Open
Cached
·
just now
5
directives
Content-Security-Policy
No enforced CSP headers found.
Content-Security-Policy-Report-Only
Content-Security-Policy-Report-Only: default-src * 'self' data: 'unsafe-inline' 'unsafe-eval'; referrer no-referrer-when-downgrade; upgrade-insecure-requests; block-all-mixed-content; report-uri https://cosmb.report-uri.io/r/default/csp/reportOnly;
default-src
Host
—
*
default-src
Keyword
—
'self'
default-src
Scheme
—
data:
default-src
Keyword
—
'unsafe-inline'
default-src
Keyword
—
'unsafe-eval'
referrer
Host
—
upgrade-insecure-requests
Source
—
(no sources)
block-all-mixed-content
Source
—
(no sources)