Open
Cached
·
7h ago
2
directives
Content-Security-Policy
No enforced CSP headers found.
Content-Security-Policy-Report-Only
Content-Security-Policy-Report-Only: default-src 'self' 'unsafe-inline' 'unsafe-eval' data: *.clickhelp.com *.gravatar.com *.googleapis.com *.gstatic.com *.googleusercontent.com *.google-analytics.com *.googletagmanager.com *.fontawesome.com mc.yandex.ru cdnjs.cloudflare.com cdn.jsdelivr.net integration.graphcomment.com *.youtube.com *.vimeo.com canny.io *.canny.io *.calendly.com d3h3meckw07nf.cloudfront.net *.scalar.com; frame-ancestors 'self';
default-src
Keyword
—
'self'
default-src
Keyword
—
'unsafe-inline'
default-src
Keyword
—
'unsafe-eval'
default-src
Scheme
—
data:
frame-ancestors
Keyword
—
'self'