Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d57bcec616f5b336616a3bb5f9f7f082e6880e14
GraphQL introspection enabled at /graphql Types: 72 (by kind: ENUM: 6, INPUT_OBJECT: 14, OBJECT: 46, SCALAR: 6) Operations: - Query: Query | fields: pro, pros, prosBy, user, users - Mutation: Mutation | fields: addBooking, addUser, cancelBooking, updateBooking, updateUser Directives: cacheControl, deprecated, include, skip, specifiedBy (total: 5)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d57bcec616f5b336616a3bb5f9f7f082e6880e14
GraphQL introspection enabled at /graphql Types: 72 (by kind: ENUM: 6, INPUT_OBJECT: 14, OBJECT: 46, SCALAR: 6) Operations: - Query: Query | fields: pro, pros, prosBy, user, users - Mutation: Mutation | fields: addBooking, addUser, cancelBooking, updateBooking, updateUser Directives: cacheControl, deprecated, include, skip, specifiedBy (total: 5)
Open service 99.83.151.71:443 · api.alli.io
2026-01-09 14:18
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 14:18:38 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=G5qf13M2aD76SMfI3PbQ%2BqxWQAh3211nLSUJBm6H1Zs%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767968318"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=G5qf13M2aD76SMfI3PbQ%2BqxWQAh3211nLSUJBm6H1Zs%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767968318"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:80 · api.alli.io
2026-01-09 09:41
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 09:42:05 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=WfqygisNibK8R%2FbpAo8GAaY8bMyPH%2FVg2pTiXfw%2FUqQ%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767951725"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=WfqygisNibK8R%2FbpAo8GAaY8bMyPH%2FVg2pTiXfw%2FUqQ%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767951725"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:443 · api.alli.io
2026-01-02 18:52
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 18:52:24 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=SUWAaNqdHjGVcKA%2FyI%2B1xIwlbV1tjGnr89L8NcfaKGs%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767379944"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=SUWAaNqdHjGVcKA%2FyI%2B1xIwlbV1tjGnr89L8NcfaKGs%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767379944"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:80 · api.alli.io
2026-01-02 11:06
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 11:06:12 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=w827UjayWx8OaQI8M8wvFyrYN4GWAb3YCBXyVd1C604%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767351972"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=w827UjayWx8OaQI8M8wvFyrYN4GWAb3YCBXyVd1C604%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767351972"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:443 · api.alli.io
2025-12-23 05:42
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Tue, 23 Dec 2025 05:42:51 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=mnxgTC7NsZDqwK5Zx1OTmLr6Ojy3aVlCIvO8%2FeX5imw%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766468571"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=mnxgTC7NsZDqwK5Zx1OTmLr6Ojy3aVlCIvO8%2FeX5imw%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766468571"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:80 · api.alli.io
2025-12-22 10:56
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 10:56:47 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ZtFwibrtjDOl21k9mP8lowwad3IvWmOzqhBlSbVfEho%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766401007"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ZtFwibrtjDOl21k9mP8lowwad3IvWmOzqhBlSbVfEho%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766401007"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:80 · api.alli.io
2025-12-21 10:46
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 10:46:49 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Y9H1BGAPbrY%2B%2BM%2BcUrYuGN5ga1wtBdh%2FJq17Yyt5WJg%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766314009"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Y9H1BGAPbrY%2B%2BM%2BcUrYuGN5ga1wtBdh%2FJq17Yyt5WJg%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766314009"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:443 · api.alli.io
2025-12-21 01:15
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 01:15:10 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=TcoTclZQLr%2FnHdtXtWMLZ1zLrZ88w2%2F23bC3Z6UwKJQ%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766279710"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=TcoTclZQLr%2FnHdtXtWMLZ1zLrZ88w2%2F23bC3Z6UwKJQ%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766279710"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:80 · api.alli.io
2025-12-19 08:50
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Fri, 19 Dec 2025 08:50:32 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=0DcWI%2FCQCcc5I%2F8i7rHn70J1jScNrRtioJc%2FEV2Z2ss%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766134232"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=0DcWI%2FCQCcc5I%2F8i7rHn70J1jScNrRtioJc%2FEV2Z2ss%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766134232"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world
Open service 99.83.151.71:443 · api.alli.io
2025-12-19 05:41
HTTP/1.1 200 OK
Access-Control-Allow-Headers: Content-Type
Access-Control-Allow-Methods: POST, GET, PUT
Access-Control-Allow-Origin: *
Content-Length: 11
Content-Type: text/html; charset=utf-8
Date: Fri, 19 Dec 2025 05:41:38 GMT
Etag: W/"b-Kq5sNclPz7QV2+lfQIuc6R7oRu0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=NCoxgFOJSlPa%2BNGANSkJa3fRYljmViEsDhGKH1UGkjk%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766122898"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=NCoxgFOJSlPa%2BNGANSkJa3fRYljmViEsDhGKH1UGkjk%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766122898"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
hello world