Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c8329733f8329733f93b77d9b240ac757bb18cb8317310bd8
Found 10 files trough .DS_Store spidering: /404.html /422.html /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Open service 15.197.149.68:443 · app.performixcollective.com
2026-01-09 23:44
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://performix.tangram.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=zrzbnaWNl%2BVm%2F51l%2BSISJLzhQzxC%2FSNRKjr6nPcWNlo%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768002285"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=zrzbnaWNl%2BVm%2F51l%2BSISJLzhQzxC%2FSNRKjr6nPcWNlo%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768002285"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: aac01019-7f74-78dc-7507-11b2b87dbc2c
X-Runtime: 0.011978
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 23:44:45 GMT
Connection: close
Open service 15.197.149.68:443 · app.performixcollective.com
2026-01-02 21:19
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://performix.tangram.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=8pKjgQLd33HdMbDvIzzqrbqsB9Mj0O2tb6iTZOeuo38%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767388780"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=8pKjgQLd33HdMbDvIzzqrbqsB9Mj0O2tb6iTZOeuo38%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767388780"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 917c7a6c-8548-77e7-e1de-6efac587aa1d
X-Runtime: 0.014975
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 21:19:40 GMT
Connection: close
Open service 15.197.149.68:443 · app.performixcollective.com
2025-12-23 05:00
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://performix.tangram.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Acg6vJJxyZB6cE9MG0CkoyHzW96bj31ccwJviq1mF00%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766466057"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Acg6vJJxyZB6cE9MG0CkoyHzW96bj31ccwJviq1mF00%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766466057"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 773dc72c-2a60-3d87-c1d1-dcc213181cc4
X-Runtime: 0.012587
X-Xss-Protection: 0
Date: Tue, 23 Dec 2025 05:00:57 GMT
Connection: close
Open service 15.197.149.68:443 · app.performixcollective.com
2025-12-21 09:49
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://performix.tangram.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=aDshNqBLpn8RYedrzLXTNBZUhpAuTnlhwysk2biV%2BX0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766310582"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=aDshNqBLpn8RYedrzLXTNBZUhpAuTnlhwysk2biV%2BX0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766310582"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: ca319b01-403e-9c0b-f4e2-8a37606b3531
X-Runtime: 0.012763
X-Xss-Protection: 0
Date: Sun, 21 Dec 2025 09:49:42 GMT
Connection: close
Open service 15.197.149.68:443 · app.performixcollective.com
2025-12-19 00:39
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://performix.tangram.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=kCpeR%2FQMTj5RnxOSUHkFvLgoEG2M6v2mIXIR4p4VAbo%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766104768"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=kCpeR%2FQMTj5RnxOSUHkFvLgoEG2M6v2mIXIR4p4VAbo%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766104768"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: b79b187a-af47-3b5e-85ee-6dea830ce4e2
X-Runtime: 0.009951
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 00:39:28 GMT
Connection: close