Open
Cached
·
just now
1
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' 'unsafe-inline' blob: data: *.fullstory.com *.ingest.sentry.io *.ingest.us.sentry.io *.mixpanel.com *.googleusercontent.com *.intercom.io *.intercomassets.com *.intercomcdn.com *.eu.intercom.io *.au.intercom.io https://intercom-sheets.com wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io wss://nexus-europe-websocket.intercom.io wss://nexus-australia-websocket.intercom.io *.typekit.net *.growsurf.com *.linkedin.com *.google-analytics.com *.googletagmanager.com *.youtube.com *.ytimg.com *.gstatic.com *.guidde.com *.guidde.co *.googleapis.com *.cloudinary.com https://*.microsoftonline.com api.stigg.io https://snap.licdn.com https://connect.facebook.net accounts.google.com apis.google.com https://graph.microsoft.com https://api.stripe.com https://hooks.stripe.com https://checkout.stripe.com https://js.stripe.com https://*.stripe.com https://js.hs-scripts.com https://script.tapfiliate.com/tapfiliate.js https://tapi.tapfiliate.com https://sc.lfeeder.com/lftracker_v1_kn9Eq4ROkQzaRlvP.js https://amplify.outbrain.com/cp/obtp.js https://js.hsadspixel.net/fb.js https://js.hs-banner.com https://js.hs-analytics.net https://tr.outbrain.com https://api.hubapi.com https://forms.hscollectedforms.net https://js.hscollectedforms.net/collectedforms.js https://track.hubspot.com https://static.hsappstatic.net https://forms.hsforms.com frstre.com assets.cello.so share.cello.so cdn.boxyhq.com *.facebook.com https://googleads.g.doubleclick.net https://www.googleadservices.com https://www.google.com https://www.google.co.in https://cdn.entail-insights.com/js/entail.js https://t.entail-insights.com/c https://www.youtube-nocookie.com/ https://analytics.google.com https://td.doubleclick.net https://youtu.be/ https://www.google.co.il https://www.google.com https://api.heygen.com *.churnkey.co *.saola.ai *.heygen.ai https://docs.google.com https://track-api-gw-1psqn9q9.uc.gateway.dev https://placehold.co https://stats.g.doubleclick.net https://www.redditstatic.com https://lh3.google.com https://lh3.googleusercontent.com *.reddit.com https://api.brandfetch.io https://cdn.brandfetch.io https://bat.bing.com https://*.intercom-messenger.com wss://*.intercom-messenger.com *.broadcast.app.guidde.com broadcast.app.guidde.com guidde-production.firebaseapp.com guidde-production.web.app wss://*.firebaseio.com https://*.firebaseio.com;
default-src
Keyword
—
'self'
default-src
Keyword
—
'unsafe-inline'
default-src
Scheme
—
blob:
default-src
Scheme
—
data:
default-src
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.