Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6337f81ddfb44bbbff4052f83f0869d5c72935c76
GraphQL introspection enabled at /api/graphql Types: 229 (by kind: ENUM: 22, INPUT_OBJECT: 97, OBJECT: 103, SCALAR: 7) Operations: - Query: RootQueryType | fields: calculateSalesTax, createHyperPayee, currentUser, dashboardStats, deactivateReseller - Mutation: RootMutationType | fields: activateUser, adminResetPassword, adminSetNoticeSet, approveOrder, attachPaymentMethod Directives: deprecated, include, skip, specifiedBy (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6337f81ddfb44bbbff4052f83f0869d5c72935c76
GraphQL introspection enabled at /api/graphql Types: 229 (by kind: ENUM: 22, INPUT_OBJECT: 97, OBJECT: 103, SCALAR: 7) Operations: - Query: RootQueryType | fields: calculateSalesTax, createHyperPayee, currentUser, dashboardStats, deactivateReseller - Mutation: RootMutationType | fields: activateUser, adminResetPassword, adminSetNoticeSet, approveOrder, attachPaymentMethod Directives: deprecated, include, skip, specifiedBy (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6299892012313a383517c7ab709c6ea68248a64ba
GraphQL introspection enabled at /api/graphql Types: 228 (by kind: ENUM: 21, INPUT_OBJECT: 96, OBJECT: 104, SCALAR: 7) Operations: - Query: RootQueryType | fields: calculateSalesTax, createHyperPayee, currentUser, dashboardStats, deactivateReseller - Mutation: RootMutationType | fields: activateUser, adminResetPassword, adminSetNoticeSet, approveOrder, attachPaymentMethod Directives: deprecated, include, skip, specifiedBy (total: 4)
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c3c1fc5e93c1fc5e94a7e0559c4452905964d48be2b6d63f2
Found 5 files trough .DS_Store spidering: /css /favicon.ico /images /index.html /js
Open service 35.71.179.82:443 · develop-api.arkamix.com
2026-01-10 01:21
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Sat, 10 Jan 2026 01:21:20 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FBjLplrb18mik2TADGH8DNef%2Bw9Cq0KMbjgyJ%2BRU81I%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768008081"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FBjLplrb18mik2TADGH8DNef%2Bw9Cq0KMbjgyJ%2BRU81I%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768008081"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: e4b2ad5e-8657-eb91-fae9-06a8b5513088
Connection: close
Not found
Open service 35.71.179.82:443 · stage-api.arkamix.com
2026-01-09 20:28
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 20:28:55 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xwkWKYT%2Fh9NsGDnrwMhNVbos%2BkVHThxk0dHLLeVLdIk%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767990535"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xwkWKYT%2Fh9NsGDnrwMhNVbos%2BkVHThxk0dHLLeVLdIk%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767990535"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 44c0666d-c544-3fc6-e3cb-1e6533615edf
Connection: close
Not found
Open service 13.248.244.96:443 · api.arkamix.com
2026-01-09 09:19
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 09:19:32 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2F%2Fh3F57KVu3LI1Yjh5Al2ScyDr%2Fpve5%2BIhv6EVX%2Bq20%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767950372"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2F%2Fh3F57KVu3LI1Yjh5Al2ScyDr%2Fpve5%2BIhv6EVX%2Bq20%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767950372"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: cd0a3ba0-53e4-88cc-af98-0131fafd97f8
Connection: close
Not found
Open service 35.71.179.82:443 · develop-api.arkamix.com
2026-01-03 00:56
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Sat, 03 Jan 2026 00:56:42 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=iP%2BUT9ChzZeCYwOVzqM7dnMwg9YFbQhCWX%2B%2BMuXCdOA%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767401802"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=iP%2BUT9ChzZeCYwOVzqM7dnMwg9YFbQhCWX%2B%2BMuXCdOA%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767401802"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 8f6fd1f5-cac9-1061-1868-5bacbaca3ec7
Connection: close
Not found
Open service 35.71.179.82:443 · stage-api.arkamix.com
2026-01-03 00:39
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Sat, 03 Jan 2026 00:39:10 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=byMZJ4er9AjttfYqs3wT8a0l%2BhyuvspvcrtVc1CnOsI%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767400751"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=byMZJ4er9AjttfYqs3wT8a0l%2BhyuvspvcrtVc1CnOsI%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767400751"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 29585a17-af47-26dc-03d9-05780dd82aac
Connection: close
Not found
Open service 13.248.244.96:443 · api.arkamix.com
2026-01-02 16:24
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 16:24:59 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=z7ik1yrUcuP%2F9dSh6YOX5jwXuRNjqa43gw9U0Oy9Tzw%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767371100"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=z7ik1yrUcuP%2F9dSh6YOX5jwXuRNjqa43gw9U0Oy9Tzw%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767371100"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: cf448e9a-5ebd-811f-abf6-2051dbf0be1e
Connection: close
Not found
Open service 35.71.179.82:443 · stage-api.arkamix.com
2025-12-23 08:03
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Tue, 23 Dec 2025 08:03:56 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=9GULoRJc4YNEMWcuQKOulSAnzU47JWXXUE%2BVI%2BJjQkU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766477037"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=9GULoRJc4YNEMWcuQKOulSAnzU47JWXXUE%2BVI%2BJjQkU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766477037"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: a585830a-f147-1552-62b7-9e3424da4c86
Connection: close
Not found
Open service 13.248.244.96:443 · api.arkamix.com
2025-12-23 06:24
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Tue, 23 Dec 2025 06:24:30 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=MXq4bLD3vyglK87Gpbg6KXNL9DwJknD%2B6%2FSvBnU0io0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766471071"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=MXq4bLD3vyglK87Gpbg6KXNL9DwJknD%2B6%2FSvBnU0io0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766471071"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 6bfee0e5-43c2-9b34-9049-c5954a09f8b2
Connection: close
Not found
Open service 35.71.179.82:443 · develop-api.arkamix.com
2025-12-22 23:09
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 23:09:26 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2F3UENXK5uenrrPYjic8ro3pv%2BTAYYYIrwgSLPcJBURc%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766444966"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2F3UENXK5uenrrPYjic8ro3pv%2BTAYYYIrwgSLPcJBURc%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766444966"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 76a63ef6-f8bd-f0ad-ae40-e8b7cc77ac00
Connection: close
Not found
Open service 35.71.179.82:443 · develop-api.arkamix.com
2025-12-21 07:58
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 07:58:42 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=HWDVvUGEb09rFHNTWj3EUGRIRNZOjkvisLRVSJgcwwg%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766303923"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=HWDVvUGEb09rFHNTWj3EUGRIRNZOjkvisLRVSJgcwwg%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766303923"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: b6649621-5589-a5f1-1f12-b223e29afe03
Connection: close
Not found
Open service 13.248.244.96:443 · api.arkamix.com
2025-12-21 06:22
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 06:22:41 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cghgyHT6Mr0HyR8Fcn3qj%2Fe9Ni3lTdATvd9lrUo9JJ8%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766298162"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cghgyHT6Mr0HyR8Fcn3qj%2Fe9Ni3lTdATvd9lrUo9JJ8%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766298162"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 8148e640-2354-192e-271e-7f8483ab6173
Connection: close
Not found
Open service 35.71.179.82:443 · stage-api.arkamix.com
2025-12-21 04:19
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 04:19:22 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=JjEjRbOvCD11l9edNjDoya1JcnqdcVgK4hAQ7X2pwW0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766290763"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=JjEjRbOvCD11l9edNjDoya1JcnqdcVgK4hAQ7X2pwW0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766290763"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 0c18ab83-5c1f-7ec5-4e5e-797fa8a11e61
Connection: close
Not found
Open service 35.71.179.82:443 · develop-api.arkamix.com
2025-12-19 09:47
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Fri, 19 Dec 2025 09:47:39 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2Fbwg%2FAp0zt2nwS%2ByG%2FjKaZBqCA4qwPUfVUrL6%2FD3zCA%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766137659"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2Fbwg%2FAp0zt2nwS%2ByG%2FjKaZBqCA4qwPUfVUrL6%2FD3zCA%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766137659"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: ab8031f6-4db0-43ed-167b-60528ccb52e6
Connection: close
Not found
Open service 13.248.244.96:443 · api.arkamix.com
2025-12-19 08:24
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Fri, 19 Dec 2025 08:24:54 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=jc3DDHxp27yEdw2M1aw7%2BDJNOC48lb6KKrBmE75RyW8%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766132694"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=jc3DDHxp27yEdw2M1aw7%2BDJNOC48lb6KKrBmE75RyW8%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766132694"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: d6bfc021-15aa-a3de-0da8-e6d2b3418901
Connection: close
Not found
Open service 35.71.179.82:443 · stage-api.arkamix.com
2025-12-19 01:55
HTTP/1.1 404 Not Found
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 9
Content-Type: text/html; charset=utf-8
Date: Fri, 19 Dec 2025 01:55:27 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=RFEgvNucMOxEVqHLPr0qUjTIQFZJ%2F8OgIbBh7YtNpU0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766109328"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=RFEgvNucMOxEVqHLPr0qUjTIQFZJ%2F8OgIbBh7YtNpU0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766109328"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 81c1ca89-7f2a-da23-d923-cdf1ee8070b5
Connection: close
Not found