Open
Cached
·
just now
11
directives
Content-Security-Policy
Content-Security-Policy: script-src 'self' blob: 'unsafe-eval' *.vendorpedia.com vendorlist.consensu.org *.vo.msecnd.net cdn.cookielaw.org *.chargebeeportal.com https://js.stripe.com *.aptrinsic.com static.cloudflareinsights.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ cdn.pendo.io pendo-static-4821648466051072.storage.googleapis.com 'sha256-yVHVcOm8BkBWcoZWeTzJ0jJ7z8OCCMxicEv2kTruVsA=' 'sha256-B4IZn05ZJPSk/61UEBtX5hIgK6YtOGBWsi8MgULkxMk=' 'sha256-oZhLbc2kO8b8oaYLrUc7uye1MgVKMyLtPqWR4WtKF+c=' 'sha256-E0TuAR2Ds5rZ2yeqw9H/uyFRuhJVZtDO7jPuwfTTXh0='; default-src https: wss: 'self' *.chargebeeportal.com *.nats.onetrust.com; style-src https: 'self' blob: 'unsafe-inline' *.chargebeeportal.com https://snippet.maze.co pendo-io-static.storage.googleapis.com; font-src https: 'self' data: *.chargebeeportal.com https://snippet.maze.co; object-src 'none'; connect-src https: 'self' blob: wss: https://prompts.maze.co https://api.maze.co data.pendo.io pendo-static-4821648466051072.storage.googleapis.com https://api.stripe.com; img-src data: * blob: https://snippet.maze.co data.pendo.io pendo-static-4821648466051072.storage.googleapis.com; child-src * blob:; media-src 'self' captcha.1trust.app captcha.onetrust.com www.google.com/recaptcha/ www.gstatic.com/recaptcha/ blob:; frame-src https: https://t.maze.co https://js.stripe.com https://hooks.stripe.com; worker-src 'self' blob:;
script-src
Keyword
—
'self'
script-src
Scheme
—
blob:
script-src
Keyword
—
'unsafe-eval'
script-src
Host
—
script-src
Hash
—
'sha256-yVHVcOm8BkBWcoZWeTzJ0jJ7z8OCCMxicEv2kTruVsA='
script-src
Hash
—
'sha256-B4IZn05ZJPSk/61UEBtX5hIgK6YtOGBWsi8MgULkxMk='
script-src
Hash
—
'sha256-oZhLbc2kO8b8oaYLrUc7uye1MgVKMyLtPqWR4WtKF+c='
script-src
Hash
—
'sha256-E0TuAR2Ds5rZ2yeqw9H/uyFRuhJVZtDO7jPuwfTTXh0='
default-src
Scheme
—
https:
default-src
Scheme
—
wss:
default-src
Keyword
—
'self'
default-src
Host
—
style-src
Scheme
—
https:
style-src
Keyword
—
'self'
style-src
Scheme
—
blob:
style-src
Keyword
—
'unsafe-inline'
style-src
Host
—
font-src
Scheme
—
https:
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
font-src
Host
—
object-src
Keyword
—
'none'
connect-src
Scheme
—
https:
connect-src
Keyword
—
'self'
connect-src
Scheme
—
blob:
connect-src
Scheme
—
wss:
img-src
Scheme
—
data:
img-src
Host
—
*
img-src
Scheme
—
blob:
child-src
Host
—
*
child-src
Scheme
—
blob:
media-src
Keyword
—
'self'
media-src
Scheme
—
blob:
frame-src
Scheme
—
https:
worker-src
Keyword
—
'self'
worker-src
Scheme
—
blob:
Content-Security-Policy-Report-Only
No report-only CSP headers found.