GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6d5e6ea65d5e6ea65d5e6ea65d5e6ea65d5e6ea65
GraphQL introspection enabled at /api/graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d65cc8bff8bcdb8b1c5b4c9c21ad3516769f2dff36
GraphQL introspection enabled at /api/graphql Types: 612 (by kind: ENUM: 57, INPUT_OBJECT: 154, INTERFACE: 30, OBJECT: 366, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3)
Open service 151.101.131.10:80 · dev.endesaxway.com
2026-01-25 14:56
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Retry-After: 0 Location: https://dev.endesaxway.com/ Accept-Ranges: bytes Date: Sun, 25 Jan 2026 14:56:54 GMT Strict-Transport-Security: max-age=31557600 X-Served-By: cache-sjc10037-SJC X-Cache: HIT X-Timer: S1769353014.248713,VS0,VE47
Open service 151.101.3.10:80 · dev.endesaxway.com
2026-01-25 14:56
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Retry-After: 0 Location: https://dev.endesaxway.com/ Accept-Ranges: bytes Date: Sun, 25 Jan 2026 14:56:54 GMT Strict-Transport-Security: max-age=31557600 X-Served-By: cache-sin-wsss1830097-SIN X-Cache: HIT X-Timer: S1769353014.423549,VS0,VE2
Open service 151.101.3.10:443 · dev.endesaxway.com
2026-01-25 14:56
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 236 strict-transport-security: max-age=63072000; includeSubDomains; preload cache-control: max-age=300 expires: Sun, 25 Jan 2026 15:01:53 GMT content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Sun, 25 Jan 2026 14:56:54 GMT Age: 1 location: https://dev.endesaxway.com/es X-Served-By: cache-sin-wsss1830032-SIN X-Cache: HIT X-Timer: S1769353015.811673,VS0,VS0,VE4 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://dev.endesaxway.com/es">here</a>.</p> </body></html>
Open service 151.101.195.10:80 · dev.endesaxway.com
2026-01-25 14:56
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Retry-After: 0 Location: https://dev.endesaxway.com/ Accept-Ranges: bytes Date: Sun, 25 Jan 2026 14:56:54 GMT Strict-Transport-Security: max-age=31557600 X-Served-By: cache-lga21985-LGA X-Cache: HIT X-Timer: S1769353014.180704,VS0,VE1
Open service 151.101.195.10:443 · dev.endesaxway.com
2026-01-25 14:56
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 236 strict-transport-security: max-age=63072000; includeSubDomains; preload cache-control: max-age=300 expires: Sun, 25 Jan 2026 15:01:53 GMT content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Sun, 25 Jan 2026 14:56:54 GMT Age: 1 location: https://dev.endesaxway.com/es X-Served-By: cache-rtm-ehrd2290049-RTM X-Cache: HIT X-Timer: S1769353014.133639,VS0,VS0,VE3 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://dev.endesaxway.com/es">here</a>.</p> </body></html>
Open service 151.101.67.10:80 · dev.endesaxway.com
2026-01-25 14:56
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Retry-After: 0 Location: https://dev.endesaxway.com/ Accept-Ranges: bytes Date: Sun, 25 Jan 2026 14:56:54 GMT Strict-Transport-Security: max-age=31557600 X-Served-By: cache-lga21979-LGA X-Cache: HIT X-Timer: S1769353014.180406,VS0,VE1
Open service 151.101.131.10:443 · dev.endesaxway.com
2026-01-25 14:56
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 236 strict-transport-security: max-age=63072000; includeSubDomains; preload cache-control: max-age=300 expires: Sun, 25 Jan 2026 15:01:53 GMT content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Sun, 25 Jan 2026 14:56:55 GMT Age: 2 location: https://dev.endesaxway.com/es X-Served-By: cache-lcy-egml8630057-LCY X-Cache: HIT X-Timer: S1769353014.466588,VS0,VS0,VE546 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://dev.endesaxway.com/es">here</a>.</p> </body></html>
Open service 151.101.67.10:443 · dev.endesaxway.com
2026-01-25 14:56
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 236 strict-transport-security: max-age=63072000; includeSubDomains; preload cache-control: max-age=300 expires: Sun, 25 Jan 2026 15:01:54 GMT content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Age: 0 Date: Sun, 25 Jan 2026 14:56:54 GMT set-cookie: affinity="9fdbe2d45d035676"; Path=/; HttpOnly; secure location: https://dev.endesaxway.com/es X-Served-By: cache-fra-eddf8230037-FRA X-Cache: MISS X-Timer: S1769353014.031693,VS0,VS0,VE249 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://dev.endesaxway.com/es">here</a>.</p> </body></html>
Open service 151.101.131.10:443 · dev.endesaxway.com
2026-01-23 11:33
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 236 strict-transport-security: max-age=63072000; includeSubDomains; preload cache-control: max-age=300 expires: Fri, 23 Jan 2026 11:38:19 GMT content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Fri, 23 Jan 2026 11:33:20 GMT Age: 1 location: https://dev.endesaxway.com/es X-Served-By: cache-sin-wsss1830084-SIN X-Cache: HIT X-Timer: S1769168001.525215,VS0,VS0,VE3 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://dev.endesaxway.com/es">here</a>.</p> </body></html>
Open service 151.101.131.10:443 · dev.endesaxway.com
2026-01-09 11:07
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 236 strict-transport-security: max-age=63072000; includeSubDomains; preload cache-control: max-age=300 expires: Fri, 09 Jan 2026 11:12:34 GMT content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Fri, 09 Jan 2026 11:07:36 GMT Age: 2 location: https://dev.endesaxway.com/es X-Served-By: cache-fra-eddf8230033-FRA X-Cache: HIT X-Timer: S1767956856.283224,VS0,VS0,VE2 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://dev.endesaxway.com/es">here</a>.</p> </body></html>
Open service 151.101.131.10:443 · dev.endesaxway.com
2026-01-02 17:22
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 236 strict-transport-security: max-age=63072000; includeSubDomains; preload cache-control: max-age=300 expires: Fri, 02 Jan 2026 17:27:34 GMT content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Fri, 02 Jan 2026 17:22:34 GMT Age: 0 location: https://dev.endesaxway.com/es X-Served-By: cache-fra-eddf8230043-FRA X-Cache: HIT X-Timer: S1767374554.405672,VS0,VS0,VE3 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://dev.endesaxway.com/es">here</a>.</p> </body></html>
Open service 151.101.131.10:443 · dev.endesaxway.com
2025-12-23 09:16
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 236 strict-transport-security: max-age=63072000; includeSubDomains; preload cache-control: max-age=300 expires: Tue, 23 Dec 2025 09:21:05 GMT content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Age: 0 Date: Tue, 23 Dec 2025 09:16:05 GMT set-cookie: affinity="afe53e21511ce759"; Path=/; HttpOnly; secure location: https://dev.endesaxway.com/es X-Served-By: cache-sjc10077-SJC X-Cache: MISS X-Timer: S1766481364.314454,VS0,VS0,VE1164 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="http://dev.endesaxway.com/es">here</a>.</p> </body></html>