---
title: List detected scripts
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Page Shield](https://developers.cloudflare.com/api/go/resources/page_shield)

[Scripts](https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# List detected scripts

client.PageShield.Scripts.List(ctx, params) (\*SinglePage\[[ScriptListResponse](<https://developers.cloudflare.com/api/go/resources/page_shield#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)>)], error)

GET/zones/{zone\_id}/page\_shield/scripts

Lists scripts detected on webpages in the zone, with filtering and pagination.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Page Shield``Domain Page Shield Read``Domain Page Shield``Page Shield Read``Zone Settings Write``Zone Settings Read`

##### ParametersExpand Collapse

<details>

<summary>

params ScriptListParams

</summary>

ZoneID param.Field\[string]

Path param: Identifier

maxLength32

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone_id">Link to this property</a>

<details>

<summary>

Direction param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts/methods/list#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">ScriptListParamsDirection</a>]Optional

Query param: The direction used to sort returned scripts.

</summary>

const ScriptListParamsDirectionAsc <a href="https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts/methods/list#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">ScriptListParamsDirection</a> = "asc"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const ScriptListParamsDirectionDesc <a href="https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts/methods/list#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">ScriptListParamsDirection</a> = "desc"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction">Link to this property</a>

ExcludeCDNCGI param.Field\[bool]Optional

Query param: When true, excludes scripts seen in a <code>/cdn-cgi</code> path from the returned scripts. The default value is true.

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20exclude_cdn_cgi">Link to this property</a>

ExcludeDuplicates param.Field\[bool]Optional

Query param: When true, excludes duplicate scripts. We consider a script duplicate of another if their javascript content matches and they share the same url host and zone hostname. In such case, we return the most recent script for the URL host and zone hostname combination.

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20exclude_duplicates">Link to this property</a>

ExcludeURLs param.Field\[string]Optional

Query param: Excludes scripts whose URL contains one of the URL-encoded URLs separated by commas.

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20exclude_urls">Link to this property</a>

<details>

<summary>

Export param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts/methods/list#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20export%20%3E%20(schema)">ScriptListParamsExport</a>]Optional

Query param: Export the list of scripts as a file, limited to 50000 entries.

</summary>

const ScriptListParamsExportCsv <a href="https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts/methods/list#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20export%20%3E%20(schema)">ScriptListParamsExport</a> = "csv"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20export%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

</details>

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20export">Link to this property</a>

Hosts param.Field\[string]Optional

Query param: Includes scripts that match one or more URL-encoded hostnames separated by commas.

Wildcards are supported at the start and end of each hostname to support starts with, ends with and contains. If no wildcards are used, results will be filtered by exact match

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20hosts">Link to this property</a>

<details>

<summary>

OrderBy param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts/methods/list#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by%20%3E%20(schema)">ScriptListParamsOrderBy</a>]Optional

Query param: The field used to sort returned scripts.

</summary>

const ScriptListParamsOrderByFirstSeenAt <a href="https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts/methods/list#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by%20%3E%20(schema)">ScriptListParamsOrderBy</a> = "first\_seen\_at"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const ScriptListParamsOrderByLastSeenAt <a href="https://developers.cloudflare.com/api/go/resources/page_shield/subresources/scripts/methods/list#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by%20%3E%20(schema)">ScriptListParamsOrderBy</a> = "last\_seen\_at"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by">Link to this property</a>

Page param.Field\[string]Optional

Query param: The current page number of the paginated results.

We additionally support a special value “all”. When “all” is used, the API will return all the scripts with the applied filters in a single page. This feature is best-effort and it may only work for zones with a low number of scripts

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page">Link to this property</a>

PageURL param.Field\[string]Optional

Query param: Includes scripts that match one or more page URLs (separated by commas) where they were last seen

Wildcards are supported at the start and end of each page URL to support starts with, ends with and contains. If no wildcards are used, results will be filtered by exact match

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page_url">Link to this property</a>

PerPage param.Field\[float64]Optional

Query param: The number of results per page.

maximum100

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page">Link to this property</a>

PrioritizeMalicious param.Field\[bool]Optional

Query param: When true, malicious scripts appear first in the returned scripts.

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20prioritize_malicious">Link to this property</a>

Status param.Field\[string]Optional

Query param: Filters the returned scripts using a comma-separated list of scripts statuses. Accepted values: <code>active</code>, <code>infrequent</code>, and <code>inactive</code>. The default value is <code>active</code>.

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20status">Link to this property</a>

URLs param.Field\[string]Optional

Query param: Includes scripts whose URL contain one or more URL-encoded URLs separated by commas.

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20urls">Link to this property</a>

</details>

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type ScriptListResponse struct{…}

</summary>

ID string

Identifier

maxLength32

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

AddedAt Time

formatdate-time

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20added_at">Link to this property</a>

FirstSeenAt Time

formatdate-time

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20first_seen_at">Link to this property</a>

Host string

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20host">Link to this property</a>

LastSeenAt Time

formatdate-time

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20last_seen_at">Link to this property</a>

URL string

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

URLContainsCDNCGIPath bool

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20url_contains_cdn_cgi_path">Link to this property</a>

CryptominingScore int64Optional

The cryptomining score of the JavaScript content.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20cryptomining_score">Link to this property</a>

DeprecatedDataflowScore int64Optional

The dataflow score of the JavaScript content. This field has been deprecated in favour of js\_integrity\_score.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20dataflow_score">Link to this property</a>

DomainReportedMalicious boolOptional

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20domain_reported_malicious">Link to this property</a>

FetchedAt stringOptional

The timestamp of when the script was last fetched.

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20fetched_at">Link to this property</a>

FirstPageURL stringOptional

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20first_page_url">Link to this property</a>

Hash stringOptional

The computed hash of the analyzed script.

maxLength64

minLength64

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20hash">Link to this property</a>

JSIntegrityScore int64Optional

The integrity score of the JavaScript content.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20js_integrity_score">Link to this property</a>

MagecartScore int64Optional

The magecart score of the JavaScript content.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20magecart_score">Link to this property</a>

MaliciousDomainCategories \[]stringOptional

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20malicious_domain_categories">Link to this property</a>

MaliciousURLCategories \[]stringOptional

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20malicious_url_categories">Link to this property</a>

MalwareScore int64Optional

The malware score of the JavaScript content.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20malware_score">Link to this property</a>

DeprecatedObfuscationScore int64Optional

The obfuscation score of the JavaScript content. This field has been deprecated in favour of js\_integrity\_score.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20obfuscation_score">Link to this property</a>

PageURLs \[]stringOptional

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20page_urls">Link to this property</a>

URLReportedMalicious boolOptional

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)%20%3E%20(property)%20url_reported_malicious">Link to this property</a>

</details>

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(model)%20ScriptListResponse%20%3E%20(schema)>)

### List detected scripts

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/option"
  "github.com/cloudflare/cloudflare-go/page_shield"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  page, err := client.PageShield.Scripts.List(context.TODO(), page_shield.ScriptListParams{
    ZoneID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", page)
}
```

200 example

```
{
  "result": [
    {
      "id": "023e105f4ecef8ad9ca31a8372d0c353",
      "added_at": "2021-08-18T10:51:10.09615Z",
      "first_seen_at": "2021-08-18T10:51:08Z",
      "host": "blog.cloudflare.com",
      "last_seen_at": "2021-09-02T09:57:54Z",
      "url": "https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.6.0/js/bootstrap.min.js",
      "url_contains_cdn_cgi_path": false,
      "cryptomining_score": 1,
      "dataflow_score": 1,
      "domain_reported_malicious": false,
      "fetched_at": "fetched_at",
      "first_page_url": "blog.cloudflare.com/page",
      "hash": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
      "js_integrity_score": 1,
      "magecart_score": 1,
      "malicious_domain_categories": [
        "Malware"
      ],
      "malicious_url_categories": [
        "Malware"
      ],
      "malware_score": 1,
      "obfuscation_score": 1,
      "page_urls": [
        "blog.cloudflare.com/page1",
        "blog.cloudflare.com/page2"
      ],
      "url_reported_malicious": false
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  },
  "success": true,
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ]
}
```

##### Returns Examples

200 example

```
{
  "result": [
    {
      "id": "023e105f4ecef8ad9ca31a8372d0c353",
      "added_at": "2021-08-18T10:51:10.09615Z",
      "first_seen_at": "2021-08-18T10:51:08Z",
      "host": "blog.cloudflare.com",
      "last_seen_at": "2021-09-02T09:57:54Z",
      "url": "https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.6.0/js/bootstrap.min.js",
      "url_contains_cdn_cgi_path": false,
      "cryptomining_score": 1,
      "dataflow_score": 1,
      "domain_reported_malicious": false,
      "fetched_at": "fetched_at",
      "first_page_url": "blog.cloudflare.com/page",
      "hash": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
      "js_integrity_score": 1,
      "magecart_score": 1,
      "malicious_domain_categories": [
        "Malware"
      ],
      "malicious_url_categories": [
        "Malware"
      ],
      "malware_score": 1,
      "obfuscation_score": 1,
      "page_urls": [
        "blog.cloudflare.com/page1",
        "blog.cloudflare.com/page2"
      ],
      "url_reported_malicious": false
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  },
  "success": true,
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ]
}
```