Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 99.83.151.71:80 · api.antioxida.com
2026-01-09 20:15
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Content-Length: 15
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 20:16:54 GMT
Etag: W/"f-r++mntI8V8+PvFk9pVKSw5Tgn0w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=tXHVWJYXhi5dUtXdrSybNkNsU0ZfQp4B1xeJqCdk5JU%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767989814"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=tXHVWJYXhi5dUtXdrSybNkNsU0ZfQp4B1xeJqCdk5JU%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767989814"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
REACHED The API
Open service 13.248.132.87:443 · api.antioxida.com
2026-01-09 14:14
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Content-Length: 15
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 14:14:10 GMT
Etag: W/"f-r++mntI8V8+PvFk9pVKSw5Tgn0w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=uqZoBJTK%2BmldoT9K4GCzSCq87z80ewPodAJgdG8dreI%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767968050"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=uqZoBJTK%2BmldoT9K4GCzSCq87z80ewPodAJgdG8dreI%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767968050"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
REACHED The API
Open service 13.248.132.87:443 · api.antioxida.com
2026-01-02 19:18
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Content-Length: 15
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 19:18:40 GMT
Etag: W/"f-r++mntI8V8+PvFk9pVKSw5Tgn0w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7YAoTX2PPwvmIaeNnAzSHQ3dUurdDuNhhTil%2B0h%2FnKU%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767381520"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7YAoTX2PPwvmIaeNnAzSHQ3dUurdDuNhhTil%2B0h%2FnKU%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767381520"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
REACHED The API
Open service 99.83.151.71:80 · api.antioxida.com
2026-01-02 17:54
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Content-Length: 15
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 17:54:22 GMT
Etag: W/"f-r++mntI8V8+PvFk9pVKSw5Tgn0w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=NjhdX6PHztPfR6MzbKi%2FG1fWRhOzvqGkJBIStA7yG0w%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767376462"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=NjhdX6PHztPfR6MzbKi%2FG1fWRhOzvqGkJBIStA7yG0w%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767376462"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
REACHED The API
Open service 13.248.132.87:443 · api.antioxida.com
2025-12-22 21:17
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Content-Length: 15
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 21:17:07 GMT
Etag: W/"f-r++mntI8V8+PvFk9pVKSw5Tgn0w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=5dVbJipFlJ19Nc1yt0EDHN4AvhnbQtTk%2FqP9Bxp18mY%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766438227"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=5dVbJipFlJ19Nc1yt0EDHN4AvhnbQtTk%2FqP9Bxp18mY%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766438227"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
REACHED The API
Open service 99.83.151.71:80 · api.antioxida.com
2025-12-22 19:59
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Content-Length: 15
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 19:59:56 GMT
Etag: W/"f-r++mntI8V8+PvFk9pVKSw5Tgn0w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=AjFSRyhCb0pqLqmiTMiDz8%2Blc4EzU0f3pO7dO57evS4%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766433596"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=AjFSRyhCb0pqLqmiTMiDz8%2Blc4EzU0f3pO7dO57evS4%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766433596"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
REACHED The API
Open service 99.83.151.71:80 · api.antioxida.com
2025-12-21 04:22
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Content-Length: 15
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 04:23:03 GMT
Etag: W/"f-r++mntI8V8+PvFk9pVKSw5Tgn0w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=nQPay6RVOaJAupcL35wDWsQF%2B4xIbMobVu7FJWwhIAg%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766290983"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=nQPay6RVOaJAupcL35wDWsQF%2B4xIbMobVu7FJWwhIAg%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766290983"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
REACHED The API
Open service 99.83.151.71:80 · api.antioxida.com
2025-12-19 04:24
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Content-Length: 15
Content-Type: text/html; charset=utf-8
Date: Fri, 19 Dec 2025 04:24:24 GMT
Etag: W/"f-r++mntI8V8+PvFk9pVKSw5Tgn0w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=WxbMkQLD%2BjzjAPfEpjWZ9GA4mxN8AkohMcqoQTx7v4A%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766118264"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=WxbMkQLD%2BjzjAPfEpjWZ9GA4mxN8AkohMcqoQTx7v4A%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766118264"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
REACHED The API