Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37a70fc5deae40f3f169d4861cb020f48c3f6c870
GraphQL introspection enabled at /graphql Types: 23 (by kind: ENUM: 3, INPUT_OBJECT: 1, OBJECT: 15, SCALAR: 4) Operations: - Query: Query | fields: allEnhancePages, campaign, enhance_page, experiment - Mutation: Mutation | fields: createEnhancePage Directives: deprecated, include, skip (total: 3)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37a70fc5deae40f3f169d4861cb020f48c3f6c870
GraphQL introspection enabled at /graphql Types: 23 (by kind: ENUM: 3, INPUT_OBJECT: 1, OBJECT: 15, SCALAR: 4) Operations: - Query: Query | fields: allEnhancePages, campaign, enhance_page, experiment - Mutation: Mutation | fields: createEnhancePage Directives: deprecated, include, skip (total: 3)
Open service 151.101.130.132:80 · dev.maker.co
2026-01-10 01:22
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=1vm%2FoFeKKMqT2erTopqMy4KzbphxVkXht4Z0umw6044%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1768008153"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=1vm%2FoFeKKMqT2erTopqMy4KzbphxVkXht4Z0umw6044%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1768008153"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: b4821220-8713-923d-ddbe-fc56465b2bd7
X-Runtime: 0.015346
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Age: 0
Date: Sat, 10 Jan 2026 01:22:33 GMT
X-Served-By: cache-iad-kiad7000038-IAD, cache-fra-eddf8230149-FRA
X-Cache: MISS, MISS
X-Cache-Hits: 0, 0
X-Timer: S1768008154.758488,VS0,VE124
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:443 · dev.maker.co
2026-01-10 00:50
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=FxDn0FGka9tmMPmwwjp56Z4c8beRb8%2Bxcb6qBKSSapU%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1768006255"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=FxDn0FGka9tmMPmwwjp56Z4c8beRb8%2Bxcb6qBKSSapU%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1768006255"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 41221cdb-7740-4428-c7c4-e5b84257ad35
X-Runtime: 0.015035
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Date: Sat, 10 Jan 2026 00:50:55 GMT
Age: 0
X-Served-By: cache-iad-kiad7000038-IAD, cache-lga21949-LGA
X-Cache: MISS, MISS
X-Cache-Hits: 0, 0
X-Timer: S1768006255.248280,VS0,VE40
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:80 · dev.maker.co
2026-01-03 00:55
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=gPdL3RX8ntbdgZi%2FAdyIy6ClWNMNHOKxbvB29IZKUmI%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1767401749"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=gPdL3RX8ntbdgZi%2FAdyIy6ClWNMNHOKxbvB29IZKUmI%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1767401749"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 7abd6789-4c4b-ac74-825a-9e8f18b8afcf
X-Runtime: 0.036386
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Date: Sat, 03 Jan 2026 00:55:49 GMT
Age: 0
X-Served-By: cache-iad-kiad7000038-IAD, cache-lcy-egml8630080-LCY
X-Cache: MISS, HIT
X-Cache-Hits: 0, 1
X-Timer: S1767401749.389085,VS0,VE1
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:443 · dev.maker.co
2026-01-02 19:39
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=mBcSJQLuSyJKv3sG350N4OsYuUVp0qZbd0WOriaorzg%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1767382774"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=mBcSJQLuSyJKv3sG350N4OsYuUVp0qZbd0WOriaorzg%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1767382774"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: cd400473-ab56-3617-e404-bc93e4e92836
X-Runtime: 0.029114
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Date: Fri, 02 Jan 2026 19:39:34 GMT
Age: 0
X-Served-By: cache-iad-kiad7000038-IAD, cache-vie6348-VIE
X-Cache: MISS, HIT
X-Cache-Hits: 0, 1
X-Timer: S1767382774.199978,VS0,VE0
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:443 · dev.maker.co
2025-12-23 00:55
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=LDAhahr6gI%2BJMuMVIrpy3hEFQabTxR%2B3juxQsXduU9g%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1766451351"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=LDAhahr6gI%2BJMuMVIrpy3hEFQabTxR%2B3juxQsXduU9g%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1766451351"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 57b1b98e-7e36-05cc-2df1-2b6379d824fa
X-Runtime: 0.015612
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Date: Tue, 23 Dec 2025 00:55:51 GMT
Age: 0
X-Served-By: cache-iad-kiad7000038-IAD, cache-lga21927-LGA
X-Cache: MISS, HIT
X-Cache-Hits: 0, 1
X-Timer: S1766451351.362421,VS0,VE1
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:80 · dev.maker.co
2025-12-22 23:26
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=w4EMXUcdHx6yrK1xhjWlwyCVXiC7wGx1U%2B4Y%2BnaGzCU%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1766445992"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=w4EMXUcdHx6yrK1xhjWlwyCVXiC7wGx1U%2B4Y%2BnaGzCU%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1766445992"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 9ef7fd23-2962-366d-02b4-e00712b9e1fe
X-Runtime: 0.015257
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Date: Mon, 22 Dec 2025 23:26:32 GMT
Age: 0
X-Served-By: cache-iad-kiad7000038-IAD, cache-bom-vanm7210066-BOM
X-Cache: MISS, HIT
X-Cache-Hits: 0, 1
X-Timer: S1766445993.864091,VS0,VE1
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:443 · dev.maker.co
2025-12-21 09:26
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2BQMC2k9oIRqXEqfFkL0yqqRV2JvAIgnifKC%2FhL3Kzg0%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1766309199"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2BQMC2k9oIRqXEqfFkL0yqqRV2JvAIgnifKC%2FhL3Kzg0%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1766309199"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 49886d86-f8a5-944d-d10a-13c3c03d8970
X-Runtime: 0.016160
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Date: Sun, 21 Dec 2025 09:26:39 GMT
Age: 0
X-Served-By: cache-iad-kiad7000038-IAD, cache-lcy-egml8630076-LCY
X-Cache: MISS, HIT
X-Cache-Hits: 0, 1
X-Timer: S1766309200.732652,VS0,VE33
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:80 · dev.maker.co
2025-12-21 07:45
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=lpOgSYVI9Vs2h8fE1ylrHhEnEVIw9ZbclJXvZDQ359Y%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1766303147"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=lpOgSYVI9Vs2h8fE1ylrHhEnEVIw9ZbclJXvZDQ359Y%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1766303147"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 74b67d8d-2b89-f1a1-f759-4fe371083edd
X-Runtime: 0.017982
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Age: 0
Date: Sun, 21 Dec 2025 07:45:47 GMT
X-Served-By: cache-iad-kiad7000038-IAD, cache-sjc1000129-SJC
X-Cache: HIT, MISS
X-Cache-Hits: 1, 0
X-Timer: S1766303147.144819,VS0,VE67
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:80 · dev.maker.co
2025-12-19 09:55
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=f9XVlZ8RKLZIZkJcCvoUsC%2FW5Y85%2Fy4HqKYT%2BcYadfw%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1766138135"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=f9XVlZ8RKLZIZkJcCvoUsC%2FW5Y85%2Fy4HqKYT%2BcYadfw%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1766138135"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 357b40e4-292b-246a-729e-174962d75f47
X-Runtime: 0.018486
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Date: Fri, 19 Dec 2025 09:55:35 GMT
Age: 0
X-Served-By: cache-iad-kiad7000038-IAD, cache-sin-wsss1830095-SIN
X-Cache: MISS, HIT
X-Cache-Hits: 0, 1
X-Timer: S1766138136.717155,VS0,VE1
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>
Open service 151.101.130.132:443 · dev.maker.co
2025-12-19 01:23
HTTP/1.1 302 Found
Connection: close
Content-Length: 87
Cache-Control: no-store
Content-Type: text/html; charset=utf-8
Location: https://www.maker.co/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=mtV6UHX5SG%2F%2Fb3pnDFNnAZ6UMbhMRTRsCuylhvtpsuM%3D\u0026sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d\u0026ts=1766107429"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=mtV6UHX5SG%2F%2Fb3pnDFNnAZ6UMbhMRTRsCuylhvtpsuM%3D&sid=e11707d5-02a7-43ef-b45e-2cf4d2036f7d&ts=1766107429"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router, 1.1 varnish, 1.1 varnish
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 3b275e72-fee1-f3b8-7db5-4eab37c533ad
X-Runtime: 0.018731
X-Xss-Protection: 1; mode=block
Accept-Ranges: bytes
Date: Fri, 19 Dec 2025 01:23:49 GMT
Age: 0
X-Served-By: cache-iad-kiad7000038-IAD, cache-sin-wsat1880051-SIN
X-Cache: MISS, HIT
X-Cache-Hits: 0, 1
X-Timer: S1766107429.390985,VS0,VE0
Vary: Accept-Encoding
<html><body>You are being <a href="https://www.maker.co/">redirected</a>.</body></html>