---
title: List detected scripts
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api)

[Page Shield](https://developers.cloudflare.com/api/resources/page_shield)

[Scripts](https://developers.cloudflare.com/api/resources/page_shield/subresources/scripts)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# List detected scripts

GET/zones/{zone\_id}/page\_shield/scripts

Lists scripts detected on webpages in the zone, with filtering and pagination.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Page Shield``Domain Page Shield Read``Domain Page Shield``Page Shield Read``Zone Settings Write``Zone Settings Read`

##### P ath ParametersExpand Collapse

zone\_id: string

Identifier

maxLength32

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20zone_id%20%3E%20(schema)>)

##### Q uery ParametersExpand Collapse

<details>

<summary>

direction: optional "asc"or "desc"

The direction used to sort returned scripts.

</summary>

One of the following:

"asc"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"desc"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)>)

exclude\_cdn\_cgi: optional boolean

When true, excludes scripts seen in a `/cdn-cgi` path from the returned scripts. The default value is true.

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20exclude_cdn_cgi%20%3E%20(schema)>)

exclude\_duplicates: optional boolean

When true, excludes duplicate scripts. We consider a script duplicate of another if their javascript content matches and they share the same url host and zone hostname. In such case, we return the most recent script for the URL host and zone hostname combination.

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20exclude_duplicates%20%3E%20(schema)>)

exclude\_urls: optional string

Excludes scripts whose URL contains one of the URL-encoded URLs separated by commas.

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20exclude_urls%20%3E%20(schema)>)

export: optional "csv"

Export the list of scripts as a file, limited to 50000 entries.

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20export%20%3E%20(schema)>)

hosts: optional string

Includes scripts that match one or more URL-encoded hostnames separated by commas.

Wildcards are supported at the start and end of each hostname to support starts with, ends with and contains. If no wildcards are used, results will be filtered by exact match

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20hosts%20%3E%20(schema)>)

<details>

<summary>

order\_by: optional "first\_seen\_at"or "last\_seen\_at"

The field used to sort returned scripts.

</summary>

One of the following:

"first\_seen\_at"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"last\_seen\_at"

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20order_by%20%3E%20(schema)>)

page: optional string

The current page number of the paginated results.

We additionally support a special value “all”. When “all” is used, the API will return all the scripts with the applied filters in a single page. This feature is best-effort and it may only work for zones with a low number of scripts

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page%20%3E%20(schema)>)

page\_url: optional string

Includes scripts that match one or more page URLs (separated by commas) where they were last seen

Wildcards are supported at the start and end of each page URL to support starts with, ends with and contains. If no wildcards are used, results will be filtered by exact match

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page_url%20%3E%20(schema)>)

per\_page: optional number

The number of results per page.

maximum100

minimum1

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page%20%3E%20(schema)>)

prioritize\_malicious: optional boolean

When true, malicious scripts appear first in the returned scripts.

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20prioritize_malicious%20%3E%20(schema)>)

status: optional string

Filters the returned scripts using a comma-separated list of scripts statuses. Accepted values: `active`, `infrequent`, and `inactive`. The default value is `active`.

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20status%20%3E%20(schema)>)

urls: optional string

Includes scripts whose URL contain one or more URL-encoded URLs separated by commas.

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20urls%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

result: array of object {id, added\_at, first\_seen\_at, 18 more }

</summary>

id: string

Identifier

maxLength32

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

added\_at: string

formatdate-time

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20added_at">Link to this property</a>

first\_seen\_at: string

formatdate-time

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20first_seen_at">Link to this property</a>

host: string

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20host">Link to this property</a>

last\_seen\_at: string

formatdate-time

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20last_seen_at">Link to this property</a>

url: string

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20url">Link to this property</a>

url\_contains\_cdn\_cgi\_path: boolean

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20url_contains_cdn_cgi_path">Link to this property</a>

cryptomining\_score: optional number

The cryptomining score of the JavaScript content.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20cryptomining_score">Link to this property</a>

Deprecateddataflow\_score: optional number

The dataflow score of the JavaScript content. This field has been deprecated in favour of js\_integrity\_score.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20dataflow_score">Link to this property</a>

domain\_reported\_malicious: optional boolean

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20domain_reported_malicious">Link to this property</a>

fetched\_at: optional string

The timestamp of when the script was last fetched.

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20fetched_at">Link to this property</a>

first\_page\_url: optional string

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20first_page_url">Link to this property</a>

hash: optional string

The computed hash of the analyzed script.

maxLength64

minLength64

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20hash">Link to this property</a>

js\_integrity\_score: optional number

The integrity score of the JavaScript content.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20js_integrity_score">Link to this property</a>

magecart\_score: optional number

The magecart score of the JavaScript content.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20magecart_score">Link to this property</a>

malicious\_domain\_categories: optional array of string

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20malicious_domain_categories">Link to this property</a>

malicious\_url\_categories: optional array of string

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20malicious_url_categories">Link to this property</a>

malware\_score: optional number

The malware score of the JavaScript content.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20malware_score">Link to this property</a>

Deprecatedobfuscation\_score: optional number

The obfuscation score of the JavaScript content. This field has been deprecated in favour of js\_integrity\_score.

maximum99

minimum1

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20obfuscation_score">Link to this property</a>

page\_urls: optional array of string

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20page_urls">Link to this property</a>

url\_reported\_malicious: optional boolean

<a href="#(resource)%20page_shield.scripts%20%3E%20(model)%20script_list_response%20%3E%20(schema)%20%3E%20(property)%20url_reported_malicious">Link to this property</a>

</details>

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result>)

<details>

<summary>

result\_info: object {count, page, per\_page, 2 more }

</summary>

count: number

Total number of results for the requested service

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20count">Link to this property</a>

page: number

Current page within paginated list of results

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20page">Link to this property</a>

per\_page: number

Number of results per page of results

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20per_page">Link to this property</a>

total\_count: number

Total results available without any search parameters

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20total_count">Link to this property</a>

total\_pages: number

Total number of pages

<a href="#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info%20%3E%20(property)%20total_pages">Link to this property</a>

</details>

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20result_info>)

success: true

Whether the API call was successful

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20success>)

<details>

<summary>

errors: optional array of <a href="https://developers.cloudflare.com/api/resources/$shared#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)">ResponseInfo</a> { code, message, documentation\_url, source }

</summary>

code: number

minimum1000

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20code">Link to this property</a>

message: string

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: optional string

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: optional object {pointer }

</summary>

pointer: optional string

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

</details>

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20errors>)

<details>

<summary>

messages: optional array of <a href="https://developers.cloudflare.com/api/resources/$shared#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)">ResponseInfo</a> { code, message, documentation\_url, source }

</summary>

code: number

minimum1000

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20code">Link to this property</a>

message: string

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20message">Link to this property</a>

documentation\_url: optional string

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20documentation_url">Link to this property</a>

<details>

<summary>

source: optional object {pointer }

</summary>

pointer: optional string

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20source%20%3E%20(property)%20pointer">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20response_info%20%3E%20(schema)%20%3E%20(property)%20source">Link to this property</a>

</details>

[Link to this property](<#(resource)%20page_shield.scripts%20%3E%20(method)%20list%20%3E%20(network%20schema)%20%3E%20(property)%20messages>)

### List detected scripts

HTTP

HTTPTypeScriptPythonGoTerraform

```
curl https://api.cloudflare.com/client/v4/zones/$ZONE_ID/page_shield/scripts \
    -H "Authorization: Bearer $CLOUDFLARE_API_TOKEN"
```

200 example

```
{
  "result": [
    {
      "id": "023e105f4ecef8ad9ca31a8372d0c353",
      "added_at": "2021-08-18T10:51:10.09615Z",
      "first_seen_at": "2021-08-18T10:51:08Z",
      "host": "blog.cloudflare.com",
      "last_seen_at": "2021-09-02T09:57:54Z",
      "url": "https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.6.0/js/bootstrap.min.js",
      "url_contains_cdn_cgi_path": false,
      "cryptomining_score": 1,
      "dataflow_score": 1,
      "domain_reported_malicious": false,
      "fetched_at": "fetched_at",
      "first_page_url": "blog.cloudflare.com/page",
      "hash": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
      "js_integrity_score": 1,
      "magecart_score": 1,
      "malicious_domain_categories": [
        "Malware"
      ],
      "malicious_url_categories": [
        "Malware"
      ],
      "malware_score": 1,
      "obfuscation_score": 1,
      "page_urls": [
        "blog.cloudflare.com/page1",
        "blog.cloudflare.com/page2"
      ],
      "url_reported_malicious": false
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  },
  "success": true,
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ]
}
```

##### Returns Examples

200 example

```
{
  "result": [
    {
      "id": "023e105f4ecef8ad9ca31a8372d0c353",
      "added_at": "2021-08-18T10:51:10.09615Z",
      "first_seen_at": "2021-08-18T10:51:08Z",
      "host": "blog.cloudflare.com",
      "last_seen_at": "2021-09-02T09:57:54Z",
      "url": "https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.6.0/js/bootstrap.min.js",
      "url_contains_cdn_cgi_path": false,
      "cryptomining_score": 1,
      "dataflow_score": 1,
      "domain_reported_malicious": false,
      "fetched_at": "fetched_at",
      "first_page_url": "blog.cloudflare.com/page",
      "hash": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
      "js_integrity_score": 1,
      "magecart_score": 1,
      "malicious_domain_categories": [
        "Malware"
      ],
      "malicious_url_categories": [
        "Malware"
      ],
      "malware_score": 1,
      "obfuscation_score": 1,
      "page_urls": [
        "blog.cloudflare.com/page1",
        "blog.cloudflare.com/page2"
      ],
      "url_reported_malicious": false
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000,
    "total_pages": 100
  },
  "success": true,
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ]
}
```