https://www.giappichelli.it/lo-stato-ecologico-9791221103571

提交的 URL:
https://www.giappichelli.it/lo-stato-ecologico-9791221103571
报告完成时间:

风险 · 找到 0 个

Copy link

可能带来安全风险的做法

  • 无分类

安全标头 · 找到 3 个

Copy link

可以增强 Web 应用程序安全性的 HTTP 响应标头

了解更多...
名称支持信息
Strict-Transport-Security良性声明只能通过安全连接 (HTTPS) 访问网站。

单击可了解更多信息...
X-Frame-OptionsSAMEORIGIN良性表明是否允许浏览器在 <frame>、<iframe>、<embed> 或 <object> 中渲染页面。

单击可了解更多信息...
X-Content-Type-Optionsnosniff良性表明应该遵循 Content-Type 标头中公布的 MIME 类型,并且不得进行更改。

单击可了解更多信息...
Content-Security-Policy良性控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
Referrer-Policy良性控制请求中应该包含多少引荐者信息。

单击可了解更多信息...
Clear-Site-Data良性控制客户端浏览器为来源服务器存储的数据。

单击可了解更多信息...
X-Permitted-Cross-Domain-Policies良性控制 Web 客户端(例如 Adobe Flash Player 或 Adobe Acrobat)是否拥有跨域处理数据的权限。

单击可了解更多信息...
Permissions-Policy允许和拒绝在文档或 iframe 中使用浏览器功能。

单击可了解更多信息...
Cross-Origin-Embedder-Policy配置将跨源资源嵌入到文档中。

单击可了解更多信息...
Cross-Origin-Opener-Policy确保顶级文档不与跨源文档共享浏览背景组。

单击可了解更多信息...
Cross-Origin-Resource-Policy请求浏览器阻止对给定资源的 no-cors 跨源/跨站点请求。

单击可了解更多信息...
X-XSS-Protection1; mode=block停用已弃用。当检测到页面遭受反射式跨站点脚本 (XSS) 攻击时,停止加载页面。

单击可了解更多信息...
Feature-Policy停用已弃用。替换为 Permissions-Policy 标头。

单击可了解更多信息...
Expect-CT停用已弃用。选择加入报告和/或执行证书透明度要求。

单击可了解更多信息...
Public-Key-Pins停用已弃用。允许 HTTPS 网站抵御攻击者使用错误颁发的或其他欺诈性证书进行假冒。

单击可了解更多信息...

安全违规行为 · 找到 19 个

Copy link

违反安全策略的请求或资源

违规类型信息
资源
https://www.giappichelli.it/lo-stato-ecologico-9791221103571
描述
[Report Only] Refused to load the image 'https://giappichelli-usa.com/media/bssstoresflags/stores/2/en_1.png' because it violates the following Content Security Policy directive: "img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.iubenda.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com *.google.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com wss://jquerymanagerus.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
描述
[Report Only] Refused to load the script 'https://connect.facebook.net/en_US/fbevents.js' because it violates the following Content Security Policy directive: "script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.iubenda.com *.disqus.com *.avada.io cdn.jsdelivr.net https://player.vimeo.com https://www.youtube.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtm.js?id=GTM-5LT9583
描述
[Report Only] Refused to load the script 'https://static.hotjar.com/c/hotjar-3542165.js?sv=7' because it violates the following Content Security Policy directive: "script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.iubenda.com *.disqus.com *.avada.io cdn.jsdelivr.net https://player.vimeo.com https://www.youtube.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/
描述
[Report Only] Refused to frame 'https://www.googletagmanager.com/' because it violates the following Content Security Policy directive: "frame-src 'self' fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.iubenda.com https://player.vimeo.com https://www.youtube-nocookie.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/
描述
[Report Only] Refused to frame 'https://www.googletagmanager.com/' because it violates the following Content Security Policy directive: "frame-src 'self' fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.iubenda.com https://player.vimeo.com https://www.youtube-nocookie.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-5HBMHENWBH&l=dataLayer&cx=c&gtm=45He51r0v9121834497za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-5HBMHENWBH&gtm=45je51r0v9132218300z89121834497za200zb9121834497&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102308675&cid=573248678.1738143439&ecid=760587142&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_s=1&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&_fv=1&_nsi=1&_ss=1&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2601' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-5HBMHENWBH&l=dataLayer&cx=c&gtm=45He51r0v9121834497za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-5HBMHENWBH&gtm=45je51r0v9132218300z89121834497za200zb9121834497&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102308675&cid=573248678.1738143439&ecid=760587142&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_s=1&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&_fv=1&_nsi=1&_ss=1&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2601' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-5HBMHENWBH&l=dataLayer&cx=c&gtm=45He51r0v9121834497za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-5HBMHENWBH&gtm=45je51r0v9132218300z89121834497za200zb9121834497&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102308675&cid=573248678.1738143439&ecid=760587142&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_z=1-00~2-00~3-00~4-00~7-00~8-00~9-00~6-00~5-00&ec_mode=a&_s=2&sid=1738143439&sct=1&seg=1&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=page_view&ep.pageType=product&ep.pagePath=%2Flo-stato-ecologico-9791221103571&tfd=2666' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-5HBMHENWBH&l=dataLayer&cx=c&gtm=45He51r0v9121834497za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-5HBMHENWBH&gtm=45je51r0v9132218300z89121834497za200zb9121834497&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102308675&cid=573248678.1738143439&ecid=760587142&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_z=1-00~2-00~3-00~4-00~7-00~8-00~9-00~6-00~5-00&ec_mode=a&_s=2&sid=1738143439&sct=1&seg=1&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=page_view&ep.pageType=product&ep.pagePath=%2Flo-stato-ecologico-9791221103571&tfd=2666' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808z8863639067za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_eu=Ag&_s=1&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&_fv=1&_ss=1&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2779' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808z8863639067za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_eu=Ag&_s=1&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&_fv=1&_ss=1&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2779' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&frm=0&pscdl=denied&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&_eu=AAg&_s=2&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2846' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&frm=0&pscdl=denied&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&_eu=AAg&_s=2&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2846' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808z8863639067za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&ec_mode=a&_s=3&sid=1738143439&sct=1&seg=1&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=page_view&ep.pageType=product&ep.pagePath=%2Flo-stato-ecologico-9791221103571&tfd=2849' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808z8863639067za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&ec_mode=a&_s=3&sid=1738143439&sct=1&seg=1&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=page_view&ep.pageType=product&ep.pagePath=%2Flo-stato-ecologico-9791221103571&tfd=2849' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://connect.facebook.net/en_US/fbevents.js
描述
[Report Only] Refused to load the script 'https://connect.facebook.net/signals/config/545633762292837?v=2.9.180&r=stable&domain=www.giappichelli.it&hme=1b2b48fb279bc2e2881583cc2153b57f55e340ed882b2c5394167c8bc992d930&ex_m=70%2C122%2C107%2C111%2C61%2C4%2C100%2C69%2C16%2C97%2C89%2C51%2C54%2C174%2C177%2C189%2C185%2C186%2C188%2C29%2C101%2C53%2C77%2C187%2C169%2C172%2C182%2C183%2C190%2C132%2C41%2C192%2C193%2C34%2C144%2C15%2C50%2C198%2C197%2C134%2C18%2C40%2C1%2C43%2C65%2C66%2C67%2C71%2C93%2C17%2C14%2C96%2C92%2C91%2C108%2C52%2C110%2C39%2C109%2C30%2C94%2C26%2C170%2C173%2C141%2C86%2C56%2C84%2C33%2C73%2C0%2C95%2C32%2C28%2C82%2C83%2C88%2C47%2C46%2C87%2C37%2C11%2C12%2C13%2C6%2C7%2C25%2C22%2C23%2C57%2C62%2C64%2C75%2C102%2C27%2C76%2C9%2C8%2C80%2C48%2C21%2C104%2C103%2C105%2C98%2C10%2C20%2C3%2C38%2C74%2C19%2C5%2C90%2C81%2C44%2C35%2C85%2C2%2C36%2C63%2C42%2C106%2C45%2C79%2C68%2C112%2C60%2C59%2C31%2C99%2C58%2C55%2C49%2C78%2C72%2C24%2C113' because it violates the following Content Security Policy directive: "script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.iubenda.com *.disqus.com *.avada.io cdn.jsdelivr.net https://player.vimeo.com https://www.youtube.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://static.hotjar.com/c/hotjar-3542165.js?sv=7
描述
[Report Only] Refused to load the script 'https://script.hotjar.com/modules.c2a25c7c94182e6bbdbd.js' because it violates the following Content Security Policy directive: "script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.iubenda.com *.disqus.com *.avada.io cdn.jsdelivr.net https://player.vimeo.com https://www.youtube.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.giappichelli.it/lo-stato-ecologico-9791221103571
描述
[Report Only] Refused to load the image 'https://www.facebook.com/tr/?id=545633762292837&ev=PageView&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&rl=&if=false&ts=1738143439758&sw=1&sh=1&v=2.9.180&r=stable&ec=0&o=12318&fbp=fb.1.1738143439751.634890438962546188&cs_est=true&ler=empty&cdl=API_unavailable&it=1738143439418&coo=false&rqm=GET' because it violates the following Content Security Policy directive: "img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.iubenda.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com *.google.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com wss://jquerymanagerus.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...
资源
https://www.giappichelli.it/lo-stato-ecologico-9791221103571
描述
[Report Only] Refused to load the image 'https://www.facebook.com/tr/?id=545633762292837&ev=ViewContent&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&rl=&if=false&ts=1738143439764&cd[content_ids]=9791221153682&cd[content_type]=product&sw=1&sh=1&v=2.9.180&r=stable&ec=1&o=12318&fbp=fb.1.1738143439751.634890438962546188&ler=empty&cdl=API_unavailable&it=1738143439418&coo=false&rqm=GET' because it violates the following Content Security Policy directive: "img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.iubenda.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com *.google.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com wss://jquerymanagerus.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'".
内容安全策略控制允许用户代理为指定页面加载的资源。

单击可了解更多信息...

证书 · 找到· 10 个

Copy link

SSL/TLS 证书使网站能够加密客户端和服务器之间的事务并提供服务器身份验证

主题颁发日期到期日期
giappichelli.it
cdn.scalapay.com
*.iubenda.com
giappichelli.com
*.google-analytics.com
www.google.com
*.facebook.com
*.hotjar.com
upload.video.google.com
*.gstatic.com