Open
Cached
·
just now
9
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' *.hubspotusercontent40.net *.netdna-ssl.com *.marketo.com *.cloudfront.net *.zoominfo.com; script-src blob: data: 'self' 'unsafe-inline' 'unsafe-eval' *.demandbase.com *.influitive.com *.b-cdn.net *.clearbitjs.com *.hscta.net *.usemessages.com *.clickagy.com *.hubspot.com *.google.com *.googleoptimize.com *.hsforms.net *.doubleclick.net *.hs-analytics.net *.hs-banner.com *.hsadspixel.net *.hsleadflows.net *.hscollectedforms.net *.hs-scripts.com *.6sc.co *.dreamdata.cloud *.capterra.com *.sf-syn.com *.googleadservices.com *.netdna-ssl.com *.vidyard.com cdn.jsdelivr.net www.googletagmanager.com secure.gift2pair.com *.olark.com polyfill.io www.google-analytics.com *.marketo.com scout-cdn.salesloft.com tracking.g2crowd.com v2.listenloop.com grow.clearbit.com s.adroll.com *.intercom.io *.hotjar.com static.ads-twitter.com snap.licdn.com connect.facebook.net *.cloudfront.net munchkin.marketo.net js.intercomcdn.com *.adroll.com *.twitter.com *.zoominfo.com ssl.chatanexpert.com *.trustradius.com *.chilipiper.com *.addevent.com *.hsappstatic.net; style-src 'self' 'unsafe-inline' *.cdnfonts.com *.influitive.com *.cloudfront.net *.b-cdn.net *.google.com *.netdna-ssl.com use.fontawesome.com cdn.jsdelivr.net *.olark.com *.marketo.com fonts.googleapis.com *.trustradius.com; font-src data: 'self' *.cdnfonts.com *.influitive.com *.b-cdn.net *.intercomcdn.com fonts.gstatic.com *.netdna-ssl.com use.fontawesome.com *.olark.com *.cloudfront.net; img-src data: 'self' 'unsafe-inline' *.influitive.com *.b-cdn.net *.hs-embed-reporting.com *.sitescout.com *.hubspotusercontent-na1.net *.demdex.net *.agkn.com *.clickagy.com *.crwdcntrl.net *.rlcdn.com *.hsappstatic.net *.elegantthemes.com *.gstatic.com *.hsforms.com *.hubspot.com *.twitter.com *.6sc.co *.googleadservices.com *.doubleclick.net *.capterra.com *.linkedin.com *.marketo.com *.intercomcdn.com *.intercomassets.com *.postbeyond.com *.google.ca *.google.com *.g2crowd.com *.googletagmanager.com *.netdna-ssl.com secure.gravatar.com *.vidyard.com grow.clearbitjs.com px.ads.linkedin.com t.co www.facebook.com *.olark.com *.adroll.com segment.prod.bidr.io px4.ads.linkedin.com dsum-sec.casalemedia.com pixel.rubiconproject.com pixel.advertising.com simage2.pubmatic.com sync.outbrain.com ads.yahoo.com sync.taboola.com eb2.3lift.com x.bidswitch.net ib.adnxs.com idsync.rlcdn.com us-u.openx.net p.adsymptotic.com ups.analytics.yahoo.com segments.company-target.com *.intercom.io px.surveywall-api.survata.com tags.rd.linksynergy.com *.spotify.com a.tribalfusion.com *.wpengine.com ps.w.org www.google-analytics.com dp-sync.dotomi.com *.google.com *.cloudfront.net *.trustradius.com *.chilipiper.com *.addevent.com; connect-src 'self' *.6sense.com *.googlesyndication.com *.google.com *.uc.r.appspot.com *.plyr.io *.vouchfor.com *.hscollectedforms.net *.facebook.com *.company-target.com *.influitive.com *.hubspotusercontent40.net *.hs-banner.com *.linkedin.oribi.io *.g2.com *.digitaloceanspaces.com *.clickagy.com *.elegantthemes.com *.hsforms.com *.s3.amazonaws.com *.hubspot.com *.hubapi.com *.adnxs.com *.6sc.co *.hotjar.io *.dreamdata.cloud *.netdna-ssl.com *.olark.com play.vidyard.com abm2.listenloop.com notify.bugsnag.com *.mktoresp.com *.hotjar.com *.intercom.io wss://nexus-websocket-a.intercom.io ws.zoominfo.com yoast.com *.wpengine.com www.google-analytics.com *.cloudfront.net stats.g.doubleclick.net *.salesloft.com *.trustradius.com *.chilipiper.com; prefetch-src 'self' *.jotform.com *.netdna-ssl.com play.vidyard.com; frame-src 'self' *.vouchfor.com *.company-target.com *.influitive.com *.jotform.com *.jotformeu.com *.hs-sites.com *.google.com *.doubleclick.net *.hsforms.com *.sf-syn.com *.g2.com *.spotify.com *.applytojob.com *.netdna-ssl.com *.hotjar.com www.facebook.com *.olark.com *.marketo.com *.vidyard.com *.trustradius.com *.hubspot.com *.hsappstatic.net *.chilipiper.com *.hubspotusercontent40.net *.static.hsappstatic.net; media-src blob: 'self' *.vouchfor.com *.cloudfront.net *.plyr.io *.influitive.com *.intercomcdn.com *.netdna-ssl.com *.olark.com *.jotform.com *.chilipiper.com *.hubspotusercontent40.net;
default-src
Keyword
—
'self'
script-src
Scheme
—
blob:
script-src
Scheme
—
data:
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Host
—
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
font-src
Scheme
—
data:
font-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Keyword
—
'self'
img-src
Keyword
—
'unsafe-inline'
img-src
Host
—
img-src
Host
—
img-src
Host
—
img-src
Host
—
img-src
Host
—
connect-src
Keyword
—
'self'
connect-src
Host
—
prefetch-src
Keyword
—
'self'
frame-src
Keyword
—
'self'
media-src
Scheme
—
blob:
media-src
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.