31 technologies5 categories
maxphoto.co.uk is built on WordPress with Google Tag Manager and Google Analytics.
The frontend relies on Bootstrap. Analytics are handled by Google Tag Manager and Google Analytics. Infrastructure includes Fastly and DNSimple.
Tech Stack Highlights
Core Platform2
Magento
Ecommerce
100%
3 evidence signals
Cookie
mage-cache-storageCookie
mage-cache-storage-section-invalidationScript
https://www.maxphoto.co.uk/static/version1780492897/frontend/Affinity/MaxPhoto/en_GB/Magento_Translation/js/mage-translation-dictionary.jsWordPress
CMS
75%
1 evidence signal
HTML
<a href="https://www.timpson-group.co.uk/wp-content/Frameworks & Languages4
PHP
Programming languages
75%
1 evidence signal
Cookie
PHPSESSIDBootstrap
UI frameworks
75%
3 evidence signals
Script
https://www.maxphoto.co.uk/static/version1780492897/frontend/Affinity/MaxPhoto/en_GB/mage/bootstrap.jsScript
https://www.maxphoto.co.uk/static/version1780492897/frontend/Affinity/MaxPhoto/en_GB/Magento_Ui/js/lib/knockout/bootstrap.jsScript
https://www.maxphoto.co.uk/static/version1780492897/frontend/Affinity/MaxPhoto/en_GB/Magento_Ui/js/lib/knockout/bindings/bootstrap.jsAngular
JavaScript frameworks
75%
1 evidence signal
HTML
<a href="/photo-printing-appMySQL
Databases
75%
1 evidence signal
HTML
implied by MagentoAnalytics & Marketing11
Google Tag Manager
Tag managers
100%
3 evidence signals
HTML
googletagmanager.com/gtm.jsJS Global
google_tag_manager → objectJS Global
dataLayer → objectGoogle Analytics
Analytics
100%
3 evidence signals
Cookie
_gaScript
https://www.googletagmanager.com/gtag/js?id=G-65113DXZ4J&cx=c>m=4e6631Script
https://www.googletagmanager.com/gtag/js?id=AW-871804613&cx=c>m=4e6631Facebook Pixelv2.9.334
Analytics
100%
3 evidence signals
Script
https://connect.facebook.net/signals/config/1392500900916303?v=2.9.334&r=stable&domain=www.maxphoto.co.uk&hme=d9eb83ce5750216745fae8e2064a8c1ed2255ecaf2468f800b2a146e6168b65e&ex_m=105%2C208%2C156%2C22%2C73%2C74%2C147%2C69%2C68%2C11%2C165%2C91%2C16%2C139%2C128%2C39%2C76%2C79%2C135%2C161%2C167%2C8%2C4%2C5%2C7%2C6%2C3%2C92%2C102%2C168%2C173%2C222%2C62%2C189%2C190%2C55%2C280%2C30%2C75%2C234%2C233%2C232%2C23%2C33%2C104%2C61%2C10%2C64%2C98%2C99%2C100%2C106%2C131%2C31%2C29%2C133%2C134%2C130%2C129%2C157%2C77%2C160%2C158%2C159%2C50%2C60%2C124%2C15%2C164%2C45%2C267%2C268%2C266%2C26%2C27%2C28%2C48%2C148%2C78%2C113%2C18%2C20%2C44%2C40%2C42%2C41%2C84%2C93%2C97%2C111%2C146%2C149%2C46%2C112%2C24%2C21%2C120%2C70%2C36%2C151%2C150%2C152%2C143%2C141%2C25%2C35%2C59%2C110%2C163%2C71%2C17%2C154%2C115%2C82%2C67%2C19%2C86%2C87%2C117%2C85%2C137%2C136%2C140%2C162%2C34%2C282%2C298%2C215%2C204%2C205%2C203%2C301%2C292%2C52%2C216%2C108%2C132%2C81%2C122%2C54%2C47%2C49%2C114%2C121%2C127%2C126%2C58%2C65%2C63%2C153%2C116%2C37%2C32%2C53%2C56%2C101%2C166%2C1%2C125%2C14%2C123%2C12%2C2%2C57%2C94%2C66%2C119%2C90%2C89%2C169%2C170%2C95%2C96%2C9%2C103%2C51%2C144%2C88%2C80%2C72%2C118%2C107%2C43%2C145%2C0%2C83%2C138%2C142%2C155%2C38%2C109%2C13%2C171Script
https://connect.facebook.net/en_US/fbevents.jsJS Global
_fbq → function(v2.9.334)Microsoft Advertising
Advertising
100%
5 evidence signals
Cookie
_uetsidCookie
_uetvidScript
https://bat.bing.com/bat.jsJS Global
UET → functionJS Global
uetq → objectMouse Flow
Analytics
100%
2 evidence signals
Script
https://cdn.mouseflow.com/projects/4ad1f965-3cce-4f94-b4f0-bad624d4ad7d.jsJS Global
_mfq → objectDotdigitalv4
Marketing automation
100%
4 evidence signals
Script
https://static.trackedweb.net/js/_dmptv4.jsScript
https://r1.trackedweb.net/js/_dmptv4.jsJS Global
dmPt → functionJS Global
dmtrackingobjectname → stringP
Proofpoint
Email
100%
1 evidence signal
dns
MX: mxb-004eb201.gslb.pphosted.comNew Relic
RUM
75%
2 evidence signals
JS Global
NREUM → objectJS Global
newrelic → objectTikTok Pixel
Analytics
75%
1 evidence signal
JS Global
TiktokAnalyticsObject → stringOptinMonster
Marketing automation
75%
1 evidence signal
JS Global
OptinMonsterApp → functionReviews.io
Reviews
75%
2 evidence signals
JS Global
reviewsio_hasVoted → functionJS Global
reviewsio_shareLink → functionInfrastructure & Security9
F
Fastly
CDN
100%
1 evidence signal
dns
CNAME: prod.magentocloud.map.fastly.netD
DNSimple
PaaS
100%
1 evidence signal
dns
NS: ns4.dnsimple.comreCAPTCHA
Security
75%
2 evidence signals
Script
https://www.google.com/recaptcha/api.js?onload=globalOnRecaptchaOnLoadCallback&render=explicitScript
https://www.google.com/recaptcha/api.js?onload=globalOnRecaptchaOnLoadCallback&render=explicitHSTS
Security
75%
1 evidence signal
Header
max-age=31536000; includeSubDomains; preloadhCaptcha
Security
75%
1 evidence signal
Header
(?:\.|//)hcaptcha\.com: font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.cloudflare.com *.googleapis.com https://www.gstatic.com *.trustedshops.com *.twimg.com *.twitter.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com cdn.honey.io *.timpson.com a.omappapi.com z.omappapi.com maxcdn.bootstrapcdn.com *.fontawesome.com isnaps-builder.maxphoto.co.uk 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com https://cdnjs.cloudflare.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.sandbox.paypal.com *.paypalobjects.com *.timpson-group.co.uk paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com https://seo.mageplaza.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.awin1.com *.zenaps.com *.doubleclick.net *.bing.com *.twitter.com https://*.google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com *.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com *.xtento.com *.timpson-group.co.uk paypal.com *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com birdeye.com *.birdeye.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.facebook.com *.googlesyndication.com account.fetchify.com g3d-app.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.reviews.io *.reviews.co.uk www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.maxphoto.co.uk *.tescophoto.com *.snappysnaps.co.uk photo.asda.com ap.affinity-dev.co.uk *.cloudfront.net blob: *.googleadservices.com *.klarna.com *.lightemporium.com *.twimg.com *.twitter.com *.usercentrics.eu *.ytimg.com https://*.google.com google.com *.googleapis.com *.static.com *.googletagmanager.com *.googleusercontent.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com www.xtento.com *.timpson-group.co.uk *.timpson.com paypal.com *.bing.com *.bing.net *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat analytics.tiktok.com images.timpson.co.uk *.timpsonlocksmiths.co.uk *.timpsonsecurity.co.uk lantern.roeye.com a.omappapi.com z.omappapi.com *.magentocommerce.com birdeye.com *.birdeye.com *.supabase.co *.trackedlink.net *.ddlnk.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com isnaps-builder.maxphoto.co.uk 'self' data: *.facebook.com *.facebook.net *.googlesyndication.com *.soreto.com g3d-app.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com *.reviews.io *.reviews.co.uk cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com 'report-sha256' *.fontawesome.com *.trustedshops.com *.twimg.com *.twitter.com *.usercentrics.eu https://*.google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net *.ggpht.com *.xtento.com *.timpson-group.co.uk *.timpson.com *.paypal.com paypal.com *.bing.com *.termly.io *.hotjar.com *.hotjar.io *.popupsmart.com *.doubleclick.net cdn.mouseflow.com analytics.tiktok.com a.omappapi.com cdn.studentbeans.com connect.facebook.net birdeye.com *.birdeye.com *.trysoro.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com isnaps-builder.maxphoto.co.uk *.google.bg *.facebook.com *.facebook.net *.gstatic.com *.googlesyndication.com *.soreto.com cc-cdn.com g3d-app.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com https://cdnjs.cloudflare.com *.reviews.io *.reviews.co.uk www.xtento.com cdn.xtento.com https://www.maxphoto.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.usercentrics.eu https://fonts.googleapis.com google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com *.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com *.xtento.com *.timpson-group.co.uk *.paypal.com paypal.com *.bing.com *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net a.omappapi.com *.timpson.com birdeye.com *.birdeye.com maxcdn.bootstrapcdn.com assets.braintreegateway.com isnaps-builder.maxphoto.co.uk *.facebook.com *.googlesyndication.com cc-cdn.com g3d-app.com https://hcaptcha.com https://*.hcaptcha.com https://cdnjs.cloudflare.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.twitter.com *.twimg.com https://*.google.com *.google.co.uk *.google.ie *.google.fr *.google.de *.google.se *.google.nl *.google.dk *.google.it *.google.ca *.google.es google.co.uk *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net *.ggpht.com *.xtento.com *.timpson-group.co.uk *.timpson.com paypal.com *.bing.com *.bing.net *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net api.omappapi.com analytics.tiktok.com analytics-ipv6.tiktokw.us eu01.rec.mouseflow.com *.omappapi.com a.omappapi.com z.omappapi.com kg668dbov0.execute-api.us-east-1.amazonaws.com birdeye.com *.birdeye.com rum.hlx.page *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com isnaps-builder.maxphoto.co.uk *.facebook.com *.facebook.net *.googlesyndication.com *.soreto.com *.awinblackfriday.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com g3d-app.com https://ipinfo.io https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report.centralcsp.com/6814d628f6bc10d374666be2; report-to report-endpoint;Amazon S3
CDN
75%
1 evidence signal
Header
s3[^ ]*amazonaws\.com: font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.cloudflare.com *.googleapis.com https://www.gstatic.com *.trustedshops.com *.twimg.com *.twitter.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com cdn.honey.io *.timpson.com a.omappapi.com z.omappapi.com maxcdn.bootstrapcdn.com *.fontawesome.com isnaps-builder.maxphoto.co.uk 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com https://cdnjs.cloudflare.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.sandbox.paypal.com *.paypalobjects.com *.timpson-group.co.uk paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com https://seo.mageplaza.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.awin1.com *.zenaps.com *.doubleclick.net *.bing.com *.twitter.com https://*.google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com *.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com *.xtento.com *.timpson-group.co.uk paypal.com *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com birdeye.com *.birdeye.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.facebook.com *.googlesyndication.com account.fetchify.com g3d-app.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.reviews.io *.reviews.co.uk www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.maxphoto.co.uk *.tescophoto.com *.snappysnaps.co.uk photo.asda.com ap.affinity-dev.co.uk *.cloudfront.net blob: *.googleadservices.com *.klarna.com *.lightemporium.com *.twimg.com *.twitter.com *.usercentrics.eu *.ytimg.com https://*.google.com google.com *.googleapis.com *.static.com *.googletagmanager.com *.googleusercontent.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com www.xtento.com *.timpson-group.co.uk *.timpson.com paypal.com *.bing.com *.bing.net *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat analytics.tiktok.com images.timpson.co.uk *.timpsonlocksmiths.co.uk *.timpsonsecurity.co.uk lantern.roeye.com a.omappapi.com z.omappapi.com *.magentocommerce.com birdeye.com *.birdeye.com *.supabase.co *.trackedlink.net *.ddlnk.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com isnaps-builder.maxphoto.co.uk 'self' data: *.facebook.com *.facebook.net *.googlesyndication.com *.soreto.com g3d-app.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com *.reviews.io *.reviews.co.uk cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com 'report-sha256' *.fontawesome.com *.trustedshops.com *.twimg.com *.twitter.com *.usercentrics.eu https://*.google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net *.ggpht.com *.xtento.com *.timpson-group.co.uk *.timpson.com *.paypal.com paypal.com *.bing.com *.termly.io *.hotjar.com *.hotjar.io *.popupsmart.com *.doubleclick.net cdn.mouseflow.com analytics.tiktok.com a.omappapi.com cdn.studentbeans.com connect.facebook.net birdeye.com *.birdeye.com *.trysoro.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com isnaps-builder.maxphoto.co.uk *.google.bg *.facebook.com *.facebook.net *.gstatic.com *.googlesyndication.com *.soreto.com cc-cdn.com g3d-app.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com https://cdnjs.cloudflare.com *.reviews.io *.reviews.co.uk www.xtento.com cdn.xtento.com https://www.maxphoto.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.usercentrics.eu https://fonts.googleapis.com google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com *.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com *.xtento.com *.timpson-group.co.uk *.paypal.com paypal.com *.bing.com *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net a.omappapi.com *.timpson.com birdeye.com *.birdeye.com maxcdn.bootstrapcdn.com assets.braintreegateway.com isnaps-builder.maxphoto.co.uk *.facebook.com *.googlesyndication.com cc-cdn.com g3d-app.com https://hcaptcha.com https://*.hcaptcha.com https://cdnjs.cloudflare.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.twitter.com *.twimg.com https://*.google.com *.google.co.uk *.google.ie *.google.fr *.google.de *.google.se *.google.nl *.google.dk *.google.it *.google.ca *.google.es google.co.uk *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net *.ggpht.com *.xtento.com *.timpson-group.co.uk *.timpson.com paypal.com *.bing.com *.bing.net *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net api.omappapi.com analytics.tiktok.com analytics-ipv6.tiktokw.us eu01.rec.mouseflow.com *.omappapi.com a.omappapi.com z.omappapi.com kg668dbov0.execute-api.us-east-1.amazonaws.com birdeye.com *.birdeye.com rum.hlx.page *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com isnaps-builder.maxphoto.co.uk *.facebook.com *.facebook.net *.googlesyndication.com *.soreto.com *.awinblackfriday.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com g3d-app.com https://ipinfo.io https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report.centralcsp.com/6814d628f6bc10d374666be2; report-to report-endpoint;Unpkg
CDN
75%
2 evidence signals
Script
https://unpkg.com/@adobe/magento-storefront-events-sdk@%5E1/dist/index.jsScript
https://unpkg.com/@adobe/magento-storefront-event-collector@%5E1/dist/index.jsPlatform.sh
PaaS
75%
1 evidence signal
Header
i-0851742bda89651ac
i-0851742bda89651acAmazon Web Services
PaaS
50%
1 evidence signal
HTML
implied by Amazon S3Libraries & Utilities5
Underscore.js
JavaScript libraries
75%
1 evidence signal
Script
https://www.maxphoto.co.uk/static/version1780492897/frontend/Affinity/MaxPhoto/en_GB/underscore.jscore-js
JavaScript libraries
75%
1 evidence signal
JS Global
__core-js_shared__ → objectPayPal
Payment processors
75%
1 evidence signal
Header
\.paypal\.com: font-src fonts.gstatic.com use.typekit.net www.paypalobjects.com *.typekit.net *.gstatic.com *.cloudflare.com *.googleapis.com https://www.gstatic.com *.trustedshops.com *.twimg.com *.twitter.com pouch-global-font-assets.s3.eu-central-1.amazonaws.com cdn.honey.io *.timpson.com a.omappapi.com z.omappapi.com maxcdn.bootstrapcdn.com *.fontawesome.com isnaps-builder.maxphoto.co.uk 'self' data: *.doubleclick.net *.facebook.com *.googlesyndication.com https://fonts.gstatic.com https://cdnjs.cloudflare.com *.cloudfront.net *.reviews.io *.reviews.co.uk data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com *.twitter.com *.sandbox.paypal.com *.paypalobjects.com *.timpson-group.co.uk paypal.com *.cardinalcommerce.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * *.facebook.com *.googlesyndication.com https://seo.mageplaza.com *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com www.paypalobjects.com player.vimeo.com https://www.google.com/recaptcha/ *.braintreegateway.com *.paypal.com google.com *.google.com www.googletagmanager.com *.awin1.com *.zenaps.com *.doubleclick.net *.bing.com *.twitter.com https://*.google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com *.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com *.xtento.com *.timpson-group.co.uk paypal.com *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com birdeye.com *.birdeye.com *.dotdigital-pages.com *.dotdigital.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com * *.facebook.com *.googlesyndication.com account.fetchify.com g3d-app.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.reviews.io *.reviews.co.uk www.xtento.com 'self' 'unsafe-inline'; img-src data: assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com www.googleadservices.com *.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net *.analytics.google.com www.googletagmanager.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com *.paypal.com *.typekit.net *.gstatic.com validator.swagger.io *.ftcdn.net *.behance.net *.awin1.com *.zenaps.com *.wepowerconnections.com *.maxphoto.co.uk *.tescophoto.com *.snappysnaps.co.uk photo.asda.com ap.affinity-dev.co.uk *.cloudfront.net blob: *.googleadservices.com *.klarna.com *.lightemporium.com *.twimg.com *.twitter.com *.usercentrics.eu *.ytimg.com https://*.google.com google.com *.googleapis.com *.static.com *.googletagmanager.com *.googleusercontent.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com www.xtento.com *.timpson-group.co.uk *.timpson.com paypal.com *.bing.com *.bing.net *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net *.google.ad *.google.ae *.google.com.af *.google.com.ag *.google.com.ai *.google.al *.google.am *.google.co.ao *.google.com.ar *.google.as *.google.at *.google.com.au *.google.az *.google.ba *.google.com.bd *.google.be *.google.bf *.google.bg *.google.com.bh *.google.bi *.google.bj *.google.com.bn *.google.com.bo *.google.com.br *.google.bs *.google.co.bw *.google.by *.google.com.bz *.google.ca *.google.cd *.google.cf *.google.cg *.google.ch *.google.ci *.google.co.ck *.google.cl *.google.cm *.google.cn *.google.com.co *.google.co.cr *.google.com.cu *.google.cv *.google.com.cy *.google.cz *.google.de *.google.dj *.google.dk *.google.dm *.google.com.do *.google.dz *.google.com.ec *.google.ee *.google.eg *.google.es *.google.com.et *.google.fi *.google.com.fj *.google.fm *.google.fr *.google.ga *.google.ge *.google.gg *.google.com.gh *.google.com.gi *.google.gl *.google.gm *.google.gr *.google.com.gt *.google.gy *.google.com.hk *.google.hn *.google.hr *.google.ht *.google.hu *.google.co.id *.google.ie *.google.co.il *.google.im *.google.co.in *.google.iq *.google.is *.google.it *.google.je *.google.com.jm *.google.jo *.google.co.jp *.google.co.ke *.google.com.kh *.google.ki *.google.kg *.google.co.kr *.google.com.kw *.google.kz *.google.la *.google.com.lb *.google.li *.google.lk *.google.co.ls *.google.lt *.google.lu *.google.lv *.google.com.ly *.google.co.ma *.google.md *.google.me *.google.mg *.google.mk *.google.ml *.google.com.mm *.google.mn *.google.ms *.google.com.mt *.google.mu *.google.mv *.google.mw *.google.com.mx *.google.com.my *.google.co.mz *.google.com.na *.google.com.ng *.google.com.ni *.google.ne *.google.nl *.google.no *.google.com.np *.google.nr *.google.nu *.google.co.nz *.google.com.om *.google.com.pa *.google.com.pe *.google.com.pg *.google.com.ph *.google.com.pk *.google.pl *.google.pn *.google.com.pr *.google.ps *.google.pt *.google.com.py *.google.com.qa *.google.ro *.google.ru *.google.rw *.google.com.sa *.google.com.sb *.google.sc *.google.se *.google.com.sg *.google.sh *.google.si *.google.sk *.google.com.sl *.google.sn *.google.so *.google.sm *.google.sr *.google.st *.google.com.sv *.google.td *.google.tg *.google.co.th *.google.com.tj *.google.tl *.google.tm *.google.tn *.google.to *.google.com.tr *.google.tt *.google.com.tw *.google.co.tz *.google.com.ua *.google.co.ug *.google.co.uk *.google.com.uy *.google.co.uz *.google.com.vc *.google.co.ve *.google.vg *.google.co.vi *.google.com.vn *.google.vu *.google.ws *.google.rs *.google.co.za *.google.co.zm *.google.co.zw *.google.cat analytics.tiktok.com images.timpson.co.uk *.timpsonlocksmiths.co.uk *.timpsonsecurity.co.uk lantern.roeye.com a.omappapi.com z.omappapi.com *.magentocommerce.com birdeye.com *.birdeye.com *.supabase.co *.trackedlink.net *.ddlnk.net www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com isnaps-builder.maxphoto.co.uk 'self' data: *.facebook.com *.facebook.net *.googlesyndication.com *.soreto.com g3d-app.com https://*.googleapis.com https://*.googleusercontent.com magefan.com cm.magefan.com *.disqus.com *.reviews.io *.reviews.co.uk cdn.xtento.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com unpkg.com/@adobe/ cdn.jsdelivr.net/npm/@adobe/ commerce.adobedtm.com js.magento-datasolutions.com *.newrelic.com *.nr-data.net amcglobal.sc.omtrdc.net *.adobe.io use.typekit.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com magento-recs-sdk.adobe.net s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com *.magento-ds.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.typekit.net google.com *.google.com *.cdn-apple.com *.braintreegateway.com *.magento-datasolutions.com https://rum.hlx.page *.awin1.com *.dwin1.com *.zenaps.com *.wepowerconnections.com https://the.sciencebehindecommerce.com lantern.roeyecdn.com 'report-sha256' *.fontawesome.com *.trustedshops.com *.twimg.com *.twitter.com *.usercentrics.eu https://*.google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net *.ggpht.com *.xtento.com *.timpson-group.co.uk *.timpson.com *.paypal.com paypal.com *.bing.com *.termly.io *.hotjar.com *.hotjar.io *.popupsmart.com *.doubleclick.net cdn.mouseflow.com analytics.tiktok.com a.omappapi.com cdn.studentbeans.com connect.facebook.net birdeye.com *.birdeye.com *.trysoro.com *.trackedlink.net *.trackedweb.net *.ddlnk.net *.dotdigital-pages.com debug-tracking.dotdigital.internal js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com songbirdstag.cardinalcommerce.com isnaps-builder.maxphoto.co.uk *.google.bg *.facebook.com *.facebook.net *.gstatic.com *.googlesyndication.com *.soreto.com cc-cdn.com g3d-app.com https://*.googleapis.com https://*.ggpht.com https://*.googleusercontent.com https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com *.disqus.com https://cdnjs.cloudflare.com *.reviews.io *.reviews.co.uk www.xtento.com cdn.xtento.com https://www.maxphoto.co.uk 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.magento-datasolutions.com *.magento-ds.com *.fontawesome.com *.trustedshops.com *.twimg.com *.twitter.com *.typekit.net *.usercentrics.eu https://fonts.googleapis.com google.com *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.google-analytics.com *.cloudflare.com *.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.newrelic.com *.nr-data.net *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net vimeo.com *.ggpht.com *.xtento.com *.timpson-group.co.uk *.paypal.com paypal.com *.bing.com *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net a.omappapi.com *.timpson.com birdeye.com *.birdeye.com maxcdn.bootstrapcdn.com assets.braintreegateway.com isnaps-builder.maxphoto.co.uk *.facebook.com *.googlesyndication.com cc-cdn.com g3d-app.com https://hcaptcha.com https://*.hcaptcha.com https://cdnjs.cloudflare.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com data: 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google-analytics.com www.googleadservices.com *.analytics.google.com www.googletagmanager.com *.snplow.net commerce.adobedc.net *.newrelic.com *.nr-data.net vimeo.com api.magento.com *.adobe.io performance.typekit.net www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com commerce.adobe.io *.sentry.io *.paypal.com google.com *.google.com *.braintreegateway.com *.braintree-api.com *.magento-datasolutions.com *.magento-ds.com *.wepowerconnections.com https://the.sciencebehindecommerce.com *.twitter.com *.twimg.com https://*.google.com *.google.co.uk *.google.ie *.google.fr *.google.de *.google.se *.google.nl *.google.dk *.google.it *.google.ca *.google.es google.co.uk *.googleapis.com *.static.com *.googleadservices.com *.googletagmanager.com *.googleusercontent.com *.cloudflare.com https://*.gstatic.com *.sandbox.paypal.com *.paypalobjects.com *.csp-reporting-service.com *.trustist.com trustist.blob.core.windows.net *.ggpht.com *.xtento.com *.timpson-group.co.uk *.timpson.com paypal.com *.bing.com *.bing.net *.termly.io *.hotjar.com *.hotjar.io *.dwin1.com *.popupsmart.com *.doubleclick.net api.omappapi.com analytics.tiktok.com analytics-ipv6.tiktokw.us eu01.rec.mouseflow.com *.omappapi.com a.omappapi.com z.omappapi.com kg668dbov0.execute-api.us-east-1.amazonaws.com birdeye.com *.birdeye.com rum.hlx.page *.trackedlink.net *.trackedweb.net *.dotdigital-pages.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.cardinalcommerce.com isnaps-builder.maxphoto.co.uk *.facebook.com *.facebook.net *.googlesyndication.com *.soreto.com *.awinblackfriday.com api.craftyclicks.co.uk pcls1.craftyclicks.co.uk cc-cdn.com g3d-app.com https://ipinfo.io https://*.googleapis.com https://hcaptcha.com https://*.hcaptcha.com *.cloudfront.net *.reviews.io *.reviews.co.uk 'self' 'unsafe-inline'; child-src *.awin1.com *.zenaps.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://report.centralcsp.com/6814d628f6bc10d374666be2; report-to report-endpoint;Moment.js
JavaScript libraries
75%
1 evidence signal
Script
https://www.maxphoto.co.uk/static/version1780492897/frontend/Affinity/MaxPhoto/en_GB/moment.jsFont Awesome
Font scripts
75%
1 evidence signal
stylesheet
https://www.maxphoto.co.uk/static/version1780492897/frontend/Affinity/MaxPhoto/en_GB/Ubertheme_Base/css/font-awesome.min-5.14.0.css