Open
Cached
·
just now
10
directives
Content-Security-Policy
Content-Security-Policy: script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https://cdn.snitcher.com https://rp4.liadm.com/ https://api.onesignal.com/ https://cdn-cookieyes.com https://cdn.bolddesk.com https://support.boldreports.com https://www.redditstatic.com https://bat.bing.com https://static.ads-twitter.com https://static.cloudflareinsights.com *.clarity.ms https://cdn.boldreports.com d3mx6exl5w6355.cloudfront.net yoast.com faq.boldreports.com.s3-website-us-east-1.amazonaws.com cdn.onesignal.com onesignal.com assets.calendly.com static.hotjar.com script.hotjar.com dev-chat-integration.bolddesk.com https://cdn.syncfusion.com https://www.googletagmanager.com https://cdn.swaychat.com netdna.bootstrapcdn.com www.youtube.com api.swayio.com www.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net a.opmnstr.com serve.albacross.com cdnjs.cloudflare.com djtflbt20bdde.cloudfront.net connect.facebook.net www.google.com www.gstatic.com cdn.jsdelivr.net d3rgboivvvc92.cloudfront.net dev-boldreports.bolddesk.com storage.googleapis.com cse.google.com; img-src 'self' data: https://rp4.liadm.com/ https://fonts.gstatic.com/ https://www.google.com https://bat.bing.net/ https://www.google.co.uk/ https://s3.us-east-1.amazonaws.com https://cdn.bolddesk.com https://cdnjs.cloudflare.com https://library.keydesign.xyz https://boldreports.com https://support.boldreports.com *.clarity.ms analytics.twitter.com t.co *.bing.com alb.reddit.com redirect.prod.experiment.routing.cloudfront.aws.a2z.com assets.calendly.com https://cdn-cookieyes.com https://cdn.bolddesk.com/chat/ cdn.boldbi.com www.googletagmanager.com connect.facebook.net cdn.syncfusion.com cdn.swaychat.com storage.googleapis.com www.gravatar.com i.ytimg.com tawk.link www.google-analytics.com www.google.com www.google.co.in googleads.g.doubleclick.net new-collect.albacross.com secure.gravatar.com ps.w.org www.facebook.com cdn.jsdelivr.net stats.g.doubleclick.net cdn.boldreports.com static.hotjar.com script.hotjar.com d3rgboivvvc92.cloudfront.net; style-src 'self' 'unsafe-inline' https://www.googletagmanager.com/ cdn.bolddesk.com qik.radiantthemes.com code.jquery.com onesignal.com cdn.syncfusion.com assets.calendly.com storage.googleapis.com fonts.googleapis.com cdn.jsdelivr.net static.hotjar.com script.hotjar.com d3rgboivvvc92.cloudfront.net cse.google.com www.google.com; frame-src 'self' vars.hotjar.com https://www.g2.com calendly.com *.syncfusion.com https://www.googletagmanager.com bid.g.doubleclick.net www.youtube.com www.youtube-nocookie.com www.google.com www.gstatic.com dev-boldreports.bolddesk.com cse.google.com; frame-ancestors 'self'; form-action 'self'; base-uri 'self'; media-src 'self' https://www.google.com/ cdn.boldbi.com https://storage.cloud.google.com/ cdn.syncfusion.com storage.googleapis.com cdn.boldreports.com; object-src 'none'; connect-src 'self' https://radar.snitcher.com https://rp4.liadm.com/ https://www.google.co.in/ https://googleads.g.doubleclick.net https://www.google.com https://www.googletagmanager.com/ https://www.googleadservices.com/ https://bat.bing.net/ https://region1.analytics.google.com/ https://api.country.is/ https://stats.g.doubleclick.net https://api64.ipify.org *.clarity.ms cdn.onesignal.com directory.cookieyes.com support.boldreports.com pixel-config.reddit.com *.clarity.ms bat.bing.com https://api.onesignal.com https://cdn.boldreports.com/ https://cdn.boldbi.com/ https://onesignal.com/ https://log.cookieyes.com/ https://cdn-cookieyes.com/ *.hotjar.com *.hotjar.io ws://*.hotjar.com wss://chat-server.bolddesk.com analytics.syncfusion.com dev-chat-integration.bolddesk.com analytics.google.com cse.google.com;
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Scheme
—
data:
script-src
Scheme
—
blob:
script-src
Host
—
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
frame-src
Keyword
—
'self'
frame-src
Host
—
frame-ancestors
Keyword
—
'self'
form-action
Keyword
—
'self'
base-uri
Keyword
—
'self'
media-src
Keyword
—
'self'
object-src
Keyword
—
'none'
connect-src
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.