Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3610fd47530f94f77de1d8a433e4b64c2ca6072d2
GraphQL introspection enabled at /graphql Types: 290 (by kind: ENUM: 2, INPUT_OBJECT: 59, INTERFACE: 1, OBJECT: 217, SCALAR: 8, UNION: 3) Operations: - Query: Query | fields: address, addresses, adminDashboard, areaSubscription, areaSubscriptions - Mutation: Mutation | fields: addOrderBillingAddress, authGmail, cloneOrder, closeLead, createAddress Directives: deprecated, include, skip (total: 3)
Open service 76.223.57.73:443 · api.containeralliance.com
2026-01-11 03:27
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: application/json; charset=utf-8
Etag: W/"f79a0e6fe9e6c0b80d8903776f06ef0d"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=h2rx3Pmw7dcJyvuQLwgQ3AqaVurgyl62%2BKdwoFjPYcw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768102082"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=h2rx3Pmw7dcJyvuQLwgQ3AqaVurgyl62%2BKdwoFjPYcw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768102082"
Server: Heroku
Set-Cookie: ahoy_track=true; path=/; SameSite=Lax; secure
Set-Cookie: ahoy_visitor=cec4ea0a-5484-4cdb-a7c9-c7dde8d0ad68; path=/; expires=Tue, 11 Jan 2028 03:28:02 GMT; SameSite=Lax; secure
Set-Cookie: ahoy_visit=46db97e1-5ecc-422f-a030-32e25d061987; path=/; expires=Sun, 11 Jan 2026 07:28:02 GMT; SameSite=Lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: ccb6a74d-d47f-bac3-5472-e6918999fd82
X-Runtime: 0.007987
X-Xss-Protection: 1; mode=block
Date: Sun, 11 Jan 2026 03:28:02 GMT
Content-Length: 35
Connection: close
{"time":"2026-01-11T03:28:02.617Z"}
Open service 3.33.241.96:80 · api.containeralliance.com
2026-01-11 03:27
HTTP/1.1 301 Moved Permanently
Content-Type: text/html
Location: https://api.containeralliance.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=SH0tXRUO9l6i0Fc5LKDcSWp56fHV0eBZ5TMItGN2iUU%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768102142"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=SH0tXRUO9l6i0Fc5LKDcSWp56fHV0eBZ5TMItGN2iUU%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768102142"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
Date: Sun, 11 Jan 2026 03:29:02 GMT
Content-Length: 0
Connection: close
Open service 15.197.149.68:443 · api.containeralliance.com
2026-01-11 03:27
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: application/json; charset=utf-8
Etag: W/"072bfd899726e69c2b17f6c4c1e277aa"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=h2rx3Pmw7dcJyvuQLwgQ3AqaVurgyl62%2BKdwoFjPYcw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768102082"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=h2rx3Pmw7dcJyvuQLwgQ3AqaVurgyl62%2BKdwoFjPYcw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768102082"
Server: Heroku
Set-Cookie: ahoy_track=true; path=/; SameSite=Lax; secure
Set-Cookie: ahoy_visitor=c14c42a3-08fd-4585-938e-63da5fb62691; path=/; expires=Tue, 11 Jan 2028 03:28:02 GMT; SameSite=Lax; secure
Set-Cookie: ahoy_visit=c7e55cae-2390-47d0-a0b3-4b431838cce0; path=/; expires=Sun, 11 Jan 2026 07:28:02 GMT; SameSite=Lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 815d5ecd-0454-cd18-43e8-bad20160fff5
X-Runtime: 0.005697
X-Xss-Protection: 1; mode=block
Date: Sun, 11 Jan 2026 03:28:02 GMT
Content-Length: 35
Connection: close
{"time":"2026-01-11T03:28:02.103Z"}
Open service 15.197.149.68:80 · api.containeralliance.com
2026-01-11 03:27
HTTP/1.1 301 Moved Permanently
Content-Type: text/html
Location: https://api.containeralliance.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=10eCUYt5uj52CIDPoSn57EaVUEfNc7vjvCgKWaDQRaI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768102143"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=10eCUYt5uj52CIDPoSn57EaVUEfNc7vjvCgKWaDQRaI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768102143"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
Date: Sun, 11 Jan 2026 03:29:03 GMT
Content-Length: 0
Connection: close
Open service 13.248.213.92:443 · api.containeralliance.com
2026-01-11 03:27
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: application/json; charset=utf-8
Etag: W/"7cd74ec18f779cb9d7303dceea48c16c"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=h2rx3Pmw7dcJyvuQLwgQ3AqaVurgyl62%2BKdwoFjPYcw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768102082"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=h2rx3Pmw7dcJyvuQLwgQ3AqaVurgyl62%2BKdwoFjPYcw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768102082"
Server: Heroku
Set-Cookie: ahoy_track=true; path=/; SameSite=Lax; secure
Set-Cookie: ahoy_visitor=fc64b71f-ace4-4c10-b108-1dc38c805183; path=/; expires=Tue, 11 Jan 2028 03:28:02 GMT; SameSite=Lax; secure
Set-Cookie: ahoy_visit=efea0895-1172-4d2b-b969-859062927915; path=/; expires=Sun, 11 Jan 2026 07:28:02 GMT; SameSite=Lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 26bc287b-14b3-40c9-c756-6b54b056900d
X-Runtime: 0.006429
X-Xss-Protection: 1; mode=block
Date: Sun, 11 Jan 2026 03:28:02 GMT
Content-Length: 35
Connection: close
{"time":"2026-01-11T03:28:02.310Z"}
Open service 3.33.241.96:443 · api.containeralliance.com
2026-01-11 03:27
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: application/json; charset=utf-8
Etag: W/"ec6ae2c09b43accbf1d54f25a8f351b9"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=h2rx3Pmw7dcJyvuQLwgQ3AqaVurgyl62%2BKdwoFjPYcw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768102082"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=h2rx3Pmw7dcJyvuQLwgQ3AqaVurgyl62%2BKdwoFjPYcw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768102082"
Server: Heroku
Set-Cookie: ahoy_track=true; path=/; SameSite=Lax; secure
Set-Cookie: ahoy_visitor=2be81527-d606-4210-8335-dab300a1c726; path=/; expires=Tue, 11 Jan 2028 03:28:02 GMT; SameSite=Lax; secure
Set-Cookie: ahoy_visit=a429f39e-07cf-4b92-a7da-74ac4d1838fd; path=/; expires=Sun, 11 Jan 2026 07:28:02 GMT; SameSite=Lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 3db290d6-cd59-3f18-f36e-f8a8b7bb1713
X-Runtime: 0.005266
X-Xss-Protection: 1; mode=block
Date: Sun, 11 Jan 2026 03:28:02 GMT
Content-Length: 35
Connection: close
{"time":"2026-01-11T03:28:02.187Z"}
Open service 13.248.213.92:80 · api.containeralliance.com
2026-01-11 03:27
HTTP/1.1 301 Moved Permanently
Content-Type: text/html
Location: https://api.containeralliance.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=10eCUYt5uj52CIDPoSn57EaVUEfNc7vjvCgKWaDQRaI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768102143"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=10eCUYt5uj52CIDPoSn57EaVUEfNc7vjvCgKWaDQRaI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768102143"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
Date: Sun, 11 Jan 2026 03:29:03 GMT
Content-Length: 0
Connection: close
Open service 76.223.57.73:80 · api.containeralliance.com
2026-01-11 03:27
HTTP/1.1 301 Moved Permanently
Content-Type: text/html
Location: https://api.containeralliance.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=10eCUYt5uj52CIDPoSn57EaVUEfNc7vjvCgKWaDQRaI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768102143"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=10eCUYt5uj52CIDPoSn57EaVUEfNc7vjvCgKWaDQRaI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768102143"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
Date: Sun, 11 Jan 2026 03:29:03 GMT
Content-Length: 0
Connection: close
Open service 3.33.241.96:443 · api.containeralliance.com
2026-01-09 14:38
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: application/json; charset=utf-8
Etag: W/"07f2dcff22d1c74e348b7c22e3624488"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=obbFSzVvItkTp5weZuNGAZpFbzj3Tn%2Bo22IYPzoxqeU%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767969525"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=obbFSzVvItkTp5weZuNGAZpFbzj3Tn%2Bo22IYPzoxqeU%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767969525"
Server: Heroku
Set-Cookie: ahoy_track=true; path=/; SameSite=Lax; secure
Set-Cookie: ahoy_visitor=20fca331-d0fc-4e3a-856b-7b728123764f; path=/; expires=Sun, 09 Jan 2028 14:38:45 GMT; SameSite=Lax; secure
Set-Cookie: ahoy_visit=ac7d9db9-119d-4dae-9aed-0c229841892c; path=/; expires=Fri, 09 Jan 2026 18:38:45 GMT; SameSite=Lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: a392b51f-8d23-2357-9b90-2fa706565edf
X-Runtime: 0.007069
X-Xss-Protection: 1; mode=block
Date: Fri, 09 Jan 2026 14:38:45 GMT
Content-Length: 35
Connection: close
{"time":"2026-01-09T14:38:45.761Z"}
Open service 3.33.241.96:443 · api.containeralliance.com
2026-01-02 14:56
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: application/json; charset=utf-8
Etag: W/"dd71dfcd0df60d9cdb3dbe0eface4f85"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FK%2B1YkQE8WhT6%2F%2BquHxFrPs8GRMq7i9H%2FXr3P%2B73rhI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767365763"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FK%2B1YkQE8WhT6%2F%2BquHxFrPs8GRMq7i9H%2FXr3P%2B73rhI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767365763"
Server: Heroku
Set-Cookie: ahoy_track=true; path=/; SameSite=Lax; secure
Set-Cookie: ahoy_visitor=6b50cc3a-42b7-4cf0-b103-4c704ea58e4e; path=/; expires=Sun, 02 Jan 2028 14:56:03 GMT; SameSite=Lax; secure
Set-Cookie: ahoy_visit=764ecafe-acaf-4251-846f-252926261b7e; path=/; expires=Fri, 02 Jan 2026 18:56:03 GMT; SameSite=Lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: a0bcd589-e486-2e22-01e5-268fdc303589
X-Runtime: 0.006204
X-Xss-Protection: 1; mode=block
Date: Fri, 02 Jan 2026 14:56:03 GMT
Content-Length: 35
Connection: close
{"time":"2026-01-02T14:56:03.567Z"}
Open service 3.33.241.96:443 · api.containeralliance.com
2025-12-23 05:42
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: application/json; charset=utf-8
Etag: W/"bd828e5463c297ac434ce9b0dd2ccb3a"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7vmFpsWcz%2B%2FEfybke8Cy9nTjHPDiMO0JXMfHZRcG6r0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766468525"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7vmFpsWcz%2B%2FEfybke8Cy9nTjHPDiMO0JXMfHZRcG6r0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766468525"
Server: Heroku
Set-Cookie: ahoy_track=true; path=/; SameSite=Lax; secure
Set-Cookie: ahoy_visitor=ab5c6e71-214a-4d42-8f69-a7bc0327bac6; path=/; expires=Thu, 23 Dec 2027 05:42:05 GMT; SameSite=Lax; secure
Set-Cookie: ahoy_visit=e5efd909-2207-4ef6-9f1f-c10befd475aa; path=/; expires=Tue, 23 Dec 2025 09:42:05 GMT; SameSite=Lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0c621b8b-55a5-e802-ee64-5fef6a98376d
X-Runtime: 0.033321
X-Xss-Protection: 1; mode=block
Date: Tue, 23 Dec 2025 05:42:05 GMT
Content-Length: 35
Connection: close
{"time":"2025-12-23T05:42:05.827Z"}
Open service 3.33.241.96:443 · api.containeralliance.com
2025-12-20 14:00
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: application/json; charset=utf-8
Etag: W/"8f5f7ea7162b378720153b30fdd8a3de"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=A4wQG1y8lqgAnxXmEYlPiY0p2cSoZcaJMQU%2BhdtzwnY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766239225"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=A4wQG1y8lqgAnxXmEYlPiY0p2cSoZcaJMQU%2BhdtzwnY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766239225"
Server: Heroku
Set-Cookie: ahoy_track=true; path=/; SameSite=Lax; secure
Set-Cookie: ahoy_visitor=59b5669e-ca8b-4fcd-a1d0-c7ac75f5b64c; path=/; expires=Mon, 20 Dec 2027 14:00:25 GMT; SameSite=Lax; secure
Set-Cookie: ahoy_visit=d49956a2-d1c4-407a-9ba9-f9ee16ce70d9; path=/; expires=Sat, 20 Dec 2025 18:00:25 GMT; SameSite=Lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 25ce02a8-2283-5046-f4f8-73f934a3679c
X-Runtime: 0.035644
X-Xss-Protection: 1; mode=block
Date: Sat, 20 Dec 2025 14:00:25 GMT
Content-Length: 35
Connection: close
{"time":"2025-12-20T14:00:25.135Z"}