- Scan ID:
- e835cb76-a2c7-4a4a-89cd-4391fbb3ec6aFinished
- Submitted URL:
- https://trk.cmpgnr.com/click/grek-2vk63c-kad8a9-l4z9unt8/Redirected
- Report Finished:
Risks · 0 found
Practices that may pose security risks
Security Headers · 3 found
HTTP response headers that can harden the security of a web application
Learn more...Name | Value | Support | Info |
---|---|---|---|
Strict-Transport-Security | max-age=63072000; includeSubDomains; preload | Good | Declare that a website is only accessible over a secure connection (HTTPS). Click to learn more... |
X-Frame-Options | — | Good | Indicate whether a browser should be allowed to render a page in a <frame>, <iframe>, <embed> or <object>. Click to learn more... |
X-Content-Type-Options | nosniff | Good | Indicate that the MIME types advertised in the Content-Type headers should be followed and not be changed. Click to learn more... |
Content-Security-Policy | default-src 'self' *.stripe.com dev.visualwebsiteoptimizer.com *.wistia.com *.pusher.com wss://*.pusher.com wss://*.drift.com *.segment.com *.segment.io *.litix.io *.1drv.ms *.google.com www.google-analytics.com www.googletagmanager.com *.dropbox.com *.amazonaws.com rpm.newrelic.com app.pendo.io data.pendo.io pendo-static-6272184944689152.storage.googleapis.com formstack.com *.formstack.com blob: formstack.com static.formstack.com static.cdn-formstack.com platform-assets.cdn-formstack.com s3.amazonaws.com/files.formstack.com s3.amazonaws.com/files.formstack.com/admin s3.amazonaws.com/files.formstack.com/public s3.amazonaws.com/files.formstack.com files.formstack.com.amazonaws.com s3.amazonaws.com/files-private.formstack.com files-private.formstack.com.amazonaws.com s3.amazonaws.com/us-east-1-prod-forms-submission-uploads us-east-1-prod-forms-submission-uploads.amazonaws.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com pendo-static-6272184944689152.storage.googleapis.com formstack.com *.formstack.com blob: formstack.com static.formstack.com static.cdn-formstack.com platform-assets.cdn-formstack.com s3.amazonaws.com/files.formstack.com s3.amazonaws.com/files.formstack.com/admin s3.amazonaws.com/files.formstack.com/public s3.amazonaws.com/files.formstack.com files.formstack.com.amazonaws.com s3.amazonaws.com/files-private.formstack.com files-private.formstack.com.amazonaws.com s3.amazonaws.com/us-east-1-prod-forms-submission-uploads us-east-1-prod-forms-submission-uploads.amazonaws.com; script-src 'self' 'unsafe-eval' dev.visualwebsiteoptimizer.com js.driftt.com js.stripe.com ajax.googleapis.com *.google.com www.googletagmanager.com www.google-analytics.com *.hotjar.com browser-intake-datadoghq.com code.jquery.com fast.wistia.com *.litix.io *.akamaihd.net *.truendo.com *.pusher.com *.segment.com js.sentry-cdn.com app.pendo.io cdn.pendo.io data.pendo.io pendo-static-6272184944689152.storage.googleapis.com formstack.com *.formstack.com blob: formstack.com static.formstack.com static.cdn-formstack.com platform-assets.cdn-formstack.com s3.amazonaws.com/files.formstack.com s3.amazonaws.com/files.formstack.com/admin s3.amazonaws.com/files.formstack.com/public s3.amazonaws.com/files.formstack.com files.formstack.com.amazonaws.com s3.amazonaws.com/files-private.formstack.com files-private.formstack.com.amazonaws.com s3.amazonaws.com/us-east-1-prod-forms-submission-uploads us-east-1-prod-forms-submission-uploads.amazonaws.com 'nonce-4cfd679a4a88a77751b9906be921b32abc27e0b618cb5d60805038300b62cf20'; script-src-attr 'self'; img-src 'self' *.amazonaws.com *.visualwebsiteoptimizer.com www.gravatar.com data: w3.org/2000/svg fast.wistia.com embed-ssl.wistia.com 1drv.ms *.1drv.ms *.google.com *.hexagon-analytics.com hexagon-analytics.com *.dropbox.com *.box.com www.googletagmanager.com app.pendo.io cdn.pendo.io data.pendo.io pendo-static-6272184944689152.storage.googleapis.com formstack.com *.formstack.com blob: formstack.com static.formstack.com static.cdn-formstack.com platform-assets.cdn-formstack.com s3.amazonaws.com/files.formstack.com s3.amazonaws.com/files.formstack.com/admin s3.amazonaws.com/files.formstack.com/public s3.amazonaws.com/files.formstack.com files.formstack.com.amazonaws.com s3.amazonaws.com/files-private.formstack.com files-private.formstack.com.amazonaws.com s3.amazonaws.com/us-east-1-prod-forms-submission-uploads us-east-1-prod-forms-submission-uploads.amazonaws.com; font-src 'self' *.cdn-formstack.com fonts.gstatic.com fast.wistia.com data: application/x-font-woff formstack.com *.formstack.com blob: formstack.com static.formstack.com static.cdn-formstack.com platform-assets.cdn-formstack.com s3.amazonaws.com/files.formstack.com s3.amazonaws.com/files.formstack.com/admin s3.amazonaws.com/files.formstack.com/public s3.amazonaws.com/files.formstack.com files.formstack.com.amazonaws.com s3.amazonaws.com/files-private.formstack.com files-private.formstack.com.amazonaws.com s3.amazonaws.com/us-east-1-prod-forms-submission-uploads us-east-1-prod-forms-submission-uploads.amazonaws.com; frame-src 'self' js.stripe.com js.driftt.com rpm.newrelic.com www.google.com app.pendo.io formstack.com *.formstack.com blob: formstack.com static.formstack.com static.cdn-formstack.com platform-assets.cdn-formstack.com s3.amazonaws.com/files.formstack.com s3.amazonaws.com/files.formstack.com/admin s3.amazonaws.com/files.formstack.com/public s3.amazonaws.com/files.formstack.com files.formstack.com.amazonaws.com s3.amazonaws.com/files-private.formstack.com files-private.formstack.com.amazonaws.com s3.amazonaws.com/us-east-1-prod-forms-submission-uploads us-east-1-prod-forms-submission-uploads.amazonaws.com | Good | Control resources the user agent is allowed to load for a given page. Click to learn more... |
Referrer-Policy | — | Good | Control how much referrer information should be included with requests. Click to learn more... |
Clear-Site-Data | — | Good | Control the data stored by a client browser for their origins. Click to learn more... |
X-Permitted-Cross-Domain-Policies | — | Good | Control whether a web client such as Adobe Flash Player or Adobe Acrobat has permission to handle data across domains. Click to learn more... |
Permissions-Policy | — | New | Allow and deny the use of browser features in a document or iframe. Click to learn more... |
Cross-Origin-Embedder-Policy | — | New | Configure embedding cross-origin resources into the document. Click to learn more... |
Cross-Origin-Opener-Policy | — | New | Ensure a top-level document does not share a browsing context group with cross-origin documents. Click to learn more... |
Cross-Origin-Resource-Policy | — | New | Request that the browser blocks no-cors cross-origin/cross-site requests to the given resource. Click to learn more... |
X-XSS-Protection | — | Deprecated | Deprecated. Stops pages from loading when they detect reflected cross-site scripting (XSS) attacks. Click to learn more... |
Feature-Policy | — | Deprecated | Deprecated. Replaced by the Permissions-Policy header. Click to learn more... |
Expect-CT | — | Deprecated | Deprecated. Opt in to reporting and/or enforcement of Certificate Transparency requirements. Click to learn more... |
Public-Key-Pins | — | Deprecated | Deprecated. Allows HTTPS websites to resist impersonation by attackers using mis-issued or otherwise fraudulent certificates. Click to learn more... |
Security Violations · 0 found
Requests or resources offending security policies
Certificates · 3 found
SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification
Subject | Issue date | Expiry date |
---|---|---|
*.formstack.com | Feb 18, 2024, 00:00:00 | Mar 18, 2025, 23:59:59 |
upload.video.google.com | Oct 21, 2024, 08:38:00 | Jan 13, 2025, 08:37:59 |
*.gstatic.com | Oct 21, 2024, 08:37:59 | Jan 13, 2025, 08:37:58 |