Open
Cached
·
just now
16
directives
Content-Security-Policy
No enforced CSP headers found.
Content-Security-Policy-Report-Only
Content-Security-Policy-Report-Only: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: *.hs-analytics.net *.hs-banner.com *.hs-scripts.com *.hsadspixel.net *.hscollectedforms.net *.hsforms.com *.hsforms.net *.hsleadflows.net *.hubspot.com *.hubspot.net *.hubspotfeedback.com *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net *.usemessages.com *.hotjar.com https://js.hubspot.com *.hs-sites.com https://*.clearbit.com https://*.clearbitjs.com https://*.clearbitscripts.com https://*.g.doubleclick.net https://app.revenuehero.io https://community.traefik.io https://feedback-eu1.hubapi.com https://feedback.hubapi.com https://js-eu1.hscta.net https://js.hscta.net https://px.ads.linkedin.com https://r2.leadsy.ai https://s3-us-west-2.amazonaws.com https://9xgnrndqve.execute-api.us-west-2.amazonaws.com https://snap.licdn.com https://static.ads-twitter.com https://static.hsappstatic.net https://traefik.github.io https://traefik.io https://www.google-analytics.com https://www.google.com https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://x.clearbitjs.com https://b-code.liadm.com https://cdn.jsdelivr.net https://connect.facebook.net https://platform.twitter.com; style-src 'self' 'unsafe-inline' *.hubspotusercontent00.net *.hubspotusercontent10.net *.hubspotusercontent20.net *.hubspotusercontent30.net *.hubspotusercontent40.net https://7052064.fs1.hubspotusercontent-na1.net https://cdn2.hubspot.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://traefik.io https://www.gstatic.com https://cdn.jsdelivr.net; object-src 'none'; base-uri 'self'; child-src 'self' https://*.hsforms.com; connect-src 'self' *.liadm.com *.hs-sites.com *.hs-banner.com *.hscollectedforms.net *.hsforms.com *.hubapi.com *.hubspot.com https://*.google.com https://www.google.co.in https://www.google.ca https://www.google.co.jp https://www.google.co.kr https://www.google.co.uk https://www.google.co.id https://www.google.co.za https://www.google.co.tz https://www.google.co.ma https://www.google.nl https://www.google.de https://www.google.at https://www.google.es https://www.google.se https://www.google.az https://www.google.so https://www.google.lk https://www.google.com.br https://www.google.com.au https://www.google.com.sg https://www.google.com.hk https://www.google.com.co https://www.google.com.pe https://www.google.com.uy https://www.google.com.eg https://www.google.ae https://www.google.al https://www.google.ba https://www.google.be https://www.google.by https://www.google.ch https://www.google.cl https://www.google.co.cr https://www.google.co.il https://www.google.co.nz https://www.google.co.th https://www.google.co.uz https://www.google.co.ve https://www.google.com.ar https://www.google.com.bd https://www.google.com.do https://www.google.com.gh https://www.google.com.mx https://www.google.com.ng https://www.google.com.np https://www.google.com.ph https://www.google.com.pk https://www.google.com.tr https://www.google.com.tw https://www.google.com.ua https://www.google.com.vn https://www.google.cz https://www.google.dk https://www.google.fr https://www.google.gr https://www.google.hr https://www.google.hu https://www.google.ie https://www.google.iq https://www.google.it https://www.google.kz https://www.google.lt https://www.google.lv https://www.google.no https://www.google.pl https://www.google.pt https://www.google.ro https://www.google.rs https://www.google.ru https://www.google.si https://www.google.sk https://www.google.tn https://hubspot-forms-static-embed.s3.amazonaws.com https://s3-us-west-2.amazonaws.com https://9xgnrndqve.execute-api.us-west-2.amazonaws.com https://www.googleadservices.com https://*.hotjar.com wss://*.hotjar.com https://*.analytics.google.com https://*.hotjar.io https://*.clearbit.com https://*.clearbitjs.com https://*.clearbitscripts.com https://*.g.doubleclick.net https://stats.g.doubleclick.net https://*.google-analytics.com https://*.traefik.io https://api.github.com https://app.clearbit.com https://app.revenuehero.io https://containous.ghost.io https://storage.ghost.io https://google.com https://pagead2.googlesyndication.com https://ingesteer.services-prod.nsvcs.net https://js-eu1.hscta.net https://js.hscta.net https://js.hsforms.net https://pro.ip-api.com https://px.ads.linkedin.com https://www.google.com https://www.googletagmanager.com https://static.scarf.sh https://static.hsappstatic.net https://*.ingest.de.sentry.io https://alocdn.com; font-src 'self' data: https://cdnjs.cloudflare.com https://fonts.gstatic.com https://use.typekit.net https://cdn.jsdelivr.net; frame-src 'self' *.hs-sites-eu1.com *.hs-sites.com *.hsforms.com *.hsforms.net *.hubspot.com *.hubspot.net https://*.g.doubleclick.net https://app.netlify.com https://community.traefik.io https://play-eu1.hubspotvideo.com https://play.hubspotvideo.com https://px.ads.linkedin.com https://traefik.io https://www.google.com https://www.googletagmanager.com https://www.youtube.com; img-src 'self' blob: data: https:; form-action 'self' https://*.hsforms.com; manifest-src 'self' https://traefik.io; media-src 'self' data: https://ssl.gstatic.com; worker-src 'self'; report-uri https://o4511099878637568.ingest.de.sentry.io/api/4511134031937616/security/?sentry_key=64999a84abc3469206792e982d195c43; report-to csp-endpoint
default-src
Keyword
—
'self'
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
script-src
Keyword
—
'unsafe-inline'
script-src
Scheme
—
blob:
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
object-src
Keyword
—
'none'
base-uri
Keyword
—
'self'
child-src
Keyword
—
'self'
connect-src
Keyword
—
'self'
connect-src
Host
—
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
frame-src
Keyword
—
'self'
img-src
Keyword
—
'self'
img-src
Scheme
—
blob:
img-src
Scheme
—
data:
img-src
Scheme
—
https:
form-action
Keyword
—
'self'
manifest-src
Keyword
—
'self'
media-src
Keyword
—
'self'
media-src
Scheme
—
data:
worker-src
Keyword
—
'self'
report-to
Host
—