Open
Cached
·
just now
14
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self';script-src 'self' 'unsafe-eval' 'unsafe-inline' ajax.aspnetcdn.com ajax.googleapis.com api.yoti.com cdn-ukwest.onetrust.com cdn.aws.yoti.com connect.facebook.net core.yoti.com forms.hsforms.com googleads.g.doubleclick.net js.hs-analytics.net js.hs-banner.com js.hs-scripts.com js.hsadspixel.net js.hscollectedforms.net js.hsforms.net s.ytimg.com script.hotjar.com snap.licdn.com static.hotjar.com www.google-analytics.com www.google.com www.googletagmanager.com code.yoti.com www-assets.yoti.com www.yoti.com;child-src 'none';connect-src 'self' 'unsafe-inline' analytics.google.com api.hubapi.com api.yoti.com cdn-ukwest.onetrust.com cdn.jsdelivr.net connect.facebook.net content.hotjar.io core.yoti.com forms.hscollectedforms.net forms.hsforms.com hubspot-forms-static-embed.s3.amazonaws.com metrics.hotjar.io privacyportal-uk.onetrust.com px.ads.linkedin.com region1.analytics.google.com region1.google-analytics.com static.hsappstatic.net stats.g.doubleclick.net vc.hotjar.io wss: www.facebook.com www.google.com code.yoti.com www.yoti.com;font-src 'self' cdn.aws.yoti.com cdn.jsdelivr.net cdnjs.cloudflare.com fonts.gstatic.com www-assets.yoti.com www.yoti.com;form-action 'self' forms.hsforms.com www.facebook.com;frame-src 'self' forms.hsforms.com player.vimeo.com www.facebook.com www.googletagmanager.com www.youtube.com youtube.com;frame-ancestors 'none';img-src 'self' api.yoti.com cdn-ukwest.onetrust.com cdn.aws.yoti.com core.yoti.com data: forms-na1.hsforms.com forms.hsforms.com get.yoti.com googleads.g.doubleclick.net i.ytimg.com px.ads.linkedin.com s.youtube.com stats.g.doubleclick.net track.hubspot.com www.facebook.com www.google-analytics.com www.google.co.uk www.google.com www.googletagmanager.com www.linkedin.com www.youtube.com code.yoti.com www-assets.yoti.com www.yoti.com;media-src cdn.aws.yoti.com;object-src 'none';style-src 'self' 'unsafe-inline' api.yoti.com cdn.aws.yoti.com cdn.jsdelivr.net cdnjs.cloudflare.com core.yoti.com fonts.googleapis.com s.ytimg.com code.yoti.com www-assets.yoti.com www.yoti.com;upgrade-insecure-requests;block-all-mixed-content;
default-src
Keyword
—
'self'
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-inline'
child-src
Keyword
—
'none'
connect-src
Keyword
—
'self'
connect-src
Keyword
—
'unsafe-inline'
connect-src
Scheme
—
wss:
font-src
Keyword
—
'self'
form-action
Keyword
—
'self'
frame-src
Keyword
—
'self'
frame-ancestors
Keyword
—
'none'
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Host
—
object-src
Keyword
—
'none'
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
upgrade-insecure-requests
Source
—
(no sources)
block-all-mixed-content
Source
—
(no sources)
Content-Security-Policy-Report-Only
No report-only CSP headers found.