Open
Cached
·
1h ago
9
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://www.dwin1.com https://*.trustpilot.com https://www.google-analytics.com https://*.heartinternet.uk http://*.doubleclick.net https://*.doubleclick.net https://*.twitter.com http://static.ads-twitter.com https://static.ads-twitter.com https://connect.facebook.net https://www.googletagmanager.com https://t.co https://www.facebook.com https://www.google.com http://www.google.com https://www.google.co.uk https://www.google.de; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com https://www.dwin1.com https://*.awin1.com https://the.sciencebehindecommerce.com https://static.cloudflareinsights.com https://googleads.g.doubleclick.net https://*.termly.io https://adac.api.yoursrs.com/static/client.js https://adac.api.yoursrs.com/ajax https://*.cloudstorage.secureserver.net https://snap.licdn.com https://*.trustpilot.com https://*.googleapis.com https://code.jquery.com http://img1.wsimg.com https://analytics.twitter.com https://*.heartinternet.uk https://img1.wsimg.com https://*.twitter.com http://static.ads-twitter.com https://static.ads-twitter.com https://www.google-analytics.com https://www.googletagmanager.com https://connect.facebook.net https://cdn.polyfill.io http://*.tiqcdn.com https://*.tiqcdn.com https://*.cloudflare.com https://*.trustpilot.com https://*.bootstrapcdn.com https://*.heg-cp.com https://*.contentsquare.net https://app.contentsquare.com; style-src 'self' 'unsafe-inline' https://*.heartinternet.uk http://*.googleapis.com https://*.googleapis.com https://*.bootstrapcdn.com https://*.jsdelivr.net; font-src 'self' 'unsafe-inline' https://*.heartinternet.uk https://releases.flowplayer.org https://*.bootstrapcdn.com; img-src 'self' data: https://*.awin1.com https://www.googletagmanager.com https://*.ads.linkedin.com https://www.google.co.uk https://*.heartinternet.uk http://googleads.g.doubleclick.net http://t.co https://t.co http://www.google.com https://www.google.co.uk https://www.google.de https://www.facebook.com https://www.google.com https://*.doubleclick.net https://www.google-analytics.com https://*.akstat.io https://*.akamaihd.net https://analytics.twitter.com https://*.contentsquare.net; frame-src 'self' https://*.awin1.com https://*.trustpilot.com https://www.google-analytics.com https://*.heartinternet.uk http://*.doubleclick.net https://*.doubleclick.net https://*.twitter.com http://static.ads-twitter.com https://static.ads-twitter.com https://connect.facebook.net https://www.googletagmanager.com https://t.co https://www.facebook.com https://www.google.com http://www.google.com https://www.google.co.uk https://www.google.de; connect-src 'self' https://*.awin1.com https://www.wepowerconnections.com https://www.zenaps.com https://the.sciencebehindecommerce.com https://www.google.com https://customer.heartinternet.uk/cp/public/v1.0/prices/domains https://customer.heartinternet.uk/cp/public/v1.0/subscriptions https://wwws.heartinternet.uk https://*.termly.io https://customer.heartinternet.uk/manage/basket.cgi https://customer.heartinternet.uk/manage/domain-search-data.cgi https://adac.api.yoursrs.com/ajax wss://adac.api.yoursrs.com/ws https://*.akstat.io https://*.go-mpulse.net https://cdn.linkedin.oribi.io https://*.akamaihd.net https://region1.google-analytics.com https://stats.g.doubleclick.net https://region1.analytics.google.com https://*.contentsquare.net https://*.contentsquare.com; worker-src blob:; child-src blob:;
default-src
Keyword
—
'self'
default-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Host
—
script-src
Host
—
script-src
Host
—
script-src
Host
—
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
font-src
Keyword
—
'self'
font-src
Keyword
—
'unsafe-inline'
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Host
—
frame-src
Keyword
—
'self'
connect-src
Keyword
—
'self'
connect-src
Host
—
connect-src
Host
—
connect-src
Host
—
worker-src
Scheme
—
blob:
child-src
Scheme
—
blob:
Content-Security-Policy-Report-Only
No report-only CSP headers found.