Open
Cached
·
just now
3
directives
Content-Security-Policy
Content-Security-Policy: object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' static.hsappstatic.net mcprod.hookah-shisha.com www.googletagmanager.com cdn.statstrk01.com cdn-widgetsrepository.yotpo.com *.yotpo.com js-eu1.usemessages.com js-eu1.hs-analytics.net js-eu1.hs-banner.com js-eu1.hscollectedforms.net www.youtube.com static.doubleclick.net www.gstatic.com js-agent.newrelic.com bam.nr-data.net *.ryzeo.com www.google-analytics.com *.signifyd.com *.spreedly.com *.privy.com www.hookah-shisha.com pop1.screenpopper.com www.googleoptimize.com *.surfside.io *.mczbf.com growth-hit.s3.us-west-2.amazonaws.com smct.co js.smct.io js.alocdn.com *.shop.pe d3rr3d0n31t48m.cloudfront.net static.bouncepilot.com addshoppers.s3.amazonaws.com static.addtoany.com imgs.cdn-btsg.com js-eu1.hsforms.net www.google.com/recaptcha/ *.klarnacdn.net *.vr-pay-ecommerce.de *.hotjar.com *.hotjar.io *.klaviyo.com connect.facebook.net cdn01.basis.net www.google.com *.pagesense.io *.zohopublic.com *.zohocdn.com *.zohostatic.com track.omguk.com addshoppers.com d2mjzob2nc713b.cloudfront.net *.traversedlp.com voltn.com wt.rqtrk.eu *.criteo.com shop.pe/widget/conv shop.pe/widget/conv/* shop.pe/widget/main/init/params shop.pe/widget/widget_async.js https://shop.pe/widget/conv https://shop.pe/widget/conv/params https://shop.pe/widget/conv/params* *.hookah-shisha.com *.southsmoke.com maps.googleapis.com player.vimeo.com us.ooka.com usa.ooka.com h64.online-metrix.net 3liglobal.github.io cdn.mida.so cdn.noibu.com *.hubspot.com *.hubspotfeedback.com *.payfabric.com cdn.userway.org alfakher2019.github.io unpkg.com livesearch-autocomplete.magento-ds.com livesearch-metrics.magento-ds.com vr-pay-ecommerce.de *.cookiefirst.com salesiq.zohopublic.eu *.hs-scripts.com data.hookah.com cdn.jsdelivr.net shisha-world.com tagmanager.google.com; report-uri /.webscale/csp-report
object-src
Keyword
—
'none'
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-hashes'
script-src
Keyword
—
'unsafe-inline'
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src
Host
—
report-uri
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.