Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 51.104.28.88:443 · api.tradelo.com
2026-01-22 18:56
HTTP/1.1 200 OK
Content-Length: 15
Connection: close
Content-Type: application/json; charset=utf-8
Date: Thu, 22 Jan 2026 18:56:45 GMT
Set-Cookie: ARRAffinity=803e132ccfbdbe0eec34210845cbd51cde1b6b7a8f7ff60935a4da01dfc38328;Path=/;HttpOnly;Secure;Domain=api.tradelo.com
Set-Cookie: ARRAffinitySameSite=803e132ccfbdbe0eec34210845cbd51cde1b6b7a8f7ff60935a4da01dfc38328;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.tradelo.com
{"status":"OK"}
Open service 51.104.28.88:443 · api.tradelo.com
2026-01-09 04:31
HTTP/1.1 200 OK
Content-Length: 15
Connection: close
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 04:32:11 GMT
Set-Cookie: ARRAffinity=803e132ccfbdbe0eec34210845cbd51cde1b6b7a8f7ff60935a4da01dfc38328;Path=/;HttpOnly;Secure;Domain=api.tradelo.com
Set-Cookie: ARRAffinitySameSite=803e132ccfbdbe0eec34210845cbd51cde1b6b7a8f7ff60935a4da01dfc38328;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.tradelo.com
{"status":"OK"}
Open service 51.104.28.88:443 · api.tradelo.com
2026-01-02 05:18
HTTP/1.1 200 OK
Content-Length: 15
Connection: close
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 05:18:26 GMT
Set-Cookie: ARRAffinity=803e132ccfbdbe0eec34210845cbd51cde1b6b7a8f7ff60935a4da01dfc38328;Path=/;HttpOnly;Secure;Domain=api.tradelo.com
Set-Cookie: ARRAffinitySameSite=803e132ccfbdbe0eec34210845cbd51cde1b6b7a8f7ff60935a4da01dfc38328;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.tradelo.com
{"status":"OK"}
Open service 51.104.28.88:443 · api.tradelo.com
2025-12-22 16:03
HTTP/1.1 503 Service Unavailable Connection: close Date: Mon, 22 Dec 2025 16:03:42 GMT Set-Cookie: ARRAffinity=803e132ccfbdbe0eec34210845cbd51cde1b6b7a8f7ff60935a4da01dfc38328;Path=/;HttpOnly;Secure;Domain=api.tradelo.com Set-Cookie: ARRAffinitySameSite=803e132ccfbdbe0eec34210845cbd51cde1b6b7a8f7ff60935a4da01dfc38328;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.tradelo.com Transfer-Encoding: chunked <div style="display: block; margin: auto; width: 600px; height: 500px; text-align: center; font-family: 'Courier', cursive, sans-serif;"><h1 style="color: 747474">:( Application Error</h1><p style="color:#666">If you are the application administrator, you can access the <a style="color: grey"href="https://tradelo-srm-api-prod.scm.azurewebsites.net/detectors">diagnostic resources</a>.</div>