Open
Cached
·
just now
12
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self' googleads.g.doubeclick.net play.google.com;script-src 'self' ajax.aspnetcdn.com *.calendly.com www.google.com maps.googleapis.com *.googleapis.com *.gstatic.com *.g2.com *.g2crowd.com recruit.hr-on.com umbracohq.matomo.cloud consent.cookiebot.com consentcdn.cookiebot.com tagmanager.google.com *.googletagmanager.com load.sst.umbraco.com *.load.sst.umbraco.com cdn.matomo.cloud connect.facebook.net *.app-us1.com trackcmp.net *.fluentos.com *.doubleclick.net app.intercom.io widget.intercom.io js.intercomcdn.com blob: 'nonce-zfOw4YzxeLSxCnXLVrtxwxXT7fGWMI4LncedbV0RAT4=';style-src 'self' fonts.googleapis.com *.calendly.com tagmanager.google.com blob: 'unsafe-inline';connect-src 'self' blob: data: maps.gstatic.com maps.googleapis.com mapsresources-pa.googleapis.com *.googletagmanager.com *.analytics.google.com *.google-analytics.com consentcdn.cookiebot.com www.google.com px.ads.linkedin.com sst.umbraco.com umbracohq.matomo.cloud *.doubleclick.net *.navattic.com *.fluentos.com via.intercom.io api.intercom.io api.au.intercom.io api.eu.intercom.io api-iam.intercom.io api-iam.eu.intercom.io api-iam.au.intercom.io api-ping.intercom.io nexus-websocket-a.intercom.io wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io wss://nexus-europe-websocket.intercom.io wss://nexus-australia-websocket.intercom.io nexus-websocket-b.intercom.io nexus-europe-websocket.intercom.io nexus-australia-websocket.intercom.io https://*.intercom-messenger.com wss://*.intercom-messenger.com uploads.intercomcdn.com uploads.intercomcdn.eu uploads.au.intercomcdn.com uploads.eu.intercomcdn.com uploads.intercomusercontent.com;font-src 'self' fonts.gstatic.com fonts.intercomcdn.com js.intercomcdn.com data:;form-action 'self' intercom.help api-iam.intercom.io api-iam.eu.intercom.io api-iam.au.intercom.io;img-src 'self' *.calendly.com data: blob: *.googleapis.com maps.gstatic.com *.ytimg.com imgsct.cookiebot.com *.googletagmanager.com googletagmanager.com ssl.gstatic.com gstatic.com *.google-analytics.com px.ads.linkedin.com www.google.com *.facebook.com facebook.com *.fluentos.com *.doubleclick.net load.sst.umbraco.com *.load.sst.umbraco.com js.intercomcdn.com static.intercomassets.com downloads.intercomcdn.com downloads.intercomcdn.eu downloads.au.intercomcdn.com uploads.intercomusercontent.com gifs.intercomcdn.com video-messages.intercomcdn.com messenger-apps.intercom.io messenger-apps.eu.intercom.io messenger-apps.au.intercom.io *.intercom-attachments-1.com *.intercom-attachments.eu *.au.intercom-attachments.com *.intercom-attachments-2.com *.intercom-attachments-3.com *.intercom-attachments-4.com *.intercom-attachments-5.com *.intercom-attachments-6.com *.intercom-attachments-7.com *.intercom-attachments-8.com *.intercom-attachments-9.com static.intercomassets.eu static.au.intercomassets.com;media-src 'self' youtube.com *.youtube.com vimeo.com *.vimeo.com js.intercomcdn.com downloads.intercomcdn.com downloads.intercomcdn.eu downloads.au.intercomcdn.com;frame-ancestors 'self';frame-src calendly.com www.g2.com www.google.com youtube.com www.youtube.com recruit.hr-on.com consentcdn.cookiebot.com *.googletagmanager.com intercom-sheets.com www.intercom-reporting.com player.vimeo.com fast.wistia.net capture.navattic.com;worker-src *.g2.com blob:;base-uri 'self'
default-src
Keyword
—
'self'
script-src
Keyword
—
'self'
script-src
Host
—
script-src
Scheme
—
blob:
script-src
Nonce
—
'nonce-zfOw4YzxeLSxCnXLVrtxwxXT7fGWMI4LncedbV0RAT4='
style-src
Keyword
—
'self'
style-src
Scheme
—
blob:
style-src
Keyword
—
'unsafe-inline'
connect-src
Keyword
—
'self'
connect-src
Scheme
—
blob:
connect-src
Scheme
—
data:
font-src
Keyword
—
'self'
font-src
Scheme
—
data:
form-action
Keyword
—
'self'
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
img-src
Scheme
—
blob:
media-src
Keyword
—
'self'
frame-ancestors
Keyword
—
'self'
worker-src
Scheme
—
blob:
base-uri
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.