heroku-router
tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4b269e82c85a23427b73e9c37465142d18f4bed25b
Public Swagger UI/API detected at path: /v3/api-docs - sample paths: DELETE /api/customer/deleteCustomer DELETE /api/customer/deleteTaskObject DELETE /api/partner/deletePartner DELETE /api/test/clearTables GET /api/partner/getPartnerPackages GET /api/paypal/paymentCancel GET /api/paypal/paymentSuccess GET /api/test/getAll GET /api/test/getNotificationsHistory POST /api/administrator/addPartnerPackage POST /api/administrator/approveUser POST /api/administrator/getAllCustomers POST /api/administrator/getAllPartners POST /api/administrator/getAllReservations POST /api/administrator/getPartnerExtraDetails POST /api/administrator/getPartnerPackages POST /api/administrator/getProblematicReservations POST /api/administrator/messaging/sms/send POST /api/administrator/package/questions/update POST /api/administrator/regions/get POST /api/administrator/removePartnerPackage POST /api/administrator/resolveProblematicReservation POST /api/administrator/searchReservations POST /api/administrator/statistics/systemStatistics POST /api/administrator/store/addServiceProduct POST /api/administrator/store/deleteServiceProduct POST /api/administrator/store/loadProductsItemLists POST /api/administrator/store/services/get POST /api/administrator/store/updateServiceProduct POST /api/administrator/suspendUser POST /api/authorization/administrator/login POST /api/authorization/customer/login POST /api/authorization/partner/login POST /api/customer/addCustomer POST /api/customer/addCustomerExtraDetails POST /api/customer/addTaskObject POST /api/customer/fcmTokenChange POST /api/customer/getAvailablePartners POST /api/customer/getCustomerExtraDetails POST /api/customer/getCustomerReservations POST /api/customer/getPartnerExtraDetails POST /api/customer/getPartnerWorkingHours POST /api/customer/myTaskObjects POST /api/customer/okayNotification POST /api/customer/quarryCity POST /api/customer/submitMissionDoneFeedback POST /api/customer/submitNewReservation POST /api/customer/updateTaskObject POST /api/customer/waitingForYouNotification POST /api/otp/generateOTP POST /api/otp/otpVerify POST /api/partner/activatePackage POST /api/partner/addNewPackage POST /api/partner/addPartner POST /api/partner/addPartnerExtraDetails POST /api/partner/addRegion POST /api/partner/arrivingSoonNotification POST /api/partner/deActivatePackage POST /api/partner/fcmTokenChange POST /api/partner/getCustomerExtraDetails POST /api/partner/getPartnerExtraDetails POST /api/partner/getSchedule POST /api/partner/getWorkingHours POST /api/partner/imHereNotification POST /api/partner/removePackage POST /api/partner/removeRegion POST /api/partner/reservationResponse POST /api/partner/submitMissionDoneFeedback POST /api/partner/updatePackage POST /api/partner/updateWorkingHours POST /api/paypal/createPayment POST /api/resources/upload POST /api/store/customer/getServicesAndProducts POST /api/store/getAllRegions POST /api/store/partner/getServicesAndProducts POST /api/test/createPartnerWithVehicle POST /api/test/createPartners POST /api/test/createReservation POST /api/test/printRequest POST /api/test/sendNotification POST /meshulam/cancel POST /meshulam/cancelTest POST /meshulam/getMeshulamInfo POST /meshulam/success POST /meshulam/successTest POST /meshulam/webhooks/cancel POST /meshulam/webhooks/success POST /wordpress/products/addProduct POST /wordpress/products/deleteProduct POST /wordpress/products/updateProduct
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4b269e82c85a23427b73e9c37465142d18f4bed25b
Public Swagger UI/API detected at path: /v3/api-docs - sample paths: DELETE /api/customer/deleteCustomer DELETE /api/customer/deleteTaskObject DELETE /api/partner/deletePartner DELETE /api/test/clearTables GET /api/partner/getPartnerPackages GET /api/paypal/paymentCancel GET /api/paypal/paymentSuccess GET /api/test/getAll GET /api/test/getNotificationsHistory POST /api/administrator/addPartnerPackage POST /api/administrator/approveUser POST /api/administrator/getAllCustomers POST /api/administrator/getAllPartners POST /api/administrator/getAllReservations POST /api/administrator/getPartnerExtraDetails POST /api/administrator/getPartnerPackages POST /api/administrator/getProblematicReservations POST /api/administrator/messaging/sms/send POST /api/administrator/package/questions/update POST /api/administrator/regions/get POST /api/administrator/removePartnerPackage POST /api/administrator/resolveProblematicReservation POST /api/administrator/searchReservations POST /api/administrator/statistics/systemStatistics POST /api/administrator/store/addServiceProduct POST /api/administrator/store/deleteServiceProduct POST /api/administrator/store/loadProductsItemLists POST /api/administrator/store/services/get POST /api/administrator/store/updateServiceProduct POST /api/administrator/suspendUser POST /api/authorization/administrator/login POST /api/authorization/customer/login POST /api/authorization/partner/login POST /api/customer/addCustomer POST /api/customer/addCustomerExtraDetails POST /api/customer/addTaskObject POST /api/customer/fcmTokenChange POST /api/customer/getAvailablePartners POST /api/customer/getCustomerExtraDetails POST /api/customer/getCustomerReservations POST /api/customer/getPartnerExtraDetails POST /api/customer/getPartnerWorkingHours POST /api/customer/myTaskObjects POST /api/customer/okayNotification POST /api/customer/quarryCity POST /api/customer/submitMissionDoneFeedback POST /api/customer/submitNewReservation POST /api/customer/updateTaskObject POST /api/customer/waitingForYouNotification POST /api/otp/generateOTP POST /api/otp/otpVerify POST /api/partner/activatePackage POST /api/partner/addNewPackage POST /api/partner/addPartner POST /api/partner/addPartnerExtraDetails POST /api/partner/addRegion POST /api/partner/arrivingSoonNotification POST /api/partner/deActivatePackage POST /api/partner/fcmTokenChange POST /api/partner/getCustomerExtraDetails POST /api/partner/getPartnerExtraDetails POST /api/partner/getSchedule POST /api/partner/getWorkingHours POST /api/partner/imHereNotification POST /api/partner/removePackage POST /api/partner/removeRegion POST /api/partner/reservationResponse POST /api/partner/submitMissionDoneFeedback POST /api/partner/updatePackage POST /api/partner/updateWorkingHours POST /api/paypal/createPayment POST /api/resources/upload POST /api/store/customer/getServicesAndProducts POST /api/store/getAllRegions POST /api/store/partner/getServicesAndProducts POST /api/test/createPartnerWithVehicle POST /api/test/createPartners POST /api/test/createReservation POST /api/test/printRequest POST /api/test/sendNotification POST /meshulam/cancel POST /meshulam/cancelTest POST /meshulam/getMeshulamInfo POST /meshulam/success POST /meshulam/successTest POST /meshulam/webhooks/cancel POST /meshulam/webhooks/success POST /wordpress/products/addProduct POST /wordpress/products/deleteProduct POST /wordpress/products/updateProduct
Open service 15.197.253.240:80 · api.wosh.co.il
2026-01-09 03:34
HTTP/1.1 404 Not Found
Content-Length: 548
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Date: 2026-01-09 03:35:23.039910745 +0000 UTC
Server: heroku-router
Page title: No such app
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>No such app</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="//www.herokucdn.com/error-pages/no-such-app.html"></iframe>
</body>
</html>
Open service 15.197.253.240:80 · api.wosh.co.il
2026-01-02 07:03
HTTP/1.1 404 Not Found
Content-Length: 548
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Date: 2026-01-02 07:03:20.836875237 +0000 UTC
Server: heroku-router
Page title: No such app
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>No such app</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="//www.herokucdn.com/error-pages/no-such-app.html"></iframe>
</body>
</html>
Open service 15.197.253.240:80 · api.wosh.co.il
2025-12-22 19:47
HTTP/1.1 404 Not Found
Content-Length: 548
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Date: 2025-12-22 19:47:27.910789906 +0000 UTC
Server: heroku-router
Page title: No such app
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>No such app</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="//www.herokucdn.com/error-pages/no-such-app.html"></iframe>
</body>
</html>
Open service 15.197.253.240:80 · api.wosh.co.il
2025-12-20 23:54
HTTP/1.1 404 Not Found
Content-Length: 548
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Date: 2025-12-20 23:54:29.648865998 +0000 UTC
Server: heroku-router
Page title: No such app
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>No such app</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="//www.herokucdn.com/error-pages/no-such-app.html"></iframe>
</body>
</html>