https://www.giappichelli.it/lo-stato-ecologico-9791221103571

已提交的 URL:
https://www.giappichelli.it/lo-stato-ecologico-9791221103571
報告完成時間:

風險 · 找到 0 個

Copy link

可能帶來安全風險的做法

  • 無分類

安全標頭 · 找到 3 個

Copy link

可增強 Web 應用程式安全性的 HTTP 回應標頭

瞭解更多...
名稱價值支援資訊
Strict-Transport-Security良性宣佈僅可透過安全連線 (HTTPS) 存取網站。

按一下以瞭解更多...
X-Frame-OptionsSAMEORIGIN良性表明是否應允許瀏覽器在 <frame>、<iframe>、<embed> 或 <object> 中呈現頁面。

按一下以瞭解更多...
X-Content-Type-Optionsnosniff良性表明應遵循在 Content-Type 標頭中公告的 MIME 類型,不得變更。

按一下以瞭解更多...
Content-Security-Policy良性控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
Referrer-Policy良性控制要求中應包含多少推薦人資訊。

按一下以瞭解更多...
Clear-Site-Data良性控制用戶端瀏覽器為來源伺服器儲存的資料。

按一下以瞭解更多...
X-Permitted-Cross-Domain-Policies良性控制 Web 用戶端(例如,Adobe Flash Player 或 Adobe Acrobat)是否有權跨網域處理資料。

按一下以瞭解更多...
Permissions-Policy允許和拒絕在文件或 iframe 中使用瀏覽器功能。

按一下以瞭解更多...
Cross-Origin-Embedder-Policy設定將跨來源資源嵌入至文件中。

按一下以瞭解更多...
Cross-Origin-Opener-Policy確保頂層文件不會與跨來源文件共用瀏覽上下文群組。

按一下以瞭解更多...
Cross-Origin-Resource-Policy要求瀏覽器封鎖對給定資源的 no-cors 跨來源/跨網站要求。

按一下以瞭解更多...
X-XSS-Protection1; mode=block已棄用已棄用。偵測到反射式 Cross-site scripting (XSS) 攻擊時,阻止載入頁面。

按一下以瞭解更多...
Feature-Policy已棄用已棄用。取代為 Permissions-Policy 標頭。

按一下以瞭解更多...
Expect-CT已棄用已棄用。選擇加入報告和/或強制執行憑證透明度要求。

按一下以瞭解更多...
Public-Key-Pins已棄用已棄用。允許 HTTPS 網站抵制攻擊者使用錯誤核發或詐騙性憑證進行假冒。

按一下以瞭解更多...

安全違規 · 找到 19 個

Copy link

違反安全性原則的要求或資源

違規類型資訊
資源
https://www.giappichelli.it/lo-stato-ecologico-9791221103571
描述
[Report Only] Refused to load the image 'https://giappichelli-usa.com/media/bssstoresflags/stores/2/en_1.png' because it violates the following Content Security Policy directive: "img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.iubenda.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com *.google.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com wss://jquerymanagerus.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
描述
[Report Only] Refused to load the script 'https://connect.facebook.net/en_US/fbevents.js' because it violates the following Content Security Policy directive: "script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.iubenda.com *.disqus.com *.avada.io cdn.jsdelivr.net https://player.vimeo.com https://www.youtube.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtm.js?id=GTM-5LT9583
描述
[Report Only] Refused to load the script 'https://static.hotjar.com/c/hotjar-3542165.js?sv=7' because it violates the following Content Security Policy directive: "script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.iubenda.com *.disqus.com *.avada.io cdn.jsdelivr.net https://player.vimeo.com https://www.youtube.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/
描述
[Report Only] Refused to frame 'https://www.googletagmanager.com/' because it violates the following Content Security Policy directive: "frame-src 'self' fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.iubenda.com https://player.vimeo.com https://www.youtube-nocookie.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/
描述
[Report Only] Refused to frame 'https://www.googletagmanager.com/' because it violates the following Content Security Policy directive: "frame-src 'self' fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com *.iubenda.com https://player.vimeo.com https://www.youtube-nocookie.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com *.wesupply.xyz https://wesupplylabs.com *.weltpixel.com www.xtento.com".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-5HBMHENWBH&l=dataLayer&cx=c&gtm=45He51r0v9121834497za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-5HBMHENWBH&gtm=45je51r0v9132218300z89121834497za200zb9121834497&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102308675&cid=573248678.1738143439&ecid=760587142&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_s=1&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&_fv=1&_nsi=1&_ss=1&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2601' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-5HBMHENWBH&l=dataLayer&cx=c&gtm=45He51r0v9121834497za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-5HBMHENWBH&gtm=45je51r0v9132218300z89121834497za200zb9121834497&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102308675&cid=573248678.1738143439&ecid=760587142&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_s=1&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&_fv=1&_nsi=1&_ss=1&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2601' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-5HBMHENWBH&l=dataLayer&cx=c&gtm=45He51r0v9121834497za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-5HBMHENWBH&gtm=45je51r0v9132218300z89121834497za200zb9121834497&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102308675&cid=573248678.1738143439&ecid=760587142&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_z=1-00~2-00~3-00~4-00~7-00~8-00~9-00~6-00~5-00&ec_mode=a&_s=2&sid=1738143439&sct=1&seg=1&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=page_view&ep.pageType=product&ep.pagePath=%2Flo-stato-ecologico-9791221103571&tfd=2666' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-5HBMHENWBH&l=dataLayer&cx=c&gtm=45He51r0v9121834497za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-5HBMHENWBH&gtm=45je51r0v9132218300z89121834497za200zb9121834497&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102308675&cid=573248678.1738143439&ecid=760587142&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_z=1-00~2-00~3-00~4-00~7-00~8-00~9-00~6-00~5-00&ec_mode=a&_s=2&sid=1738143439&sct=1&seg=1&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=page_view&ep.pageType=product&ep.pagePath=%2Flo-stato-ecologico-9791221103571&tfd=2666' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808z8863639067za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_eu=Ag&_s=1&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&_fv=1&_ss=1&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2779' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808z8863639067za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&_eu=Ag&_s=1&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&_fv=1&_ss=1&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2779' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&frm=0&pscdl=denied&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&_eu=AAg&_s=2&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2846' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&frm=0&pscdl=denied&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&_eu=AAg&_s=2&sid=1738143439&sct=1&seg=0&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=view_item&pr1=nmLo%20Stato%20Ecologico%20-%20e-Book~id9791221153682~pr0.00~caDocenti~k0currency~v0EUR~k1item_stock_status~v1Out%20of%20stock~k2item_sale_product~v2No~k3item_reviews_count~v30~k4item_reviews_score~v40&tfd=2846' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808z8863639067za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&ec_mode=a&_s=3&sid=1738143439&sct=1&seg=1&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=page_view&ep.pageType=product&ep.pagePath=%2Flo-stato-ecologico-9791221103571&tfd=2849' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.googletagmanager.com/gtag/js?id=G-7TQ0YKR7J4&l=dataLayer&cx=c&gtm=45He51r0v863639067za200
描述
[Report Only] Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-7TQ0YKR7J4&gtm=45je51r0v887981808z8863639067za200zb863639067&_p=1738143438017&gcs=G100&gcd=13p3p3V2p5l1&npa=1&dma_cps=-&dma=1&tag_exp=102067808~102081485~102123608~102538703&cid=573248678.1738143439&ecid=1644665018&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=denied&ec_mode=a&_s=3&sid=1738143439&sct=1&seg=1&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&dt=Lo%20Stato%20Ecologico%20-%20DE%20LEONARDIS%20F.%20%7C%20Giappichelli&en=page_view&ep.pageType=product&ep.pagePath=%2Flo-stato-ecologico-9791221103571&tfd=2849' because it violates the following Content Security Policy directive: "connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.adobe.io performance.typekit.net *.sentry.io *.paypal.com google.com *.google.com *.googleapis.com *.iubenda.com https://get.geojs.io *.avada.io https://fonts.googleapis.com https://fonts.gstatic.com https://api.weatherbit.io *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com https://www.google-analytics.com 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://connect.facebook.net/en_US/fbevents.js
描述
[Report Only] Refused to load the script 'https://connect.facebook.net/signals/config/545633762292837?v=2.9.180&r=stable&domain=www.giappichelli.it&hme=1b2b48fb279bc2e2881583cc2153b57f55e340ed882b2c5394167c8bc992d930&ex_m=70%2C122%2C107%2C111%2C61%2C4%2C100%2C69%2C16%2C97%2C89%2C51%2C54%2C174%2C177%2C189%2C185%2C186%2C188%2C29%2C101%2C53%2C77%2C187%2C169%2C172%2C182%2C183%2C190%2C132%2C41%2C192%2C193%2C34%2C144%2C15%2C50%2C198%2C197%2C134%2C18%2C40%2C1%2C43%2C65%2C66%2C67%2C71%2C93%2C17%2C14%2C96%2C92%2C91%2C108%2C52%2C110%2C39%2C109%2C30%2C94%2C26%2C170%2C173%2C141%2C86%2C56%2C84%2C33%2C73%2C0%2C95%2C32%2C28%2C82%2C83%2C88%2C47%2C46%2C87%2C37%2C11%2C12%2C13%2C6%2C7%2C25%2C22%2C23%2C57%2C62%2C64%2C75%2C102%2C27%2C76%2C9%2C8%2C80%2C48%2C21%2C104%2C103%2C105%2C98%2C10%2C20%2C3%2C38%2C74%2C19%2C5%2C90%2C81%2C44%2C35%2C85%2C2%2C36%2C63%2C42%2C106%2C45%2C79%2C68%2C112%2C60%2C59%2C31%2C99%2C58%2C55%2C49%2C78%2C72%2C24%2C113' because it violates the following Content Security Policy directive: "script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.iubenda.com *.disqus.com *.avada.io cdn.jsdelivr.net https://player.vimeo.com https://www.youtube.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://static.hotjar.com/c/hotjar-3542165.js?sv=7
描述
[Report Only] Refused to load the script 'https://script.hotjar.com/modules.c2a25c7c94182e6bbdbd.js' because it violates the following Content Security Policy directive: "script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net *.typekit.net google.com *.google.com *.cdn-apple.com *.googleapis.com *.gstatic.com *.iubenda.com *.disqus.com *.avada.io cdn.jsdelivr.net https://player.vimeo.com https://www.youtube.com *.development.scalapay.com *.staging.scalapay.com *.scalapay.com *.stripe.com *.stripe.network *.stripecdn.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.amazon.com *.link.com *.cloudflare.com https://www.googletagmanager.com tagmanager.google.com www.xtento.com cdn.xtento.com 'self' 'unsafe-inline' 'unsafe-eval'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.giappichelli.it/lo-stato-ecologico-9791221103571
描述
[Report Only] Refused to load the image 'https://www.facebook.com/tr/?id=545633762292837&ev=PageView&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&rl=&if=false&ts=1738143439758&sw=1&sh=1&v=2.9.180&r=stable&ec=0&o=12318&fbp=fb.1.1738143439751.634890438962546188&cs_est=true&ler=empty&cdl=API_unavailable&it=1738143439418&coo=false&rqm=GET' because it violates the following Content Security Policy directive: "img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.iubenda.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com *.google.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com wss://jquerymanagerus.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...
資源
https://www.giappichelli.it/lo-stato-ecologico-9791221103571
描述
[Report Only] Refused to load the image 'https://www.facebook.com/tr/?id=545633762292837&ev=ViewContent&dl=https%3A%2F%2Fwww.giappichelli.it%2Flo-stato-ecologico-9791221103571&rl=&if=false&ts=1738143439764&cd[content_ids]=9791221153682&cd[content_type]=product&sw=1&sh=1&v=2.9.180&r=stable&ec=1&o=12318&fbp=fb.1.1738143439751.634890438962546188&ler=empty&cdl=API_unavailable&it=1738143439418&coo=false&rqm=GET' because it violates the following Content Security Policy directive: "img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.googleapis.com *.iubenda.com *.disqus.com https://firebasestorage.googleapis.com https://www.magezon.com *.google.com blob: https://updates.themepunch.tools http://updates.themepunch.tools https://updates.themepunch-ext-a.tools http://updates.themepunch-ext-a.tools https://updates.themepunch-ext-b.tools http://updates.themepunch-ext-b.tools https://dev.sliderrevolution.com https://revolution.themepunch.com http://revolution5.themepunch.com http://pbs.twimg.com https://pbs.twimg.com http://scontent.cdninstagram.com https://img.youtube.com http://live.staticflickr.com https://live.staticflickr.com wss://jquerymanagerus.com/ *.development.scalapay.com *.staging.scalapay.com *.scalapay.com www.xtento.com cdn.xtento.com data: 'self' 'unsafe-inline'".
內容安全性原則控制允許使用者代理程式為給定頁面載入的資源。

按一下以瞭解更多...

憑證 · 找到 10 個

Copy link

SSL/TLS 憑證可讓網站加密用戶端與伺服器之間的交易,並提供伺服器身分識別驗證

主旨核發日期到期日
giappichelli.it
cdn.scalapay.com
*.iubenda.com
giappichelli.com
*.google-analytics.com
www.google.com
*.facebook.com
*.hotjar.com
upload.video.google.com
*.gstatic.com