Open
Cached
·
just now
8
directives
Content-Security-Policy
No enforced CSP headers found.
Content-Security-Policy-Report-Only
Content-Security-Policy-Report-Only: default-src https: 'unsafe-eval' 'unsafe-inline';script-src 'unsafe-eval' 'unsafe-inline' 'self' *.grouponcdn.com bat.bing.com mpsnare.iesnare.com *.boldchat.com www.googleadservices.com static.criteo.net connect.facebook.net b-code.liadm.com www.googletagmanager.com sslwidget.criteo.com *.groupon.com *.googleapis.com *.groupondev.com sc-static.net;connect-src 'unsafe-eval' 'unsafe-inline' 'self' *.grouponcdn.com bat.bing.com mpsnare.iesnare.com *.boldchat.com www.googleadservices.com static.criteo.net connect.facebook.net b-code.liadm.com www.googletagmanager.com *.groupondata.com;style-src 'self' 'unsafe-inline' *.grouponcdn.com bat.bing.com fonts.googleapis.com *.groupondev.com;img-src 'self' data: *.grouponcdn.com *.groupon.com www.google.com *.doubleclick.net rp.liadm.com www.facebook.com bat.bing.com maps.googleapis.com *.groupondev.com maps.gstatic.com *.criteo.net;font-src 'self' *.grouponcdn.com fonts.gstatic.com *.groupondev.com;object-src data: 'unsafe-eval';report-uri /csp-report
default-src
Scheme
—
https:
default-src
Keyword
—
'unsafe-eval'
default-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'self'
script-src
Host
—
connect-src
Keyword
—
'unsafe-eval'
connect-src
Keyword
—
'unsafe-inline'
connect-src
Keyword
—
'self'
connect-src
Host
—
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
font-src
Keyword
—
'self'
object-src
Scheme
—
data:
object-src
Keyword
—
'unsafe-eval'
report-uri
Host
—