Open
Cached
·
just now
4
directives
Content-Security-Policy
No enforced CSP headers found.
Content-Security-Policy-Report-Only
Content-Security-Policy-Report-Only: script-src 'self' 'unsafe-eval' https://js.stripe.com/v3 https://www.googletagmanager.com/ https://www.googleadservices.com https://apis.google.com https://googleads.g.doubleclick.net/ https://js.stripe.com/v3 https://static.cloudflareinsights.com https://connect.facebook.net https://www.youtube.com/iframe_api https://www.youtube.com/s/ https://www.google.com/pagead https://www.gstatic.com/_/mss/boq-identity/ blob:; worker-src 'self' blob:; object-src 'none'; report-uri /api/csp-report?source=kamimain&version=11;
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
script-src
Scheme
—
blob:
worker-src
Keyword
—
'self'
worker-src
Scheme
—
blob:
object-src
Keyword
—
'none'
report-uri
Host
—