Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 75.2.43.161:80 · api-dev.delivast.co.za
2026-01-09 13:27
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 13:28:45 GMT
Etag: W/"194-2XB8aP4kFJXLA5EbAI6ICYhiMsI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=RXfU16ZqP6Xld8uGeNlKbai9RUOH7pvYCAYLnyYMYtU%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767965325"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=RXfU16ZqP6Xld8uGeNlKbai9RUOH7pvYCAYLnyYMYtU%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767965325"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 599
X-Ratelimit-Reset: 1767965341
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.1<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 76.223.11.49:443 · api-dev.delivast.co.za
2026-01-08 23:13
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Thu, 08 Jan 2026 23:13:10 GMT
Etag: W/"194-2XB8aP4kFJXLA5EbAI6ICYhiMsI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dw%2BBvXgNz8OLhpvAutpHV85EZQ0slplc2r7BN5LnwFI%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767913990"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dw%2BBvXgNz8OLhpvAutpHV85EZQ0slplc2r7BN5LnwFI%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767913990"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 599
X-Ratelimit-Reset: 1767914041
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.1<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 75.2.43.161:80 · api-dev.delivast.co.za
2026-01-02 00:52
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 00:52:06 GMT
Etag: W/"194-2XB8aP4kFJXLA5EbAI6ICYhiMsI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dNN2WPBZXlmHYeOB4MMXbMscmV2Fkenm%2Bjf8Kwu0Tvs%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767315126"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dNN2WPBZXlmHYeOB4MMXbMscmV2Fkenm%2Bjf8Kwu0Tvs%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767315126"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 598
X-Ratelimit-Reset: 1767315175
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.1<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 76.223.11.49:443 · api-dev.delivast.co.za
2026-01-01 22:44
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Thu, 01 Jan 2026 22:44:28 GMT
Etag: W/"194-2XB8aP4kFJXLA5EbAI6ICYhiMsI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=blI6wtoh%2BF1VE8rn3taXPMRTkiz22uNoCbzSGzu0XOk%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767307468"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=blI6wtoh%2BF1VE8rn3taXPMRTkiz22uNoCbzSGzu0XOk%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767307468"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 599
X-Ratelimit-Reset: 1767307495
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.1<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 75.2.43.161:80 · api-dev.delivast.co.za
2025-12-30 07:34
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Tue, 30 Dec 2025 07:34:36 GMT
Etag: W/"194-2XB8aP4kFJXLA5EbAI6ICYhiMsI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=gCDmd7aIn6nQYZY0X7iEDIDsUUVyrAuajA2LHuCatl0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767080076"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=gCDmd7aIn6nQYZY0X7iEDIDsUUVyrAuajA2LHuCatl0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767080076"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 598
X-Ratelimit-Reset: 1767080130
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.1<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 76.223.11.49:443 · api-dev.delivast.co.za
2025-12-30 07:34
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Tue, 30 Dec 2025 07:34:32 GMT
Etag: W/"194-2XB8aP4kFJXLA5EbAI6ICYhiMsI"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=F8nA7teCm2ZWOTp6V%2Bff9Tfp8xtPlNgQegIbkh2duNc%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767080072"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=F8nA7teCm2ZWOTp6V%2Bff9Tfp8xtPlNgQegIbkh2duNc%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767080072"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 599
X-Ratelimit-Reset: 1767080130
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.1<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 76.223.11.49:443 · api-dev.delivast.co.za
2025-12-22 21:01
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 21:01:39 GMT
Etag: W/"194-wooG/MZxzokoyXcv/4nPoyj+zw4"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=gKTjv6o6UmaDTQ1rWwjW5muNgQk9%2FnwHC%2Fd17vUn8e8%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766437299"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=gKTjv6o6UmaDTQ1rWwjW5muNgQk9%2FnwHC%2Fd17vUn8e8%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766437299"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 599
X-Ratelimit-Reset: 1766437336
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.0<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 75.2.43.161:80 · api-dev.delivast.co.za
2025-12-22 21:01
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 21:01:41 GMT
Etag: W/"194-wooG/MZxzokoyXcv/4nPoyj+zw4"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=bZ%2FQ83nP75iV4lYbHUXsQndBXiVBdqDhXdb3hJ55H3Y%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766437301"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=bZ%2FQ83nP75iV4lYbHUXsQndBXiVBdqDhXdb3hJ55H3Y%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766437301"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 597
X-Ratelimit-Reset: 1766437336
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.0<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 75.2.43.161:80 · api-dev.delivast.co.za
2025-12-21 00:35
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 00:35:09 GMT
Etag: W/"194-wooG/MZxzokoyXcv/4nPoyj+zw4"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dH8RJ0BcsYucQHufv2VVNRTLFbQ0eYv7NXAT3pyiStg%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766277309"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dH8RJ0BcsYucQHufv2VVNRTLFbQ0eYv7NXAT3pyiStg%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766277309"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 597
X-Ratelimit-Reset: 1766277348
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.0<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>
Open service 76.223.11.49:443 · api-dev.delivast.co.za
2025-12-21 00:35
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 404
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 00:35:04 GMT
Etag: W/"194-wooG/MZxzokoyXcv/4nPoyj+zw4"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=TpsvvddRXZxwE3HoDn51T11IMl5y1OmI7jMLC1jv%2FS0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766277304"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=TpsvvddRXZxwE3HoDn51T11IMl5y1OmI7jMLC1jv%2FS0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766277304"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
X-Ratelimit-Limit: 600
X-Ratelimit-Remaining: 599
X-Ratelimit-Reset: 1766277348
Connection: close
<!DOCTYPE html><html><head><link rel='icon' href='/public/favicon.ico'></head><body><p style='position:absolute;right:0;top:0;margin:10px;'>0.121.0<p/><div style='text-align:center;margin-top:35vh;'> <img style='width:250px;object-fit:contain;' src='/public/logo_text.png'><br><br><br><h1 >API</h1><p style='text-align:center;'>Click Here to View <a href='/api-docs'>Api Docs</a></p></div></body></html>