Open
Cached
·
just now
10
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' data: 'unsafe-inline' www.google.com *.hsforms.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' www.gstatic.com www.google.com cdn.ampproject.org cdn.emerchantpay.com cdn.partner-resource-centre.emerchantpay.com d22a94htilc27o.cloudfront.net code.jquery.com www.googletagmanager.com *.clarity.ms js.hs-scripts.com static.ads-twitter.com js.hs-banner.com js.hsforms.net js.hs-analytics.net js.hsadspixel.net js.hubspot.com snap.licdn.com connect.facebook.net maxcdn.bootstrapcdn.com www.redditstatic.com www.google-analytics.com; style-src 'unsafe-inline' secure.gravatar.com *.emerchantpay.com fonts.googleapis.com cdn.emerchantpay.com cdn.partner-resource-centre.emerchantpay.com d22a94htilc27o.cloudfront.net maxcdn.bootstrapcdn.com; img-src 'self' data: *.linkedin.com www.googletagmanager.com *.hsforms.com *.google-analytics.com t.co www.facebook.com analytics.twitter.com track.hubspot.com px.ads.linkedin.com cdn.emerchantpay.com cdn.partner-resource-centre.emerchantpay.com d22a94htilc27o.cloudfront.net *.emerchantpay.com secure.gravatar.com alb.reddit.com; font-src data: *.emerchantpay.com fonts.gstatic.com fonts.googleapis.com; connect-src 'self' yoast.com *.clarity.ms forms.hubspot.com *.hsforms.com hubspot-forms-static-embed.s3.amazonaws.com px.ads.linkedin.com api.hubapi.com *.google-analytics.com connect.facebook.net cdn.ampproject.org www.googletagmanager.com pixel-config.reddit.com www.redditstatic.com conversions-config.reddit.com www.google.com www.facebook.com static.hsappstatic.net cta-service-cms2.hubspot.com; media-src cdn.emerchantpay.com cdn.partner-resource-centre.emerchantpay.com d22a94htilc27o.cloudfront.net partner-resource-centre.emerchantpay.com; object-src 'none'; frame-src * data: blob: ; frame-ancestors 'self' www.google.com *.hubspot.com *.emerchantpay.com
default-src
Keyword
—
'self'
default-src
Scheme
—
data:
default-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
style-src
Keyword
—
'unsafe-inline'
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
font-src
Scheme
—
data:
connect-src
Keyword
—
'self'
object-src
Keyword
—
'none'
frame-src
Host
—
*
frame-src
Scheme
—
data:
frame-src
Scheme
—
blob:
frame-ancestors
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.