Open
Cached
·
just now
15
directives
Content-Security-Policy
No enforced CSP headers found.
Content-Security-Policy-Report-Only
Content-Security-Policy-Report-Only: base-uri 'self'; connect-src 'self' https://*.clarity.ms/collect https://*.google-analytics.com/g/collect https://*.launchdarkly.com https://ad.doubleclick.net https://amplify.outbrain.com https://analytics.google.com https://analytics.tiktok.com https://api.segment.io https://aplo-evnt.com https://bat.bing.com https://bat.bing.net https://browser-intake-datadoghq.eu https://cdn.segment.com https://content.hotjar.io https://conversions-config.reddit.com https://cookie-cdn.cookiepro.com https://geolocation.onetrust.com https://graphql.contentful.com https://id.sage.com https://ingress.eu2.rum-ingress-coralogix.com/browser/v1beta/logs https://maps.googleapis.com https://pagead2.googlesyndication.com https://pagesense-collect.zoho.in https://pixel-config.reddit.com https://pixel.quantserve.com https://pixels.spotify.com https://postcodes.io https://privacyportal.cookiepro.com https://px.ads.linkedin.com https://rum-http-intake.logs.datadoghq.eu https://stats.g.doubleclick.net https://tide.api.kustomerapp.com https://tr.outbrain.com https://widget.trustpilot.com https://www.cloudflare.com https://www.facebook.com https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.redditstatic.com https://z.clarity.ms; default-src 'none'; font-src 'self' https://cdn.kustomerapp.com https://fonts.gstatic.com https://web-assets.tide.co; frame-ancestors 'self' https://uniclient-demo.web.app; frame-src 'self' https://14663405.fls.doubleclick.net https://forms.zohopublic.in https://widget.trustpilot.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' https://ade.googlesyndication.com https://bat.bing.net https://c.clarity.ms https://cdn.prod2.kustomerhostedcontent.com https://downloads.ctfassets.net https://heapanalytics.com https://images.ctfassets.net https://impressions.onelink.me https://px.ads.linkedin.com/collect https://q.quora.com https://web-assets.tide.co https://www.facebook.com https://www.google.co.in https://www.google.com; manifest-src 'self'; media-src 'self' https://videos.ctfassets.net; object-src 'none'; report-to csp-reporting-endpoint; report-uri https://csp-report.browser-intake-datadoghq.eu/api/v2/logs?dd-api-key=pubd4258020965cc5258eee35ac618e9586&dd-evp-origin=content-security-policy&ddsource=csp-report; script-src 'self' 'unsafe-inline' https://a.quora.com https://amplify.outbrain.com https://analytics.tiktok.com/ https://assets.apollo.io/ https://bat.bing.com https://cdn-in.pagesense.io https://cdn.datatables.net https://cdn.heapanalytics.com https://cdn.jsdelivr.net https://cdn.kustomerapp.com https://cdn.rum-ingress-coralogix.com https://cdn.segment.com/ https://cdnjs.cloudflare.com/ajax/libs/ https://code.jquery.com https://connect.facebook.net/ https://cookie-cdn.cookiepro.com/ https://d34r8q7sht0t9k.cloudfront.net https://d38xvr37kwwhcm.cloudfront.net https://geotargetly-api-2.com https://googleads.g.doubleclick.net https://googleusercontent.com https://js.stripe.com https://kit.fontawesome.com https://payments.tide.co https://pixel.byspotify.com/ https://rules.quantcount.com https://script.hotjar.com https://scripts.clarity.ms https://scripts.clarity.ms/ https://secure.quantserve.com https://snap.licdn.com https://stackpath.bootstrapcdn.com https://static.ads-twitter.com https://static.hotjar.com https://tr.outbrain.com https://wave.outbrain.com https://web-assets.tide.co/ https://widget.trustpilot.com/ https://www.clarity.ms https://www.datadoghq-browser-agent.com https://www.google-analytics.com https://www.googletagmanager.com/ https://www.gstatic.com https://www.redditstatic.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com/ajax/libs https://fonts.googleapis.com/css https://stackpath.bootstrapcdn.com https://use.typekit.net; worker-src 'self'
base-uri
Keyword
—
'self'
connect-src
Keyword
—
'self'
default-src
Keyword
—
'none'
font-src
Keyword
—
'self'
frame-ancestors
Keyword
—
'self'
frame-src
Keyword
—
'self'
img-src
Keyword
—
'self'
manifest-src
Keyword
—
'self'
media-src
Keyword
—
'self'
object-src
Keyword
—
'none'
report-to
Host
—
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
worker-src
Keyword
—
'self'