Open
Cached
·
just now
4
directives
Content-Security-Policy
Content-Security-Policy: script-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.facebook.net *.gstatic.com *.usemessages.com *.linkedin.com *.hotjar.com *.licdn.com *.hsappstatic.net *.facebook.com *.google-analytics.com *.analytics.google.com *.google.com *.googleoptimize.com *.googletagmanager.com *.wistia.net *.hsforms.net yoast.com wisesystemsorg.my.salesforce.com *.doubleclick.net *.apollo.io; frame-ancestors wisesystemsorg--build.sandbox.my.site.com wisesystemsorg.my.site.com partners.wisesystems.com wisesystemsorg.my.salesforce.com wisesystems.com; script-src-elem 'self' 'unsafe-inline' blob: data: *.facebook.net *.gstatic.com *.usemessages.com *.linkedin.com *.hotjar.com *.licdn.com *.facebook.com *.google-analytics.com *.analytics.google.com *.google.com *.googleoptimize.com *.googletagmanager.com *.wistia.net yoast.com wisesystemsorg.my.salesforce.com *.doubleclick.net *.apollo.io; form-action 'self' https://webto.salesforce.com;
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Scheme
—
data:
script-src
Scheme
—
blob:
script-src-elem
Keyword
—
'self'
script-src-elem
Keyword
—
'unsafe-inline'
script-src-elem
Scheme
—
blob:
script-src-elem
Scheme
—
data:
form-action
Keyword
—
'self'
Content-Security-Policy-Report-Only
No report-only CSP headers found.