Open
Cached
·
just now
1
directives
Content-Security-Policy
Content-Security-Policy: script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https://firestore.googleapis.com https://netlify-cdp-loader.netlify.app https://segment.com https://www.youtube.com https://use.typekit.net https://consent.trustarc.com https://cdn.jsdelivr.net https://apis.google.com https://www.googletagmanager.com https://cdn.heapanalytics.com https://maps.googleapis.com https://static.ads-twitter.com https://www.google-analytics.com https://googleads.g.doubleclick.net https://*.hotjar.com https://426814.tctm.xyz https://*.force.com https://*.chilipiper.com https://*.facebook.net https://*.bing.com https://snap.licdn.com https://*.salesforceliveagent.com https://*.salesforce.com https://*.site.com https://*.fullstory.com https://*.googleadservices.com https://redditstatic.com https://*.reddit.com https://*.outbrain.com https://*.redditstatic.com https://*.adsrvr.org https://*.cloudfront.net https://*.ghost.io https://*.referralsaasquatch.com https://vercel.live https://*.adnxs.com https://*.salesforce-scrt.com, https://*.contentsquare.net,
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-inline'
script-src
Scheme
—
blob:
script-src
Host
—
script-src
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.