Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549a5d4ae1653c01ddca5c30e3548d34b5ee948ba94
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /Api/GetCarriers
GET /Api/GetCountries
GET /Api/GetLocales
GET /Api/GetShippingProviderMethods
GET /Api/GetTransaction/{transactionId}
GET /Api/GetTransactionStatus/{transactionId}
GET /Auth/GetAccessToken
POST /Api/CreateSampleDeliveryTransaction
POST /Api/CreateSamplePaymentTransaction
POST /Api/CreateTransaction
POST /Api/SetOrderShipped
Open service 2a00:1450:4001:807::2013:80 · api.ipayon.delivery
2026-02-05 18:43
HTTP/1.1 404 Not Found Content-Length: 272 Content-Type: text/html; charset=UTF-8 Date: Thu, 05 Feb 2026 18:44:20 GMT Connection: close Page title: 404 Page not found <html><head> <meta http-equiv="content-type" content="text/html;charset=utf-8"> <title>404 Page not found</title> </head> <body text=#000000 bgcolor=#ffffff> <h1>Error: Page not found</h1> <h2>The requested URL was not found on this server.</h2> <h2></h2> </body></html>
Open service 142.250.186.147:443 · api.ipayon.delivery
2026-01-23 07:00
HTTP/1.1 404 Not Found Content-Length: 272 Content-Type: text/html; charset=UTF-8 Date: Fri, 23 Jan 2026 07:00:18 GMT Connection: close Page title: 404 Page not found <html><head> <meta http-equiv="content-type" content="text/html;charset=utf-8"> <title>404 Page not found</title> </head> <body text=#000000 bgcolor=#ffffff> <h1>Error: Page not found</h1> <h2>The requested URL was not found on this server.</h2> <h2></h2> </body></html>