Open
Cached
·
2h ago
13
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' *.commandbar.com; connect-src * *.commandbar.com https://*.commandbar.xyz:8000 https://uptight-batchelor.aws-us-east-2.cubecloudapp.dev https://*.ingest.us.sentry.io https://www.google-analytics.com https://api.intercom.io https://api-iam.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io https://uploads.intercomcdn.com https://uploads.intercomusercontent.com https://embed.explo.co https://analytics.explo.co https://data.explo.co https://data1.explo.co https://api.explo.co https://cdn.segment.com https://api.segment.io https://api.statsig.com https://heapanalytics.com https://pub.highlight.run https://commandbar-marketing-site.netlify.app https://commandbar-blog.netlify.app; font-src 'self' https://fonts.gstatic.com/ https://js.intercomcdn.com http://fonts.intercomcdn.com https://heapanalytics.com https://commandbar-marketing-site.netlify.app https://commandbar-blog.netlify.app https://ka-f.fontawesome.com; form-action https://intercom.help https://api-iam.intercom.io https://www.facebook.com https://commandbar-marketing-site.netlify.app https://commandbar-blog.netlify.app https://forms.hsforms.com; media-src *; img-src * data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.commandbar.com https://*.commandbar.xyz:8000 https://*.netlify.app https://app.intercom.io https://widget.intercom.io https://js.intercomcdn.com https://js.stripe.com https://www.googletagmanager.com https://cdn.segment.com https://embed.explo.co https://cdn.heapanalytics.com https://heapanalytics.com www.facebook.com connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://tpc.googlesyndication.com platform.twitter.com ads-twitter.com https://static.ads-twitter.com https://snap.licdn.com https://static-exp1.licdn.com https://content.linkedin.com https://platform.linkedin.com https://kit.fontawesome.com https://*.hs-scripts.com https://*.hubspot.com https://js.hscollectedforms.net https://js.hsadspixel.net https://js.hs-banner.com https://forms.hsforms.com https://*.usemessages.com https://js.hs-analytics.net https://*.hsforms.net https://app.getatlas.io https://static.highlight.io https://unpkg.com/web-vitals/dist/web-vitals.iife.js https://*.quora.com https://tag.clearbitscripts.com https://x.clearbitjs.com https://j.6sc.co https://www.googleoptimize.com https://pvdpix.com https://www.google-analytics.com https://commandbar-marketing-site.netlify.app https://commandbar-blog.netlify.app https://cdn.jsdelivr.net https://unpkg.com/ https://tracking.g2crowd.com; style-src 'self' 'unsafe-inline' *.commandbar.com https://*.commandbar.xyz:8000 https://*.netlify.app https://fonts.googleapis.com/ https://embed.explo.co https://unpkg.com/[email protected]/css/styles.css https://unpkg.com/@explo-tech/[email protected]/css/styles.css https://unpkg.com/[email protected]/dist/css/theme.min.css https://unpkg.com/[email protected]/dist/leaflet.css https://unpkg.com/[email protected]/dist/css/main.min.css https://commandbar-marketing-site.netlify.app https://commandbar-blog.netlify.app https://heapanalytics.com; frame-src 'self' *.commandbar.com https://*.commandbar.xyz:8000 https://*.netlify.app https://www.loom.com https://demo.arcade.software https://js.stripe.com/ www.facebook.com www.linkedin.com *.youtube.com/ youtu.be *.vimeo.com *.vidyard.com https://platform.twitter.com https://bid.g.doubleclick.net https://*.wistia.com https://*.wistia.net https://embedwistia-a.akamaihd.net https://commandbar-marketing-site.netlify.app https://commandbar-blog.netlify.app https://td.doubleclick.net/ https://forms.hsforms.com; frame-ancestors 'self' *.commandbar.com https://*.commandbar.xyz:8000 https://*.netlify.app; child-src https://intercom-sheets.com https://www.intercom-reporting.com https://commandbar-marketing-site.netlify.app https://commandbar-blog.netlify.app https://www.youtube.com https://www.vidyard.com https://player.vimeo.com https://demo.arcade.software https://fast.wistia.net; object-src 'none'; worker-src blob:;
default-src
Keyword
—
'self'
connect-src
Host
—
*
connect-src
Host
—
connect-src
Host
—
font-src
Keyword
—
'self'
media-src
Host
—
*
img-src
Host
—
*
img-src
Scheme
—
data:
img-src
Scheme
—
blob:
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Host
—
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
style-src
Host
—
frame-src
Keyword
—
'self'
frame-src
Host
—
frame-ancestors
Keyword
—
'self'
frame-ancestors
Host
—
object-src
Keyword
—
'none'
worker-src
Scheme
—
blob:
Content-Security-Policy-Report-Only
No report-only CSP headers found.