Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3b571938e6585c57ed32bf3abbccf0b616e54cd1e
GraphQL introspection enabled at /graphql Types: 110 (by kind: ENUM: 3, INPUT_OBJECT: 21, OBJECT: 76, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: companies, companies_aggregated, companies_by_id, companies_tags, companies_tags_by_id - Mutation: Mutation | fields: create_quiz_vizits_item, create_quiz_vizits_items, update_quiz_vizits_batch, update_quiz_vizits_item, update_quiz_vizits_items - Subscription: Subscription | fields: blocks_templates_mutated, companies_companies_tags_mutated, companies_mutated, companies_tags_mutated, directus_files_mutated Directives: deprecated, include, skip (total: 3) Readable stores: 0
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3b571938e6585c57ed32bf3abbccf0b616e54cd1e
GraphQL introspection enabled at /graphql Types: 110 (by kind: ENUM: 3, INPUT_OBJECT: 21, OBJECT: 76, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: companies, companies_aggregated, companies_by_id, companies_tags, companies_tags_by_id - Mutation: Mutation | fields: create_quiz_vizits_item, create_quiz_vizits_items, update_quiz_vizits_batch, update_quiz_vizits_item, update_quiz_vizits_items - Subscription: Subscription | fields: blocks_templates_mutated, companies_companies_tags_mutated, companies_mutated, companies_tags_mutated, directus_files_mutated Directives: deprecated, include, skip (total: 3) Readable stores: 0
Open service 76.223.57.73:80 · api-dev.motrixsolutions.com
2026-01-09 18:02
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 18:03:31 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=g3JB%2FRm%2FKlmjLrcB4O%2BAiOC4lLox04d8nZ3cqLn9hVg%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767981811"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=g3JB%2FRm%2FKlmjLrcB4O%2BAiOC4lLox04d8nZ3cqLn9hVg%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767981811"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:443 · api-dev.motrixsolutions.com
2026-01-09 08:07
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 08:07:28 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xEsYJo0AWlWGajia9JQtJu%2FlL662J1s06%2FmBF0NZGB4%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767946048"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xEsYJo0AWlWGajia9JQtJu%2FlL662J1s06%2FmBF0NZGB4%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767946048"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 76.223.57.73:80 · api-dev.motrixsolutions.com
2026-01-02 22:34
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 22:34:51 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xeuVEQb4HCJkoDUsYLtv6FyeJf6H4aeL%2BCpIbwxer%2Fw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767393291"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xeuVEQb4HCJkoDUsYLtv6FyeJf6H4aeL%2BCpIbwxer%2Fw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767393291"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:443 · api-dev.motrixsolutions.com
2026-01-02 12:42
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 12:42:23 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=B4lpPXX4KHOHx3hEH0S0Mq9d8EZ2rYAcg6n9hWw37jE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767357743"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=B4lpPXX4KHOHx3hEH0S0Mq9d8EZ2rYAcg6n9hWw37jE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767357743"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:443 · api-dev.motrixsolutions.com
2025-12-30 11:28
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 11:28:57 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=SUR3%2Bw22lTalvnT%2BHfQLfcGwpPDv1Xa65EXc8whZnF8%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767094137"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=SUR3%2Bw22lTalvnT%2BHfQLfcGwpPDv1Xa65EXc8whZnF8%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767094137"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 76.223.57.73:80 · api-dev.motrixsolutions.com
2025-12-22 22:54
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 22:54:39 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=3Hj3emZ7a9%2BU4azK79GuroTIXmNm7cY5iTyM5ZJ7yyk%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766444079"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=3Hj3emZ7a9%2BU4azK79GuroTIXmNm7cY5iTyM5ZJ7yyk%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766444079"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:443 · api-dev.motrixsolutions.com
2025-12-22 12:17
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 12:17:36 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wKPiz4cZyEeqzp2Z3E8bM9S7QVJMPf%2BCRMDhaSuK%2Ft8%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766405856"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wKPiz4cZyEeqzp2Z3E8bM9S7QVJMPf%2BCRMDhaSuK%2Ft8%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766405856"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 76.223.57.73:80 · api-dev.motrixsolutions.com
2025-12-21 02:47
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 02:47:21 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Vi4QGq0PgPA2g%2Ff60GE%2BZBBBRExiLhu1X6NN93T7Em0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766285241"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Vi4QGq0PgPA2g%2Ff60GE%2BZBBBRExiLhu1X6NN93T7Em0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766285241"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 15.197.149.68:443 · api-dev.motrixsolutions.com
2025-12-20 11:32
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 11:32:53 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=iUs2VSOp5WVAxbDGRlj48ngpamQIprfCjauTWV8V6O0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766230373"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=iUs2VSOp5WVAxbDGRlj48ngpamQIprfCjauTWV8V6O0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766230373"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin
Open service 76.223.57.73:80 · api-dev.motrixsolutions.com
2025-12-19 03:40
HTTP/1.1 302 Found
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: https://dev.motrixsolutions.com
Access-Control-Expose-Headers: Content-Range
Content-Length: 29
Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/plain; charset=utf-8
Date: Fri, 19 Dec 2025 03:40:14 GMT
Location: ./admin
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Aerhlu5qqASqCloKu6hrO7coWoRoqD4GpY6aK3PbaXE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766115614"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Aerhlu5qqASqCloKu6hrO7coWoRoqD4GpY6aK3PbaXE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766115614"
Server: Heroku
Vary: Origin, Accept
Via: 1.1 heroku-router
X-Powered-By: Directus
Connection: close
Found. Redirecting to ./admin