cloudflare
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652273d5e81a
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true hooksPath = .husky/_ [remote "origin"] url = https://github.com/apolloenergies/ecoaudit-pro-front-end.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main vscode-merge-base = origin/main
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c026392ab026392abfe5e346ebf613bf6637d010da29becce
Found 7 files trough .DS_Store spidering: /carbon-calculator /css /fonts /images /inc /js /videos
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d3ce3d1e33ce3d1e33ce3d1e33ce3d1e3
Found 1 files trough .DS_Store spidering: /prince
Open service 172.66.42.232:443 · portal.apolloenergiesinc.com
2026-01-22 20:20
HTTP/1.1 200 OK
Date: Thu, 22 Jan 2026 20:20:34 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Set-Cookie: PHPSESSID=024qvgp6m9j103h6qbb3ktg0sh; path=/
expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
pragma: no-cache
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=163,cfOrigin;dur=7
vary: accept-encoding
cf-cache-status: DYNAMIC
CF-RAY: 9c21c0b55cf7371b-FRA
alt-svc: h3=":443"; ma=86400
Page title: Apollo Energies TaxFlow Tracker
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Apollo Energies TaxFlow Tracker</title>
<!-- Link to your Windi CSS file - ensure this path is correct for your Vite setup -->
<link rel="stylesheet" href="css/windi-style.css">
<link rel="stylesheet" href="css/style.css">
<!--?php if ($css): ? -->
<!--link rel="stylesheet" href="dist/assets/" -->
<!--?php endif; ? -->
</head>
<body class="min-h-screen flex flex-col text-center items-center justify-center ">
<!-- The tailwind-keep-alive-dummy div is hidden by CSS. -->
<div id="tailwind-keep-alive-dummy" class="hidden space-x-2 pt-2 mr-4 bg-black bg-gray-100 bg-gray-300 bg-green-700 bg-opacity-50 bg-red-500 bg-white ext-3xl fixed flex flex-col font-bold font-medium font-sans font-semibold hidden hover:bg-green-700 inset-0 items-center justify-center max-w-7xl mb-2 mb-3 mb-4 mb-8 mt-6mx-auto my-4 p-4 px-4 py-2 rounded rounded-lg shadow-lg text-center text-gray-800 text-md text-white text-xl z-50"></div>
<div id="mainLogoContainer" >
<img src="/images/AE-Logo-rnd-400.webp" alt="Apollo Energies Logo" class="mx-auto">
</div>
<div style="padding:0;"></div>
<div id="app" class="w-full max-w-7xl mx-auto p-4 bg-white mt-8 ">
<h1 class="text-3xl font-bold text-center mb-4 font-sans">Apollo Energies TaxFlow Tracker</h1>
<h2 class="text-1xl text-center mb-2 font-sans">Client Management Dashboard</h2>
<h3 class="text-md font-medium mb-3 flex items-center justify-center font-sans">Tracking your projects from plan submission to tax credit submission </h3>
<!--div id="authButtons" class="flex justify-center gap-4 mb-8 font-sans">
<button id="showRegister" class="bg-green-600 hover:bg-green-700 text-white px-4 py-2 rounded">Register</button>
<button id="showLogin" class="bg-blue-600 hover:bg-blue-700 text-white px-4 py-2 rounded">Login</button>
</div-->
<!-- Main view -->
<div id="authView">
<div id="authButtons" class="flex text-center justify-center gap-4 mb-8 font-sans">
<button id="showRegister" class="bg-green-600 hover:bg-green-700 text-white px-4 py-2 rounded transform transition-transform duration-300 hover:-translate-y-1">Register</button>
<button id="showLogin" class="bg-blue-600 hover:bg-blue-700 text-white px-4 py-2 rounded transform transition-transform duration-300 hover:-translate-y-1">Login</button>
</div>
</div>
<!-- Register Modal -->
<div id="registerModal" class="hidden fixed inset-0 bg-black bg-opacity-50 flex items-center justify-center z-50">
<div id="registerModalContent" class="bg-white rounded-lg shadow-lg p-6 w-full max-w-lg">
<div class="flex justify-end">
<button id="closeRegisterModal" class="text-gray-600 hover:text-red-500">×</button>
</div>
<h2 class="flex items-center justify-center text-2xl font-semibold mb-4 font-sans">Register for 45L Tax Credits</h2>
<form id="registerForm" class="space-y-4">
<input type="text" name="company_name" id="reg_company_name" placeholder="Company Name" required class="w-full p-2 border rounded">
<input type="text" name="company_address" id="reg_company_address" placeholder="Company Address" required class="w-full p-2 border rounded">
<input type="text" name="first_name" id="reg_first_name" placeholder="First Name" required class="w-full p-2 border rounded">
<input type="text" name="last_name" id="reg_last_name" placeholder="Last Name" required class="w-full p-2 border rounded">
<input type="email" name="email" id="reg_email" placeholder="Email" required class="w-full p-2 border rounded">
<input type="tel" name="phone" id="reg_phone" placeholder="Phone Number" class="w-full p-2 border rounded">
<input type="text" name="username" id="reg_username" placeholder="Username" required class="w-full