Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa355717e3d7841d8df11d846911841d1c067fe96b0
GraphQL introspection enabled at /graphql Types: 101 (by kind: ENUM: 8, INPUT_OBJECT: 35, INTERFACE: 1, OBJECT: 49, SCALAR: 8) Operations: - Query: RootType | fields: admins, bestAudiences, emailAvailable, getUsersById, me - Mutation: Mutations | fields: attendEvent, banUser, changeAvatar, favoriteSpeaker, updateAudienceProfile Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa355717e3d7841d8df11d846911841d1c067fe96b0
GraphQL introspection enabled at /graphql Types: 101 (by kind: ENUM: 8, INPUT_OBJECT: 35, INTERFACE: 1, OBJECT: 49, SCALAR: 8) Operations: - Query: RootType | fields: admins, bestAudiences, emailAvailable, getUsersById, me - Mutation: Mutations | fields: attendEvent, banUser, changeAvatar, favoriteSpeaker, updateAudienceProfile Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 99.83.217.1:443 · api.bookingworldspeakers.com
2026-01-09 22:51
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: X-GraphQL-Operation
Content-Length: 20
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 22:51:14 GMT
Etag: W/"14-aVnUWKnJScp28AXZapvu/6gDzEQ"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=nGGkMOiuAj8gPx7shWCqUIaE4riCZDiFrBvleXt2QqE%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767999074"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=nGGkMOiuAj8gPx7shWCqUIaE4riCZDiFrBvleXt2QqE%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767999074"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Welkom op de BWS API
Open service 75.2.43.161:443 · review.api.bookingworldspeakers.com
2026-01-09 05:55
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: X-GraphQL-Operation
Content-Length: 20
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 05:55:57 GMT
Etag: W/"14-aVnUWKnJScp28AXZapvu/6gDzEQ"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=hlLmerdMEnF5hGT2Z68ZLGZvo%2FcWIGmiXArcH84vttA%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767938157"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=hlLmerdMEnF5hGT2Z68ZLGZvo%2FcWIGmiXArcH84vttA%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767938157"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Welkom op de BWS API
Open service 75.2.43.161:443 · review.api.bookingworldspeakers.com
2026-01-02 10:30
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: X-GraphQL-Operation
Content-Length: 20
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 10:30:07 GMT
Etag: W/"14-aVnUWKnJScp28AXZapvu/6gDzEQ"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=onI4fKBWs45vjCua0f4gCmroHPymltLVZCKLAApoNMk%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767349807"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=onI4fKBWs45vjCua0f4gCmroHPymltLVZCKLAApoNMk%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767349807"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Welkom op de BWS API
Open service 99.83.217.1:443 · api.bookingworldspeakers.com
2025-12-30 12:08
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: X-GraphQL-Operation
Content-Length: 20
Content-Type: text/html; charset=utf-8
Date: Tue, 30 Dec 2025 12:08:56 GMT
Etag: W/"14-aVnUWKnJScp28AXZapvu/6gDzEQ"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dww9jvsE4%2FJghKcEXeYSSzcN95hNj70La2GZkuSBrek%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767096536"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dww9jvsE4%2FJghKcEXeYSSzcN95hNj70La2GZkuSBrek%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767096536"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Welkom op de BWS API
Open service 99.83.217.1:443 · api.bookingworldspeakers.com
2025-12-22 23:20
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: X-GraphQL-Operation
Content-Length: 20
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 23:20:46 GMT
Etag: W/"14-aVnUWKnJScp28AXZapvu/6gDzEQ"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=BNdJKK3PuR2X9gf9BzjprGIGDHZp44sF7cfYlrwYl3o%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766445646"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=BNdJKK3PuR2X9gf9BzjprGIGDHZp44sF7cfYlrwYl3o%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766445646"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Welkom op de BWS API
Open service 75.2.43.161:443 · review.api.bookingworldspeakers.com
2025-12-22 19:17
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: X-GraphQL-Operation
Content-Length: 20
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 19:17:54 GMT
Etag: W/"14-aVnUWKnJScp28AXZapvu/6gDzEQ"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=EXtT4aqKZaUZDng50uf%2BWztU%2FZVXzChSN37Yh1OFV8c%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766431074"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=EXtT4aqKZaUZDng50uf%2BWztU%2FZVXzChSN37Yh1OFV8c%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766431074"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Welkom op de BWS API
Open service 99.83.217.1:443 · api.bookingworldspeakers.com
2025-12-21 01:13
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: X-GraphQL-Operation
Content-Length: 20
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 01:13:19 GMT
Etag: W/"14-aVnUWKnJScp28AXZapvu/6gDzEQ"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=lThqFSSdmF8cJ9m6qEUcxVHsg3hKoR5QplCqKyzutDQ%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766279599"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=lThqFSSdmF8cJ9m6qEUcxVHsg3hKoR5QplCqKyzutDQ%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766279599"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Welkom op de BWS API
Open service 75.2.43.161:443 · review.api.bookingworldspeakers.com
2025-12-20 20:29
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: X-GraphQL-Operation
Content-Length: 20
Content-Type: text/html; charset=utf-8
Date: Sat, 20 Dec 2025 20:29:15 GMT
Etag: W/"14-aVnUWKnJScp28AXZapvu/6gDzEQ"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ThvafEMe3zE%2Bx2Qh%2BU8oufYrnypDplbcloJkWOeJW%2B0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766262555"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ThvafEMe3zE%2Bx2Qh%2BU8oufYrnypDplbcloJkWOeJW%2B0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766262555"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Welkom op de BWS API