Open
Cached
·
5m ago
9
directives
Content-Security-Policy
Content-Security-Policy: script-src 'self' 'unsafe-inline' 'unsafe-eval' data: cdn.jsdelivr.net *.clarity.ms *.crisp.chat static.cloudflareinsights.com *.omwpapi.com *.typekit.net *.syncfusion.com www.youtube.com *.yandex.ru *.ytimg.com cdn.syncfusion.com www.googletagmanager.com *.googleapis.com netdna.bootstrapcdn.com *.firebaseio.com www.google-analytics.com www.googleadservices.com googleads.g.doubleclick.net a.opmnstr.com *.hotjar.com serve.albacross.com certify-js.alexametrics.com cdnjs.cloudflare.com *.cloudfront.net connect.facebook.net www.google.com *.tawk.to tagmanager.google.com *.gstatic.com cdn.bolddesk.com *.boldbi.com *.boldreports.com *.ampproject.org cdn.onesignal.com *.omappapi.com onesignal.com cdn-cookieyes.com *.bing.com; img-src 'self' data: cdn.syncfusion.com *.google.com *.bing.com *.clarity.ms *.yandex.com *.crisp.chat *.googleapis.com *.omappapi.com *.typekit.net *.omwpapi.com s.w.org a.opmnstr.com www.gravatar.com *.ytimg.com *.yandex.ru tawk.link *.tawk.to www.google-analytics.com www.google.com www.google.co.in googleads.g.doubleclick.net certify.alexametrics.com certify-amp.alexametrics.com *.syncfusion.com *.albacross.com secure.gravatar.com ps.w.org www.facebook.com cdn.jsdelivr.net stats.g.doubleclick.net *.gstatic.com cdn.bolddesk.com *.boldbi.com *.boldreports.com *.syncfusion.com syncfusion-contents.s3.amazonaws.com img.onesignal.com www.googletagmanager.com redirect.prod.experiment.routing.cloudfront.aws.a2z.com cdn-cookieyes.com; style-src 'self' 'unsafe-inline' *.clarity.ms *.googleapis.com cdn.jsdelivr.net *.syncfusion.com cdn.syncfusion.com *.crisp.chat *.tawk.to *.fontawesome.com *.omappapi.com *.cloudfront.net fonts.googleapis.com *.gstatic.com tagmanager.google.com www.googletagmanager.com cdn.bolddesk.com *.boldbi.com *.boldreports.com onesignal.com cdn-cookieyes.com; frame-src 'self' *.stripe.com https://calendly.com/ *.facebook.com td.doubleclick.net *.googletagmanager.com *.clarity.ms *.hotjar.com *.tawk.to *.opmnstr.com *.firebaseio.com *.syncfusion.com blob: bid.g.doubleclick.net *.addthis.com www.youtube.com www.youtube-nocookie.com *.google.com www.gstatic.com *.boldbi.com cdn.bolddesk.com *.boldreports.com onesignal.com *.moz.com ; frame-ancestors 'self' https://ej2.syncfusion.com/; media-src 'self' *.googleapis.com *.syncfusion.com *.boldbi.com cdn.bolddesk.com *.boldreports.com; worker-src blob: *.syncfusion.com ; object-src 'none'; base-uri 'none';
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Scheme
—
data:
script-src
Host
—
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Host
—
img-src
Host
—
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
frame-src
Keyword
—
'self'
frame-src
Scheme
—
blob:
frame-ancestors
Keyword
—
'self'
media-src
Keyword
—
'self'
worker-src
Scheme
—
blob:
object-src
Keyword
—
'none'
base-uri
Keyword
—
'none'
Content-Security-Policy-Report-Only
No report-only CSP headers found.