13 directives

Content-Security-Policy

upgrade-insecure-requests Source —
(no sources)
default-src Keyword —
'none'
img-src Keyword —
'none'
style-src Keyword —
'none'
script-src Nonce —
'nonce-xmwPMf799SfCsOwJOnZ63g=='
connect-src Keyword —
'none'
frame-ancestors Keyword —
'none'
base-uri Keyword —
'none'
object-src Keyword —
'none'
manifest-src Keyword —
'none'
sandbox Keyword —
allow-scripts
form-action Keyword —
'none'

Content-Security-Policy-Report-Only

No report-only CSP headers found.