- ID scansione:
- e0812ab5-865e-4772-aa33-439b8b565000Fatto
- URL inviato:
- https://www.lusha.com/privacy_topic/control-your-profile/
- Report terminato:
Rischi · 0 trovati
Pratiche che possono comportare rischi per la sicurezza
Intestazioni di sicurezza · 7 trovate
Intestazioni di risposta HTTP che possono rafforzare la sicurezza di un'applicazione Web
Ulteriori informazioni...Nome | Valore | Supporto | Info |
---|---|---|---|
Strict-Transport-Security | max-age=31536000; includeSubDomains | Buono | Dichiara che un sito Web è accessibile solo tramite una connessione sicura (HTTPS). Fai clic per saperne di più... |
X-Frame-Options | SAMEORIGIN | Buono | Indica se a un browser deve essere consentito di eseguire il rendering di una pagina in un <frame>, <iframe>, <embed> o <object>. Fai clic per saperne di più... |
X-Content-Type-Options | nosniff | Buono | Indica che i tipi MIME pubblicizzati nelle intestazioni Content-Type devono essere seguiti e non modificati. Fai clic per saperne di più... |
Content-Security-Policy | default-src 'self' *.google.com *.lusha.com https://www.g2.com https://gist.github.com localhost https://*.clarity.ms https://c.bing.com 'unsafe-inline'; img-src 'self' data: https://forms.hsforms.com/ https://forms-na1.hsforms.com/ https://js.chilipiper.com/images/ https://www.g2.com https://www.google.co.uk https://*.googlesyndication.com https://*.ads.linkedin.com https://analytics.twitter.com https://*.intercomcdn.com https://ci5.googleusercontent.com https://cdn.cookielaw.org https://sync-t1.taboola.com https://googleads.g.doubleclick.net/ https://*.privacysandbox.googleadservices.com https://ct.capterra.com/ https://cdn.cookielaw.org/logos https://trc.taboola.com https://cds.taboola.com https://google.com/pagead/ https://i.ytimg.com https://alb.reddit.com/ https://www.google.com/pagead/ https://mk0lplushacrhatidvnw.kinstacdn.com/ https://www.google.com/ads/ga-audiences https://t.co/i/ https://c.bing.com/c.gif https://c.clarity.ms/c.gif https://cx.atdmt.com https://q.quora.com connect.facebook.net www.googletagmanager.com https://s.w.org/images/core/emoji/13.0.0/svg/ https://www.w3.org https://www-services.lusha.com www.linkedin.com embedwistia-a.akamaihd.net https://js.intercomcdn.com https://static.intercomassets.com https://downloads.intercomcdn.com https://uploads.intercomusercontent.com https://gifs.intercomcdn.com https://messenger-apps.intercom.io *.intercom-attachments.com forms.hubspot.com p.adsymptotic.com www.yesware.com www.outreach.io *.lusha.com ek1m512i34ve2rek3k8v02in-wpengine.netdna-ssl.com salesloft.com www.google.com www.google-analytics.com www.google.co.il *.gstatic.com bat.bing.com www.facebook.com track.hubspot.com stats.g.doubleclick.net *.google-analytics.com *.analytics.google.com https://11988414.fls.doubleclick.net https://ad.doubleclick.net https://ade.googlesyndication.com https://stats.sa-as.com https://privacy-policy.truste.com https://flagcdn.com https://secure.gravatar.com https://track-eu1.hubspot.com https://perf-eu1.hsforms.com https://downloads.intercomcdn.eu https://static.intercomassets.eu https://media.trustradius.com https://d30ia583fbtg8i.cloudfront.net/images; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.intercomcdn.com data: localhost https://www.trustradius.com/trustquotes/trustquotes.js https://pagead2.googlesyndication.com/ https://js.hsleadflows.net https://www.g2.com https://www.google.com/pagead https://cdn.nmgassets.com https://www.googleadservices.com https://trc.taboola.com https://ssl.google-analytics.com/ga.js https://cdn.taboola.com https://analytics.tiktok.com https://cdn.cookielaw.org https://tpc.googlesyndication.com https://www.redditstatic.com/ads/pixel.js https://mk0lplushacrhatidvnw.kinstacdn.com/ https://tags.crwdcntrl.net https://analytics.twitter.com/ https://cdn.jsdelivr.net/npm/@webcomponents/[email protected]/bundles/webcomponents-sd.js https://ssl.kaptcha.com/collect/sdk https://cdn.jsdelivr.net/npm/@webcomponents/[email protected]/bundles/webcomponents-ce.js https://cdnjs.cloudflare.com/ajax/libs/webcomponentsjs/2.4.1/custom-elements-es5-adapter.js https://static.ads-twitter.com/uwt.js https://unpkg.com/react@16/umd/react.production.min.js https://unpkg.com/react-dom@16/umd/react-dom.production.min.js https://www.clarity.ms js.hs-banner.com js.hsadspixel.net *.lusha.com js.intercomcdn.com https://app.intercom.io widget.intercom.io snap.licdn.com www.comeet.co www.comeet.com forms.hsforms.com js.hsforms.net s.ytimg.com www.googletagmanager.com *.google.com www.google-analytics.com *.googleadservices.com *.typekit.net js.stripe.com connect.facebook.net bat.bing.com sjs.bizographics.com survey.survicate.com surveys-static.survicate.com js.hs-scripts.com js.hs-analytics.net js.usemessages.com tracking.g2crowd.com *.gstatic.com px.ads.linkedin.com www.linkedin.com *.fullstory.com fullstory.com dc.ads.linkedin.com *.salesloft.com *.youtube.com https://cdnjs.cloudflare.com/ajax/libs/js-sha256/ https://stats.sa-as.com/live.js https://unpkg.com/aos@next/dist/aos.js https://ipinfo.io https://extreme-ip-lookup.com https://unpkg.com/@lottiefiles/[email protected]/dist/lottie-player.js https://platform.linkedin.com/in.js https://ml314.com/ https://vi.ml314.com/ https://js.chilipiper.com/marketing.js https://cdn.amcharts.com/ https://js-eu1.hs-scripts.com/ https://js-eu1.hubspot.com/ https://js-eu1.hsleadflows.net/ https://js-eu1.hs-banner.com/ https://js-eu1.hs-analytics.net/ https://js-eu1.hsadspixel.net/fb.js https://ajax.googleapis.com/ https://googleads.g.doubleclick.net/ https://video-messages.intercomcdn.com https://messenger-apps.eu.intercom.io https://*.intercom-attachments-1.com https://*.intercom-attachments.eu https://*.intercom-attachments-2.com https://*.intercom-attachments-3.com https://*.intercom-attachments-4.com https://*.intercom-attachments-5.com https://*.intercom-attachments-6.com https://*.intercom-attachments-7.com https://*.intercom-attachments-8.com https://*.intercom-attachments-9.com https://static.intercomassets.eu https://js.partnerstack.com https://d30ia583fbtg8i.cloudfront.net/trustquotes/trustquotes.js https://d30ia583fbtg8i.cloudfront.net/trustquotes/style.css; style-src 'self' 'unsafe-inline' localhost https://www.g2.com https://mk0lplushacrhatidvnw.kinstacdn.com/ https://www.googletagmanager.com *.comeet.co *.comeet.com *.lusha.com *.typekit.net tagmanager.google.com fonts.googleapis.com; font-src 'self' data: localhost https://fonts.intercomcdn.com https://www.g2.com https://mk0lplushacrhatidvnw.kinstacdn.com/ https://www.google.com use.typekit.net *.lusha.com js.intercomcdn.com surveys-static.survicate.com fonts.googleapis.com fonts.gstatic.com dudodiprj2sv7.cloudfront.net; connect-src 'self' data: localhost https://*.clarity.ms https://px.ads.linkedin.com https://px.ads.linkedin.com https://forms.hsforms.com/embed/ https://forms.hubspot.com/ https://hubspot-forms-static-embed.s3.amazonaws.com/prod/ https://www.google.co.il/ads/ https://api.chilipiper.com/ https://tracking.chilipiper.com/ https://www.g2.com https://api.hubapi.com https://analytics.tiktok.com https://googleads.g.doubleclick.net/ https://privacyportal-eu.onetrust.com/request/v1/consentreceipts https://pagead2.googlesyndication.com https://geolocation.onetrust.com *.taboola.com https://*.crwdcntrl.net/ https://*.google.com https://cdn.cookielaw.org *.lottiefiles.com https://o412513.ingest.sentry.io https://www.clarity.ms bat.bing.com https://www-services.lusha.com api.hubapi.com https://api.intercom.io https://api-iam.intercom.io https://api-ping.intercom.io https://nexus-websocket-a.intercom.io https://nexus-websocket-b.intercom.io https://nexus-long-poller-a.intercom.io https://nexus-long-poller-b.intercom.io wss://nexus-websocket-a.intercom.io wss://nexus-websocket-b.intercom.io https://uploads.intercomcdn.com https://uploads.intercomusercontent.com http://www-services-local.lusha.co:3030/v2/user-events http://www-services-local.lusha.com:3030/v2/user-events https://private-144d5-gallusha.apiary-mock.com/questions embedwistia-a.akamaihd.net api.hubspot.com *.lusha.com *.fullstory.com respondent.survicate.com www.google-analytics.com scout.salesloft.com www.facebook.com stats.g.doubleclick.net *.google-analytics.com *.analytics.google.com https://ipinfo.io https://api.ipify.org https://ipecho.net https://myexternalip.com https://cta-eu1.hubspot.com https://perf-eu1.hsforms.com https://api-eu1.hubapi.com https://track-eu1.hubspot.com https://forms-eu1.hubspot.com https://tracking.g2crowd.com https://google.com/pagead https://google.com/ccm https://api-iam.eu.intercom.io https://via.intercom.io https://api.eu.intercom.io https://api-iam.intercom.io https://api-iam.eu.intercom.io https://api-ping.intercom.io https://nexus-europe-websocket.intercom.io wss://nexus-europe-websocket.intercom.io https://uploads.intercomcdn.eu https://uploads.eu.intercomcdn.com https://partnerlinks.io https://grsm.io dudodiprj2sv7.cloudfront.net https://www.trustradius.com/api/v1/events https://lusha.chilipiper.com; child-src localhost https://www.g2.com https://share.intercom.io https://intercom-sheets.com https://www.intercom-reporting.com https://www.youtube.com https://player.vimeo.com https://fast.wistia.net; frame-src localhost https://www.googletagmanager.com https://tpc.googlesyndication.com https://capture.navattic.com https://lusha.chilipiper.com https://www.g2.com https://business.facebook.com https://privacyportal-eu.onetrust.com/ https://*.doubleclick.net https://www.youtube.com/ https://tsdtocl.com/ https://www.linkedin.com www.comeet.com intercom-sheets.com forms.hsforms.com forms.hubspot.com js.stripe.com www.google.com *.lusha.com www.facebook.com *.youtube.com www.comeet.co https://11988414.fls.doubleclick.net; form-action localhost www.facebook.com *.lusha.com https://intercom.help https://api-iam.intercom.io https://forms.hsforms.com/submissions/ https://intercom.help https://api-iam.eu.intercom.io; worker-src blob: *.lusha.com localhost; frame-ancestors 'self' *.lusha.com https://www.lusha-business.com/contact-us; media-src 'self' data: blob: localhost *.lusha.com https://*.intercomcdn.com https://js.intercomcdn.com; object-src 'none'; | Buono | Controlla le risorse che l'agente utente può caricare per una determinata pagina. Fai clic per saperne di più... |
Referrer-Policy | no-referrer-when-downgrade | Buono | Controlla la quantità di informazioni sul referrer che devono essere incluse nelle richieste. Fai clic per saperne di più... |
Clear-Site-Data | — | Buono | Controlla i dati memorizzati da un browser client per le loro origini. Fai clic per saperne di più... |
X-Permitted-Cross-Domain-Policies | — | Buono | Controlla se un client Web come Adobe Flash Player o Adobe Acrobat dispone dell'autorizzazione per gestire i dati tra domini. Fai clic per saperne di più... |
Permissions-Policy | accelerometer=(); camera=(); geolocation=(); gyroscope=(); magnetometer=(); microphone=(); payment=(); usb=() | Nuovo | Consenti e nega l'uso delle funzionalità del browser in un documento o iframe. Fai clic per saperne di più... |
Cross-Origin-Embedder-Policy | — | Nuovo | Configura l'incorporamento di risorse multiorigine nel documento. Fai clic per saperne di più... |
Cross-Origin-Opener-Policy | — | Nuovo | Assicurati che un documento di livello superiore non condivida un gruppo di contesti di navigazione con documenti di più origini. Fai clic per saperne di più... |
Cross-Origin-Resource-Policy | — | Nuovo | Richiedere che il browser blocchi le richieste multiorigine/tra siti no-cor alla risorsa specificata. Fai clic per saperne di più... |
X-XSS-Protection | 1; mode=block | Obsoleto | Obsoleto. Impedisce il caricamento delle pagine quando rilevano attacchi XSS (cross-site scripting) riflessi. Fai clic per saperne di più... |
Feature-Policy | — | Obsoleto | Obsoleto. Sostituito dall'intestazione Permissions-Policy. Fai clic per saperne di più... |
Expect-CT | — | Obsoleto | Obsoleto. Accetta la segnalazione e/o l'applicazione dei requisiti di trasparenza dei certificati. Fai clic per saperne di più... |
Public-Key-Pins | — | Obsoleto | Obsoleto. Consente ai siti Web HTTPS di resistere alla rappresentazione da parte di autori di attacchi che utilizzano certificati emessi erroneamente o altrimenti fraudolenti. Fai clic per saperne di più... |
Violazioni della sicurezza · 0 trovate
Richieste o risorse che violano le politiche di sicurezza
Certificati · 10 trovati
I certificati SSL/TLS consentono ai siti Web di crittografare le transazioni tra il client e il server e fornire la verifica dell'identità del server
Oggetto | Data di emissione | Data di scadenza |
---|---|---|
*.lusha.com | 9 set 2024, 00:00:00 | 9 ott 2025, 23:59:59 |
upload.video.google.com | 21 ott 2024, 08:38:00 | 13 gen 2025, 08:37:59 |
chilipiper.com | 5 feb 2024, 00:00:00 | 7 mar 2025, 23:59:59 |
lusha.com | 29 mar 2024, 00:00:00 | 27 apr 2025, 23:59:59 |
*.google-analytics.com | 21 ott 2024, 08:36:57 | 13 gen 2025, 08:36:56 |
ifconfig.me | 15 nov 2024, 13:09:37 | 13 feb 2025, 13:09:36 |
cookielaw.org | 11 ott 2024, 18:54:25 | 9 gen 2025, 19:54:23 |
geolocation.onetrust.com | 11 ott 2024, 18:40:05 | 9 gen 2025, 19:40:02 |
ipify.org | 13 nov 2024, 05:59:28 | 11 feb 2025, 05:59:27 |
*.g.doubleclick.net | 21 ott 2024, 08:36:57 | 13 gen 2025, 08:36:56 |