GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa374c2942e74c2942e74c2942e74c2942e74c2942e
GraphQL introspection enabled at /graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384f1b85148b4fa93157b58fcb82c609907f9dba9
GraphQL introspection enabled at /graphql Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3)
Open service 18.217.133.29:443 · current.static.waterworks.com
2026-01-22 23:11
HTTP/1.1 301 Moved Permanently Date: Thu, 22 Jan 2026 23:11:58 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=9f3b24d716881e8c7233d88e70096c70; expires=Fri, 23-Jan-2026 23:11:58 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · current.static.waterworks.com
2026-01-08 19:10
HTTP/1.1 301 Moved Permanently Date: Thu, 08 Jan 2026 19:10:53 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=b195bdc689f537767df2c8d3f3708c4e; expires=Fri, 09-Jan-2026 19:10:53 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains