14 directives

Content-Security-Policy

base-uri Keyword
'none'
font-src Keyword
'self'
font-src Scheme
https:
font-src Scheme
data:
form-action Keyword
'self'
frame-ancestors Keyword
'self'
img-src Keyword
'self'
img-src Scheme
data:
img-src Host
object-src Keyword
'none'
script-src-attr Keyword
'unsafe-inline'
style-src Keyword
'self'
style-src Scheme
https:
style-src Keyword
'unsafe-inline'
script-src Keyword
'self'
script-src Scheme
https:
script-src Keyword
'strict-dynamic'
script-src Hash
'sha256-kq5ziRk1cYH1zpbaHP+zoOuq4O4yyyiEDk4LqDOEnqQ='
script-src Hash
'sha256-ee8OPmlOWF4m3ih7qox2Kp8KhzpQ7QfLEr9FCc3fMGo='
script-src Hash
'sha256-IAOHtZ86xDdUHnZaFdEr0Kx5jZoH/lz4OYXDGiL3JOw='
script-src Hash
'sha384-M9ebCGp+bq8Yd9fG/QMwiXgHGdNcc77t5Hq9QYNbWfK2oJRtNCI1a3S/WO+7AxMy'
script-src Hash
'sha384-f5UEwj+7F7OoakRGeJoTqTdaYbPXp9D/X+t8U5plCQxqKdtGMUwyiyQDUltiR6bd'
script-src Hash
'sha384-bl4kji/7KhDHktEWMMvTNRC4aZhZJ+PaEBnX4bhjTg+grqYh19SoDZHQzAHvGyaY'
script-src Hash
'sha384-WnTJ69ragr0PDvbRjose4cUZ+XRDPWLZ/VN6D2NKV51qUwuBk/9Pse7lfHdQYAkq'
script-src Hash
'sha384-7Nx0v3IygEf6IS4P7TP2O5RRsQ+ZmniAPcx5UFeYhpJNKdvqexj75oyd8ddeX5QF'
script-src Hash
'sha384-+hpndP3YwitJ4+YDDjznQJ8eioxTP11zS0vWMA+iNHoeQ4b+71p2P8760p0om+yN'
script-src Hash
'sha384-xDspCWyBCcaOsrp2JcgCnbqjRc59tSLEORmybl+I9LInAjflG4Jpql70FcQ1fs8x'
script-src Hash
'sha384-Lxq31m0BJm9aNSjBudWoxEHoHaR1BKMfkLNxWq3feblOpg13BZCo1rY7zFEurLev'
script-src Hash
'sha384-iIas6gi/JNOlqhibyNKQ/3LSKeUgDc6VTlmKH8oyMpcsu/AHAnHge13YqevcuYJt'
script-src Hash
'sha384-rqBR3lRDogR15EvO79xMCd7K3hSFCJtAhpyIQ/lIQRSQPdfIhL4Hir/V6evhDGDy'
script-src Hash
'sha384-ahklVkgtn9qTWMgRt8HoCIowU4oNECNwaRQtn5Ys4YREfqHULJbJoPMGJpU6Y6i2'
script-src Hash
'sha384-iEbihUHVJp61DAIbj9UxqXJCJugEwl1EDsXWCLZE8uJySZh+Dnubf12P0ts7+wv8'
script-src Hash
'sha384-i0u2lImG9HevS2O41Oz+9i/cD8EQisiWCDsHqCyna1H6WBqztj5yJQRp+jpsJXa5'
script-src Hash
'sha384-c/jhe3QQUiFj6tMEEwXHVdk0g12cGepOrXfxSzR6Gs2bFGTswmdcGaYDwhpAJeMD'
script-src Hash
'sha384-0Lr2dztt56MBjWVsUgbkEEFstESUp6iyaH7q4aQ+zGI//70psouRji0CvWZ9ZxY8'
upgrade-insecure-requests Source
(no sources)
connect-src Keyword
'self'
connect-src Host
connect-src Host
ASN | Google
connect-src Host
default-src Keyword
'self'
frame-src Keyword
'self'
frame-src Scheme
https:
frame-src Scheme
data:
media-src Keyword
'self'

Content-Security-Policy-Report-Only

No report-only CSP headers found.