Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6d6f7266f4bfe653dec1f4d939048a6e996486034
GraphQL introspection enabled at /api/graphql Types: 272 (by kind: ENUM: 18, INPUT_OBJECT: 83, INTERFACE: 1, OBJECT: 164, SCALAR: 6) Operations: - Query: RootQueryType | fields: accounts, certificationExam, certificationProgresses, courses, currentAccount - Mutation: RootMutationType | fields: acceptTerms, addCourseAssets, addSimulation, addVrVideoExample, cancelReminder - Subscription: RootSubscriptionType | fields: notificationFeed, seedCourseFeed Directives: include, skip (total: 2)
Open service 75.2.60.68:443 · develop-api.certify-ed.com
2026-01-09 19:19
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 19:19:33 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=J%2BnboQYcg5RXQQWASmO3E9R%2BrKtoMQ7XiocZz6cUgY0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767986373"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=J%2BnboQYcg5RXQQWASmO3E9R%2BrKtoMQ7XiocZz6cUgY0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767986373"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 9d0c044c-64d2-7f79-5704-5ff684573437
Connection: close
hello
Open service 75.2.60.68:443 · develop-api.certify-ed.com
2026-01-02 03:41
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 03:41:49 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Q4908OGdum9f6530t%2BiIVZVLYX6qdXGVEavzziPLcOs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767325309"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Q4908OGdum9f6530t%2BiIVZVLYX6qdXGVEavzziPLcOs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767325309"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: b9734fec-0ebd-5562-ee07-da5e0d3c11ef
Connection: close
hello
Open service 75.2.60.68:443 · develop-api.certify-ed.com
2025-12-30 11:08
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 11:08:11 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=kfJ0PDOkAPMH35o4x7oGUhv7Esu7EZnm6GBLzNtrNMA%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767092892"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=kfJ0PDOkAPMH35o4x7oGUhv7Esu7EZnm6GBLzNtrNMA%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767092892"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 739ea585-1219-f69c-9c6d-2a0d1102eeba
Connection: close
hello
Open service 75.2.60.68:443 · develop-api.certify-ed.com
2025-12-22 14:11
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 14:11:50 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=noAlJNi1S9yEVq6%2BahC6EpoIFI1JHjitU0WDuW%2BOTTs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766412710"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=noAlJNi1S9yEVq6%2BahC6EpoIFI1JHjitU0WDuW%2BOTTs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766412710"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 4eb4d8de-523f-7e95-22b4-5457479f6585
Connection: close
hello
Open service 75.2.60.68:443 · develop-api.certify-ed.com
2025-12-20 14:38
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 14:38:16 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wxlQ4Gxq6KHIYcK28oshEosRr2hS%2Ff%2BKHyzzQZu0JIM%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766241497"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wxlQ4Gxq6KHIYcK28oshEosRr2hS%2Ff%2BKHyzzQZu0JIM%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766241497"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: fbb0dd4b-4e98-6ee0-8657-73a70fb44d54
Connection: close
hello