ID da verificação
e56fc5e1-9be5-433a-8f95-216ca035070eConcluído
URL enviado:
https://www.sgs.com/en-us/certified-clients-and-products/certified-client-directory
Relatório concluído:
Público

Cookies · 2 encontrado(s)

Copiar link

Cookies são pequenos arquivos de texto armazenados no dispositivo de um usuário, frequentemente usados para lembrar as preferências do usuário e permitir experiências personalizadas

NomeValorDomínioCaminhoExpira em (UTC)SeguroSomente HTTP
AKA_A2A.sgs.com/SimSim
OptanonConsentisGpcEnabled=0&datestamp=Sun+Apr+27+2025+10%3A24%3A46+GMT%2B0000+(Coordinated+Universal+Time)&version=202503.2.0&browserGpcFlag=0&isIABGlobal=false&consentId=10f990d3-cd5d-4bd8-a90a-b6eac14e1d58&interactionCount=0&isAnonUser=1&landingPath=https%3A%2F%2Fwww.sgs.com%2Fen-us%2Fcertified-clients-and-products%2Fcertified-client-directory&groups=C0003%3A0%2CC0001%3A1%2CC0004%3A0%2CC0002%3A0&hosts=H3%3A1%2CH37%3A1%2CH18%3A0%2CH4%3A0%2CH22%3A0%2CH7%3A0%2CH11%3A0&genVendors=.www.sgs.com/NãoNão

Variáveis JavaScript · 70 encontrada(s)

Copiar link

Variáveis JavaScript globais carregadas no objeto janela de uma página são variáveis declaradas fora das funções e acessíveis de qualquer lugar no código dentro do escopo atual

NomeTipo
0object
1object
2object
3object
4object
onbeforetoggleobject
documentPictureInPictureobject
onpageswapobject
onpagerevealobject
onscrollendobject

Mensagens de registro do console · 26 encontrada(s)

Copiar link

Mensagens registradas no console web

NívelOrigemMensagem
errorsecurity
URL
https://www.sgs.com/en-us/certified-clients-and-products/certified-client-directory
Texto
Refused to load the font 'https://static.cloud.coveo.com/searchui/v2.10116/0/fonts/lato.woff2' because it violates the following Content Security Policy directive: "font-src 'self' data: *.googleapis.com *.gstatic.com *.hotjar.com *.hotjar.io *.smooch.io jobpal-sm.s3.amazonaws.com res.leadoo.com".
errorsecurity
URL
https://www.sgs.com/en-us/certified-clients-and-products/certified-client-directory
Texto
Refused to load the font 'https://staticdev.cloud.coveo.com/searchui/v2.10116/0/fonts/lato.woff2' because it violates the following Content Security Policy directive: "font-src 'self' data: *.googleapis.com *.gstatic.com *.hotjar.com *.hotjar.io *.smooch.io jobpal-sm.s3.amazonaws.com res.leadoo.com".
errorsecurity
URL
https://www.sgs.com/en-us/certified-clients-and-products/certified-client-directory
Texto
Refused to load the font 'https://static.cloud.coveo.com/searchui/v2.10116/0/fonts/lato.woff' because it violates the following Content Security Policy directive: "font-src 'self' data: *.googleapis.com *.gstatic.com *.hotjar.com *.hotjar.io *.smooch.io jobpal-sm.s3.amazonaws.com res.leadoo.com".
errorsecurity
URL
https://www.sgs.com/en-us/certified-clients-and-products/certified-client-directory
Texto
Refused to load the font 'https://staticdev.cloud.coveo.com/searchui/v2.10116/0/fonts/lato.woff' because it violates the following Content Security Policy directive: "font-src 'self' data: *.googleapis.com *.gstatic.com *.hotjar.com *.hotjar.io *.smooch.io jobpal-sm.s3.amazonaws.com res.leadoo.com".
errorsecurity
URL
https://www.googletagmanager.com/
Texto
Refused to frame 'https://www.googletagmanager.com/' because it violates the following Content Security Policy directive: "frame-src 'self' tools.eurolandir.com *.google.com youtu.be *.sgs.com *.youtube.com *.youtube-nocookie.com *.hotjar.com *.sgs.com *.sgs.pl *.sgsgroup.com.cn *.hotjar.com *.hotjar.io *.smooch.io *.doubleclick.net *.linkedin.com *.facebook.com connect.facebook.net *.leadoo.com https://www.recaptcha.net *.doubleclick.net https://*.acast.com *.spotify.com https://view.genial.ly *.baidu.com https://challenges.cloudflare.com *.flippingbook.com *.sgsonline.com.cn *.genially.com".
warningother
URL
https://www.googletagmanager.com/gtm.js?id=GTM-MMR923M
Texto
Failed to execute 'postMessage' on 'DOMWindow': The target origin provided ('https://www.googletagmanager.com') does not match the recipient window's origin ('null').
warningother
URL
https://www.googletagmanager.com/gtm.js?id=GTM-MMR923M
Texto
Failed to execute 'postMessage' on 'DOMWindow': The target origin provided ('https://www.googletagmanager.com') does not match the recipient window's origin ('null').
warningother
URL
https://www.googletagmanager.com/gtm.js?id=GTM-MMR923M
Texto
Failed to execute 'postMessage' on 'DOMWindow': The target origin provided ('https://www.googletagmanager.com') does not match the recipient window's origin ('null').
warningother
URL
https://www.googletagmanager.com/gtm.js?id=GTM-MMR923M
Texto
Failed to execute 'postMessage' on 'DOMWindow': The target origin provided ('https://www.googletagmanager.com') does not match the recipient window's origin ('null').
warningother
URL
https://www.googletagmanager.com/gtm.js?id=GTM-MMR923M
Texto
Failed to execute 'postMessage' on 'DOMWindow': The target origin provided ('https://www.googletagmanager.com') does not match the recipient window's origin ('null').

Cabeçalhos de segurança · 6 encontrado(s)

Copiar link

Cabeçalhos de resposta HTTP que podem aumentar a segurança de um aplicativo web

Saiba mais...
NomeValorSuporteInfo
Strict-Transport-Securitymax-age=86400BomDeclarar que um site só pode ser acessado por meio de uma conexão segura (HTTPS).

Clique para saber mais...
X-Frame-OptionsSAMEORIGINBomIndicar se um navegador deve ter permissão para renderizar uma página em <frame>, <iframe>, <embed> ou <object>.

Clique para saber mais...
X-Content-Type-OptionsnosniffBomIndicar que os tipos MIME anunciados nos cabeçalhos Content-Type devem ser seguidos e não alterados.

Clique para saber mais...
Content-Security-Policydefault-src 'self' 'unsafe-inline' *.coveo.com *.google-analytics.com *.google.com *.googletagmanager.com *.imgix.net *.leadoo.com *.sgs.com *.sgsgroup.com.cn cdn.cookielaw.org cdn.jsdelivr.net f7132108c1tst-store.occa.ocs.oraclecloud.com1 fonts.googleapis.com jobpal-sm.s3.amazonaws.com pagead2.googlesyndication.com; font-src 'self' data: *.googleapis.com *.gstatic.com *.hotjar.com *.hotjar.io *.smooch.io jobpal-sm.s3.amazonaws.com res.leadoo.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' *.baidu.com *.beyondwords.io *.cloudfront.net *.cookielaw.org *.coveo.com *.doubleclick.net *.eloqua.com *.en25.com *.facebook.com *.google-analytics.com *.google.com *.googleadservices.com *.googleanalytics.com *.googleoptimize.com *.googletagmanager.com *.gstatic.com *.hotjar.com *.hotjar.io *.leadoo.com *.mapbox.com *.sgsmall.com.cn *.sgsonline.com.cn *.smooch.io *.storerocket.io *.youtube.com cdn.jsdelivr.net https://challenges.cloudflare.com https://connect.facebook.net https://content.linkedin.com https://maps.googleapis.com https://platform.linkedin.com https://snap.licdn.com https://static-exp1.licdn.com https://storemapper-herokuapp-com.global.ssl.fastly.net https://unpkg.com https://www.recaptcha.net https://www.storemapper.co jobpal-sm.s3.amazonaws.com pagead2.googlesyndication.com s.go-mpulse.net; style-src 'self' 'unsafe-inline' *.google.com https://fonts.googleapis.com jobpal-sm.s3.amazonaws.com *.leadoo.com *.sgs-next.com *.coveo.com https://maps.googleapis.com *.cloudfront.net; frame-src 'self' tools.eurolandir.com *.google.com youtu.be *.sgs.com *.youtube.com *.youtube-nocookie.com *.hotjar.com *.sgs.com *.sgs.pl *.sgsgroup.com.cn *.hotjar.com *.hotjar.io *.smooch.io *.doubleclick.net *.linkedin.com *.facebook.com connect.facebook.net *.leadoo.com https://www.recaptcha.net *.doubleclick.net https://*.acast.com *.spotify.com https://view.genial.ly *.baidu.com https://challenges.cloudflare.com *.flippingbook.com *.sgsonline.com.cn *.genially.com; child-src 'self' *.youtube-nocookie.com *.youtube.com v.qq.com *.google.com *.sgs.com *.facebook.com connect.facebook.net; frame-ancestors 'self' *.googletagmanager.com *.sgs.com *.sgs.pl *.flippingbook.com; connect-src 'self' *.sgsgroup.com.cn *.sgs.com *.sgs-next.com f7132108c1tst-store.occa.ocs.oraclecloud.com cdn.cookielaw.org *.leadoo.com anl.leadoo.com pagead2.googlesyndication.com *.google-analytics.com *.google.com *.doubleclick.net privacyportal-de.onetrust.com *.go-mpulse.net jobpal-sm.s3.amazonaws.com *.hotjar.com *.hotjar.io wss://ws.hotjar.com *.smooch.io *.googletagmanager.com *.linkedin.com *.licdn.com *.facebook.com connect.facebook.net *.akstat.io https://cdn.linkedin.oribi.io https://geolocation.onetrust.com *.coveo.com https://*.beyondwords.io https://maps.googleapis.com *.cloudfront.net *.flippingbook.com *.sgsonline.com.cn storerocket.io *.mapbox.com; img-src 'self' data: *.sgsgroup.com.cn *.sgs.com *.sgs-next.com *.imgix.net *.leadoo.com *.eloqua.com i.ytimg.com cdn.cookielaw.org *.cdninstagram.com *.hotjar.com *.hotjar.io *.doubleclick.net *.smooch.io *.gstatic.com *.linkedin.com *.licdn.com p.adsymptotic.com *.facebook.com *.facebook.net *.fbcdn.net *.google.com *.googlesyndication.com *.googletagmanager.com *.google-analytics.com *.baidu.com *.cpsc.gov *.productsafety.gov.au ec.europa.eu https://maps.googleapis.com *.cloudfront.net *.sgsonline.com.cn *.google.ca *.google.de *.google.pl *.google.co.in *.google.es *.google.nl *.google.be *.google.com.hk *.google.com.au *.google.com.br *.google.co.za *.google.ae *.google.com.co *.google.com.pe *.google.com.sg *.google.ch *.google.com.tr *.google.co.id *.google.pt *.google.hu *.google.ro *.google.co.uk *.google.co.th *.google.fr *.google.com.tw *.google.com.my *.google.com.mx *.google.co.nz *.storerocket.io; worker-src 'self' https: blob:; media-src 'self' blob: media.licdn.com *.cloudfront.net; form-action 'self' *.facebook.com connect.facebook.net; BomControlar os recursos que o agente do usuário pode carregar para uma determinada página.

Clique para saber mais...
Referrer-Policystrict-origin-when-cross-originBomControlar a quantidade de informações de referência que devem ser incluídas nas solicitações.

Clique para saber mais...
Clear-Site-DataBomControlar os dados armazenados por um navegador cliente quanto às suas origens.

Clique para saber mais...
X-Permitted-Cross-Domain-PoliciesBomControlar se um cliente web, como Adobe Flash Player ou Adobe Acrobat, tem permissão para controlar dados entre domínios.

Clique para saber mais...
Permissions-PolicyRecentePermitir e negar o uso de recursos do navegador em um documento ou iframe.

Clique para saber mais...
Cross-Origin-Embedder-PolicyRecenteConfigurar a incorporação de recursos de origem cruzada no documento.

Clique para saber mais...
Cross-Origin-Opener-PolicyRecenteGarantir que um documento de nível superior não compartilhe um grupo de contexto de navegação com documentos de origem cruzada.

Clique para saber mais...
Cross-Origin-Resource-PolicyRecenteSolicitar que o navegador bloqueie solicitações de origem cruzada/entre sites no-cors para o recurso fornecido.

Clique para saber mais...
X-XSS-Protection1; mode=blockDescontinuadoDescontinuado Impede o carregamento de páginas quando detectam ataques refletidos de cross-site scripting (XSS).

Clique para saber mais...
Feature-PolicyDescontinuadoDescontinuado Substituído pelo cabeçalho Permissions-Policy.

Clique para saber mais...
Expect-CTDescontinuadoDescontinuado Optar por relatar e/ou aplicar requisitos de transparência de certificados.

Clique para saber mais...
Public-Key-PinsDescontinuadoDescontinuado Permitir que sites HTTPS resistam à falsificação de invasores usando certificados emitidos incorretamente ou fraudulentos.

Clique para saber mais...

Desempenho do tempo de navegação

Copiar link

A interface PerformanceNavigationTiming fornece métricas relacionadas aos eventos de navegação de documentos do navegador

Saiba mais...

Processar evento não carregado

EventoTempo (ms)
unloadEventStart0
unloadEventEnd0

Redirecionar

EventoTempo (ms)
redirectStart0
redirectEnd0

Inicialização do Service Worker

EventoTempo (ms)
workerStart0

Evento de busca do Service Worker

EventoTempo (ms)
fetchStart0

DNS

EventoTempo (ms)
domainLookupStart0
domainLookupEnd0

TCP

EventoTempo (ms)
connectStart56
secureConnectionStart65
connectEnd151

Solicitação

EventoTempo (ms)
requestStart151

Resposta

EventoTempo (ms)
responseStart343
responseEnd385

Processamento

EventoTempo (ms)
domInteractive594
domContentLoadedEventStart1098
domContentLoadedEventEnd1099
domComplete5135

Carregar

EventoTempo (ms)
loadEventStart5139
loadEventEnd5140