Apache
tcp/80
Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c8329733f8329733f93b77d9b240ac757bb18cb8317310bd8
Found 10 files trough .DS_Store spidering: /404.html /422.html /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Severity: low
Fingerprint: 5f32cf5d6962f09cec7f8772ec7f8772159855a0eb5bbe5662f82d32553b6d83
Found 11 files trough .DS_Store spidering: /404.html /422.html /assets /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Open service 76.223.57.73:443 · app.lovebaxter.com
2026-01-09 00:54
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.lovebaxter.com/search-vendors
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=0IyiVM%2BxDE7wWPvdu8O%2BlpVyvTRComK9sdCWfy%2FDZ%2B0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767920063"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=0IyiVM%2BxDE7wWPvdu8O%2BlpVyvTRComK9sdCWfy%2FDZ%2B0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767920063"
Server: Heroku
Set-Cookie: logged_in=false; path=/; samesite=lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 773ca0ad-349a-9390-8c6a-fe32974cd565
X-Runtime: 0.022922
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 00:54:23 GMT
Connection: close
Open service 76.223.57.73:443 · app.lovebaxter.com
2026-01-01 23:46
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.lovebaxter.com/search-vendors
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=whld41RKQ87S3d%2BPJhvu65EnSjKbe5dZHNvxjpg4R1s%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767311165"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=whld41RKQ87S3d%2BPJhvu65EnSjKbe5dZHNvxjpg4R1s%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767311165"
Server: Heroku
Set-Cookie: logged_in=false; path=/; samesite=lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 36fc2187-7240-452f-ea27-97e82399c0c8
X-Runtime: 0.021580
X-Xss-Protection: 0
Date: Thu, 01 Jan 2026 23:46:05 GMT
Connection: close
Open service 76.223.57.73:443 · app.lovebaxter.com
2025-12-30 10:31
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.lovebaxter.com/search-vendors
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=jQ1khnyGp0Sy0uGKvO0%2BUYbldxvmMr%2FO9GBIXdRS25M%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767090688"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=jQ1khnyGp0Sy0uGKvO0%2BUYbldxvmMr%2FO9GBIXdRS25M%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767090688"
Server: Heroku
Set-Cookie: logged_in=false; path=/; samesite=lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: f851da91-d487-8286-9467-9dab60fe288a
X-Runtime: 0.029319
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 10:31:28 GMT
Connection: close
Open service 76.223.57.73:443 · app.lovebaxter.com
2025-12-22 09:16
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.lovebaxter.com/search-vendors
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=E1kxfnv946XTzRZfnY5TrTTPQiy61LyEqIvKea37twI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766395011"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=E1kxfnv946XTzRZfnY5TrTTPQiy61LyEqIvKea37twI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766395011"
Server: Heroku
Set-Cookie: logged_in=false; path=/; samesite=lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 255ac491-8ab0-51b8-eef5-ec944bfae2cc
X-Runtime: 0.019997
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 09:16:51 GMT
Connection: close
Open service 66.147.237.98:80 · app.lovebaxter.com
2025-12-20 21:48
HTTP/1.1 301 Moved Permanently Date: Sat, 20 Dec 2025 21:48:18 GMT Server: Apache Location: https://app.lovebaxter.com/ Cache-Control: max-age=2592000 Expires: Mon, 19 Jan 2026 21:48:18 GMT Content-Length: 275 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://app.lovebaxter.com/">here</a>.</p> </body></html>
Open service 76.223.57.73:443 · app.lovebaxter.com
2025-12-20 09:07
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.lovebaxter.com/search-vendors
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=QON1RmmJ4XYGHXRrDFO5BmicOEpwp7Fcce3ZOsD%2BUBw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766221634"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=QON1RmmJ4XYGHXRrDFO5BmicOEpwp7Fcce3ZOsD%2BUBw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766221634"
Server: Heroku
Set-Cookie: logged_in=false; path=/; samesite=lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: e78ed0ad-2e5d-cc61-8436-97d315e061f1
X-Runtime: 0.016703
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 09:07:14 GMT
Connection: close