Heroku
tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3bf99de9c1b8656a09272584100645f438dab287c
GraphQL introspection enabled at /graphql Types: 800 (by kind: ENUM: 163, INPUT_OBJECT: 260, OBJECT: 360, SCALAR: 14, UNION: 3) Operations: - Query: Query | fields: accountById, accountConnection, accountMatchingStats, customerById, customerConnection - Mutation: Mutation | fields: createAccount, deleteAccount, mergeAccounts, updateAccount, updateCustomer - Subscription: Subscription | fields: campaignUpdated, finishAddingListItems, listItemAdded, listItemRemoved, startAddingListItems Directives: extends, external, federation__inaccessible, federation__override, federation__tag, key, link, provides, requires, shareable (total: 17)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa378b1fa93375480d19945159a39007b8a62898f6b
GraphQL introspection enabled at /graphql Types: 797 (by kind: ENUM: 162, INPUT_OBJECT: 258, OBJECT: 360, SCALAR: 14, UNION: 3) Operations: - Query: Query | fields: accountById, accountConnection, accountMatchingStats, customerById, customerConnection - Mutation: Mutation | fields: createAccount, deleteAccount, mergeAccounts, updateAccount, updateCustomer - Subscription: Subscription | fields: campaignUpdated, finishAddingListItems, listItemAdded, listItemRemoved, startAddingListItems Directives: extends, external, federation__inaccessible, federation__override, federation__tag, key, link, provides, requires, shareable (total: 17)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa32441e174086a9d787dff3529d0bb7edb47539294
GraphQL introspection enabled at /graphql Types: 773 (by kind: ENUM: 157, INPUT_OBJECT: 252, OBJECT: 347, SCALAR: 14, UNION: 3) Operations: - Query: Query | fields: accountById, accountConnection, accountMatchingStats, customerById, customerConnection - Mutation: Mutation | fields: createAccount, deleteAccount, mergeAccounts, updateAccount, updateCustomer - Subscription: Subscription | fields: campaignUpdated, finishAddingListItems, listItemAdded, listItemRemoved, startAddingListItems Directives: extends, external, federation__inaccessible, federation__override, federation__tag, key, link, provides, requires, shareable (total: 17)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3efb8ccc82a15916c85fdd545bca4df2fc466d7f0
GraphQL introspection enabled at /graphql Types: 761 (by kind: ENUM: 154, INPUT_OBJECT: 247, OBJECT: 343, SCALAR: 14, UNION: 3) Operations: - Query: Query | fields: accountById, accountConnection, accountMatchingStats, customerById, customerConnection - Mutation: Mutation | fields: createAccount, deleteAccount, mergeAccounts, updateAccount, updateCustomer - Subscription: Subscription | fields: campaignUpdated, finishAddingListItems, listItemAdded, listItemRemoved, startAddingListItems Directives: extends, external, federation__inaccessible, federation__override, federation__tag, key, link, provides, requires, shareable (total: 17)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3bf99de9c1b8656a09272584100645f438dab287c
GraphQL introspection enabled at /graphql Types: 800 (by kind: ENUM: 163, INPUT_OBJECT: 260, OBJECT: 360, SCALAR: 14, UNION: 3) Operations: - Query: Query | fields: accountById, accountConnection, accountMatchingStats, customerById, customerConnection - Mutation: Mutation | fields: createAccount, deleteAccount, mergeAccounts, updateAccount, updateCustomer - Subscription: Subscription | fields: campaignUpdated, finishAddingListItems, listItemAdded, listItemRemoved, startAddingListItems Directives: extends, external, federation__inaccessible, federation__override, federation__tag, key, link, provides, requires, shareable (total: 17)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa378b1fa93375480d19945159a39007b8a62898f6b
GraphQL introspection enabled at /graphql Types: 797 (by kind: ENUM: 162, INPUT_OBJECT: 258, OBJECT: 360, SCALAR: 14, UNION: 3) Operations: - Query: Query | fields: accountById, accountConnection, accountMatchingStats, customerById, customerConnection - Mutation: Mutation | fields: createAccount, deleteAccount, mergeAccounts, updateAccount, updateCustomer - Subscription: Subscription | fields: campaignUpdated, finishAddingListItems, listItemAdded, listItemRemoved, startAddingListItems Directives: extends, external, federation__inaccessible, federation__override, federation__tag, key, link, provides, requires, shareable (total: 17)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa32441e174086a9d787dff3529d0bb7edb47539294
GraphQL introspection enabled at /graphql Types: 773 (by kind: ENUM: 157, INPUT_OBJECT: 252, OBJECT: 347, SCALAR: 14, UNION: 3) Operations: - Query: Query | fields: accountById, accountConnection, accountMatchingStats, customerById, customerConnection - Mutation: Mutation | fields: createAccount, deleteAccount, mergeAccounts, updateAccount, updateCustomer - Subscription: Subscription | fields: campaignUpdated, finishAddingListItems, listItemAdded, listItemRemoved, startAddingListItems Directives: extends, external, federation__inaccessible, federation__override, federation__tag, key, link, provides, requires, shareable (total: 17)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3efb8ccc82a15916c85fdd545bca4df2fc466d7f0
GraphQL introspection enabled at /graphql Types: 761 (by kind: ENUM: 154, INPUT_OBJECT: 247, OBJECT: 343, SCALAR: 14, UNION: 3) Operations: - Query: Query | fields: accountById, accountConnection, accountMatchingStats, customerById, customerConnection - Mutation: Mutation | fields: createAccount, deleteAccount, mergeAccounts, updateAccount, updateCustomer - Subscription: Subscription | fields: campaignUpdated, finishAddingListItems, listItemAdded, listItemRemoved, startAddingListItems Directives: extends, external, federation__inaccessible, federation__override, federation__tag, key, link, provides, requires, shareable (total: 17)
Open service 172.217.208.121:443 · commercial-api.credplatform.com
2026-01-09 18:05
HTTP/1.1 200 OK
x-powered-by: Express
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"48-YHuaGzhNcXjKFSYidMm9gXGkwfs"
x-cloud-trace-context: 15d3f40f2cd13d2842d7e23c05b8cfbe
date: Fri, 09 Jan 2026 18:05:52 GMT
server: Google Frontend
Content-Length: 72
Connection: close
{"data":"Hello world! You can access the GraphQL endpoint at /graphql."}
Open service 75.2.60.68:80 · commercial-api.credplatform.com
2026-01-08 19:05
HTTP/1.1 503 Service Unavailable
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=0uif9xWtC4%2B2FmtUgw3BgwMTYBnmCV211dItqG7jRgY%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767899196"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=0uif9xWtC4%2B2FmtUgw3BgwMTYBnmCV211dItqG7jRgY%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767899196"
Server: Heroku
Via: 1.1 heroku-router
Date: Thu, 08 Jan 2026 19:06:36 GMT
Content-Length: 567
Connection: close
Page title: Application Error
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>Application Error</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="https://www.herokucdn.com/error-pages/application-error.html"></iframe>
</body>
</html>
Open service 172.217.208.121:443 · commercial-api.credplatform.com
2026-01-02 22:31
HTTP/1.1 200 OK
x-powered-by: Express
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"48-YHuaGzhNcXjKFSYidMm9gXGkwfs"
x-cloud-trace-context: 688a82b5bc9b5d1a0c50cc3e0a0f7c6f;o=1
date: Fri, 02 Jan 2026 22:31:24 GMT
server: Google Frontend
Content-Length: 72
Connection: close
{"data":"Hello world! You can access the GraphQL endpoint at /graphql."}
Open service 75.2.60.68:80 · commercial-api.credplatform.com
2026-01-01 19:57
HTTP/1.1 503 Service Unavailable
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=LSrlLCbUa43zSZRV7kHQsDVppAXhjZbU2%2BXyy1a7hn4%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767297469"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=LSrlLCbUa43zSZRV7kHQsDVppAXhjZbU2%2BXyy1a7hn4%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767297469"
Server: Heroku
Via: 1.1 heroku-router
Date: Thu, 01 Jan 2026 19:57:49 GMT
Content-Length: 567
Connection: close
Page title: Application Error
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>Application Error</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="https://www.herokucdn.com/error-pages/application-error.html"></iframe>
</body>
</html>
Open service 75.2.60.68:80 · commercial-api.credplatform.com
2025-12-30 04:05
HTTP/1.1 503 Service Unavailable
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=zFzAxNAqLGz%2Bl%2BNopAQYoPu7nD%2FcHsN%2FiGNLPKfswJU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767067544"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=zFzAxNAqLGz%2Bl%2BNopAQYoPu7nD%2FcHsN%2FiGNLPKfswJU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767067544"
Server: Heroku
Via: 1.1 heroku-router
Date: Tue, 30 Dec 2025 04:05:44 GMT
Content-Length: 567
Connection: close
Page title: Application Error
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>Application Error</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="https://www.herokucdn.com/error-pages/application-error.html"></iframe>
</body>
</html>
Open service 172.217.208.121:443 · commercial-api.credplatform.com
2025-12-23 01:12
HTTP/1.1 200 OK
x-powered-by: Express
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"48-YHuaGzhNcXjKFSYidMm9gXGkwfs"
x-cloud-trace-context: b25a5badeafb3571a3fa1eb92e385d1d
date: Tue, 23 Dec 2025 01:12:03 GMT
server: Google Frontend
Content-Length: 72
Connection: close
{"data":"Hello world! You can access the GraphQL endpoint at /graphql."}
Open service 75.2.60.68:80 · commercial-api.credplatform.com
2025-12-22 04:50
HTTP/1.1 503 Service Unavailable
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=R1pawJmFiDINeFifkD2E5GQrMK%2B%2BoQA6rU4G0xHvxBw%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766379014"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=R1pawJmFiDINeFifkD2E5GQrMK%2B%2BoQA6rU4G0xHvxBw%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766379014"
Server: Heroku
Via: 1.1 heroku-router
Date: Mon, 22 Dec 2025 04:50:14 GMT
Content-Length: 567
Connection: close
Page title: Application Error
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>Application Error</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="https://www.herokucdn.com/error-pages/application-error.html"></iframe>
</body>
</html>
Open service 172.217.208.121:443 · commercial-api.credplatform.com
2025-12-21 09:16
HTTP/1.1 200 OK
x-powered-by: Express
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"48-YHuaGzhNcXjKFSYidMm9gXGkwfs"
x-cloud-trace-context: 1fd271c6cf19936b0c3d01cffe14636f
date: Sun, 21 Dec 2025 09:16:29 GMT
server: Google Frontend
Content-Length: 72
Connection: close
{"data":"Hello world! You can access the GraphQL endpoint at /graphql."}
Open service 75.2.60.68:80 · commercial-api.credplatform.com
2025-12-20 04:47
HTTP/1.1 503 Service Unavailable
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=SDWTHmLuKtFIgGIVMPJvkxM0DbedXHX6rNyW0Us%2BZyQ%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766206069"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=SDWTHmLuKtFIgGIVMPJvkxM0DbedXHX6rNyW0Us%2BZyQ%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766206069"
Server: Heroku
Via: 1.1 heroku-router
Date: Sat, 20 Dec 2025 04:47:49 GMT
Content-Length: 567
Connection: close
Page title: Application Error
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>Application Error</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="https://www.herokucdn.com/error-pages/application-error.html"></iframe>
</body>
</html>
Open service 172.217.208.121:443 · commercial-api.credplatform.com
2025-12-19 02:17
HTTP/1.1 200 OK
x-powered-by: Express
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"48-YHuaGzhNcXjKFSYidMm9gXGkwfs"
x-cloud-trace-context: 10cf8000b1152ac4919a18ba7215e5b5;o=1
date: Fri, 19 Dec 2025 02:17:01 GMT
server: Google Frontend
Content-Length: 72
Connection: close
{"data":"Hello world! You can access the GraphQL endpoint at /graphql."}