Open
Cached
·
just now
5
directives
Content-Security-Policy
Content-Security-Policy: default-src wss://* blob: data: sendpulse.com *.sendpulse.com *.sendpulse.com:4434 data.sendpulse.com *.pulse-stat.com *.stat-pulse.com *.pulse-stat.com:8080 *.stat-pulse.com:8080 http://*.sendpulse.com:4434 wss://ws.binotel.com:9002 http://*.pulse-stat.com http://*.stat-pulse.com http://*.pulse-stat.com:8080 http://*.stat-pulse.com:8080 *.sendpulse.ua sendpulse.ua *.sendpulse.by *.sendpulse.kz *.sendpulse.cl *.sendpulse.com.tr *.sendpulse.ng sendpul.se *.sendpul.se trckln.com *.loginsrc.com *.routee.net *.routee.net:444 *.jquery.com *.youtu.be youtu.be *.youtube.com youtube.com *.ytimg.com *.vimeo.com *.vimeocdn.com *.tinymce.com *.ampproject.org *.hotjar.com *.hotjar.io *.ipinfo.io *.highcharts.com *.appspot.com *.doubleclick.net *.facebook.com *.facebook.net *.fbcdn.net *.fbsbx.com *.rawgit.com *.cloudflare.com *.jsdelivr.net *.kissmetrics.com *.quantserve.com *.quantcount.com *.twitter.com *.offershub.ru *.stripe.com *.braintreegateway.com *.mlstatic.com *.woopra.com *.jivosite.com *.google.com *.google.com.ua https://google.com/pay *.googleadservices.com *.google-analytics.com *.googleapis.com *.googletagmanager.com *.gstatic.com *.online-metrix.net *.retently.com *.maxmind.com *.revisionme.com revisionme.pages.dev *.mmapiws.com *.bootstrapcdn.com *.kaptcha.com *.paypal.com *.paypalobjects.com *.mercadopago.com.br *.mercadopago.com dl-media.viber.com *.braintree-api.com api.telegram.org *.goentri.com *.entri.com *.webformscr.com *.cardinalcommerce.com *.mercadolibre.com *.supportsrc.com *.instagram.com *.cdninstagram.com s3.eu-central-1.amazonaws.com *.googleoptimize.com *.sppopups.com *.privatbank.ua *.cardinalcommerce.com viacep.com.br *.wdgtsrc.com 1860267202.rsc.cdn77.org 1443908614.rsc.cdn77.org *.2checkout.com *.licdn.com *.linkedin.com *.cookiebot.com *.clarity.ms *.crisp.chat *.amplitude.com hcaptcha.com *.hcaptcha.com view.officeapps.live.com 'self' 'unsafe-eval' 'unsafe-inline'; img-src blob: data: *; font-src data: *; style-src * 'unsafe-inline';, frame-ancestors 'self';
default-src
Host
—
wss://*
default-src
Scheme
—
blob:
default-src
Scheme
—
data:
default-src
Host
—
default-src
Host
—
default-src
Host
—
default-src
Host
—
default-src
Host
—
default-src
Host
—
default-src
Host
—
default-src
Keyword
—
'self'
default-src
Keyword
—
'unsafe-eval'
default-src
Keyword
—
'unsafe-inline'
img-src
Scheme
—
blob:
img-src
Scheme
—
data:
img-src
Host
—
*
font-src
Scheme
—
data:
font-src
Host
—
*
style-src
Host
—
*
style-src
Keyword
—
'unsafe-inline'
,
Host
—
,
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.