blind spots in modern eCommerce security, and why most companies don’t even realize what scripts, tools, and third-party code are operating on their site.

From forgotten scripts and outdated plugins to invisible client-side attacks, this conversation exposes a layer of risk most teams never look at, until something breaks. Or worse.

About the Guest

Simon Wijckmans is the Founder and CEO of c/side (cside), a security company focused on client-side security, the part of the web that runs in the user’s browser. Before starting c/side, he worked on security products at Cloudflare, including Page Shield and Bot Management, and later at Vercel, where he focused on enterprise security, compliance, and identity access management. His work is rooted in a simple but increasingly urgent idea: while most companies invest heavily in protecting servers and infrastructure, the browser remains one of the most powerful and least understood attack surfaces. In 2025, Simon was named to the Forbes 30 Under 30 list.

c/side is a next-generation web security company built to protect what most traditional tools overlook: the client side. Its platform helps companies see and control everything running in visitors’ browsers, including third-party scripts, and stop attacks such as credit card skimming, data leaks, fraud, and privacy violations before they reach the user. By combining real-time monitoring, AI-driven detection, and automated compliance support for standards like PCI DSS, c/side gives teams better visibility and faster protection in the browser, where many modern threats now happen.

The Key Takeaways

The Browser Is the New Weakest Link

Most security investments still focus on servers and infrastructure. But modern eCommerce doesn’t run only on servers anymore; it runs heavily in the browser. As security on the backend improved, attackers simply moved to the next weakest link:
client-side environments.

You Don’t Know What’s Running on Your Website

Here’s the uncomfortable truth: Most companies cannot answer a simple question:

What scripts are running in your users’ browsers right now?

Marketing tools, analytics scripts, chat widgets, and third-party integrations pile up over time, and many are forgotten, unmanaged, or even owned by vendors that no longer exist.

Simon mentions thousands of scripts still active from companies that are already gone. That’s considered a security risk.

More Scripts = Bigger Attack Surface

Every script you add increases your “supply chain” risk. And attackers don’t need sophisticated methods when simple ones work:

  • buying expired domains used in scripts
  • injecting malicious code into old plugins
  • hijacking third-party tools

Sometimes, the attack costs less than $10. And still works.

Modern Attacks Are Surprisingly Simple

Not all attacks are advanced. Some are almost… embarrassingly simple.

For example:

  • fake payment forms layered over real ones
  • capturing credit card data before showing the real checkout
  • stealing login credentials or session tokens

The scary part? Users often don’t notice anything unusual.

Security Tools Don’t See the Full Picture

Traditional security tools focus on network traffic and server-side protection. But browser behavior is a completely different environment.

Many tools:

  • don’t see what scripts actually do
  • can’t detect dynamic or location-based payloads
  • rely on incomplete visibility

Which creates a dangerous illusion: “We’re protected.”

Server-Side Tracking Didn’t Solve This

Even with the rise of server-side tracking, the core problem remains: Most scripts still execute in the browser.

So while tracking methods changed, the attack surface didn’t disappear; it just shifted.

Marketing Teams Accidentally Create Risk

This is where it gets real for operators.

Marketing teams:

  • add scripts
  • test tools
  • install tags
  • forget what’s live

Engineering doesn’t fully own it.  Marketing doesn’t fully track it.

And the result? A blind spot no one is responsible for.

If You Think You’d Notice an Attack, You Probably Wouldn’t

Most merchants assume, “We’d know if something was wrong.

But Simon challenges that assumption directly. Because if you don’t know what’s running on your site, you won’t know when something changes.

The Fix Isn’t Complexity, It’s Awareness

Improving security doesn’t start with more tools.

It starts with awareness:

  • knowing what scripts run
  • understanding their behavior
  • monitoring changes in real time

Because you can’t protect what you can’t see.

Resources Mentioned

  • cside – A client-side security platform that monitors browser behavior and detects malicious scripts in real time.
  • Cloudflare PageShield – A tool that attempts to monitor scripts but lacks full visibility into their behavior.
  • Google Tag Manager – A common entry point for scripts, but only one part of the overall risk landscape
  • Incrementality Testing – Experiments designed to determine whether a marketing activity actually drives additional revenue.
  • Magento / WordPress / React ecosystems – Common sources of vulnerabilities through outdated plugins, themes, and dependencies.

Conclusion

Modern eCommerce doesn’t just run on your infrastructure. It runs in your customer’s browser. And that environment is often the least understood and least protected part of the entire system.

As Simon explains, the biggest risk isn’t always sophisticated attacks. It’s the accumulation of small, forgotten, invisible pieces of code that no one is tracking anymore.

Because in the end, security isn’t just about blocking threats. It’s about knowing what’s actually happening on your site.

The No.1 eCom Operations hack

“The more things you add to your website, the bigger your supply chain becomes, the higher the risk of your security issues.”

Quote, The eCom Ops Podcast. Simon Wijckmans, CEO at CSIDE, is pictured alongside his quote: "Do you know how your web application behaves in the browser of the user? The answer is usually no."

This episode is brought to you by B2Bware

B2Bware by SyncSpider is a self-service B2B portal designed for manufacturers, distributors, and wholesalers that rely on complex pricing, ERP data, and large product catalogs, and don’t want to add more scripts. Schedule Your Free Consultation

Banner ad for B2Bware by SyncSpider promoting a B2B eCommerce solution that connects natively with ERP and PIM systems.

See You on the Show!

Enjoyed this episode? Subscribe to the eCom Ops Podcast for more real talk with leaders in eCommerce, tech, and operations. If you’d like to share your story on the show, drop us a message. We’re always on the lookout for smart operators doing meaningful work.

See you next time!

Get news about integrations and apps, every week

Talk to the Integration Expert

Unique business needs require unique solutions – We’re here to find them for you!

integrations aplications image