Open
Cached
·
just now
11
directives
Content-Security-Policy
Content-Security-Policy: base-uri 'none';object-src 'none';connect-src 'self' https: *.google-analytics.com wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io wss://primary-realtime.intercom-messenger.com blob: https://challenges.cloudflare.com;default-src 'self' blob: https://1874966808.rsc.cdn77.org;font-src 'self' https: data: https://1874966808.rsc.cdn77.org;frame-src 'self' https://accounts.google.com https://www.google.com https://www.facebook.com https://webforms.pipedrive.com https://td.doubleclick.net/ https://intercom-sheets.com/ https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net https://www.loom.com https://challenges.cloudflare.com;img-src 'self' https: blob: data: *.googletagmanager.com a.storyblok.com img2.storyblok.com;media-src 'self' https: blob: data: a.storyblok.com;report-uri https://fe7d76b887471114b1ffc4f4c426faa7.report-uri.com/r/d/csp/enforce;script-src 'unsafe-inline' 'unsafe-eval' https: 'self' https://apis.google.com https://www.googletagmanager.com https://www.clarity.ms http://app.storyblok.com https://widget.intercom.io https://app.intercom.io https://js.intercomcdn.com https://challenges.cloudflare.com https://1874966808.rsc.cdn77.org;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://tagmanager.google.com https://1874966808.rsc.cdn77.org
base-uri
Keyword
—
'none'
object-src
Keyword
—
'none'
connect-src
Keyword
—
'self'
connect-src
Scheme
—
https:
connect-src
Scheme
—
blob:
default-src
Keyword
—
'self'
default-src
Scheme
—
blob:
font-src
Keyword
—
'self'
font-src
Scheme
—
https:
font-src
Scheme
—
data:
frame-src
Keyword
—
'self'
img-src
Keyword
—
'self'
img-src
Scheme
—
https:
img-src
Scheme
—
blob:
img-src
Scheme
—
data:
media-src
Keyword
—
'self'
media-src
Scheme
—
https:
media-src
Scheme
—
blob:
media-src
Scheme
—
data:
script-src
Keyword
—
'unsafe-inline'
script-src
Keyword
—
'unsafe-eval'
script-src
Scheme
—
https:
script-src
Keyword
—
'self'
style-src
Keyword
—
'self'
style-src
Keyword
—
'unsafe-inline'
Content-Security-Policy-Report-Only
No report-only CSP headers found.