Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6d6f7266f4bfe653dec1f4d939048a6e996486034
GraphQL introspection enabled at /api/graphql Types: 272 (by kind: ENUM: 18, INPUT_OBJECT: 83, INTERFACE: 1, OBJECT: 164, SCALAR: 6) Operations: - Query: RootQueryType | fields: accounts, certificationExam, certificationProgresses, courses, currentAccount - Mutation: RootMutationType | fields: acceptTerms, addCourseAssets, addSimulation, addVrVideoExample, cancelReminder - Subscription: RootSubscriptionType | fields: notificationFeed, seedCourseFeed Directives: include, skip (total: 2)
Open service 75.2.60.68:443 · development-api.certify-ed.com
2026-01-09 22:55
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 22:55:49 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=5uy1VIetVblgQbTzOUuwq%2BoRKfs3B97yeHw5V93olOI%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767999350"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=5uy1VIetVblgQbTzOUuwq%2BoRKfs3B97yeHw5V93olOI%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767999350"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 7c6c0379-e9c7-8125-f241-16c37403efeb
Connection: close
hello
Open service 75.2.60.68:443 · development-api.certify-ed.com
2025-12-30 12:03
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 12:03:15 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7aCvCOPbelvXHiwsJjxhqbhxMu%2F35i3%2FpAB6Zt1OpX8%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767096196"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7aCvCOPbelvXHiwsJjxhqbhxMu%2F35i3%2FpAB6Zt1OpX8%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767096196"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 6f767f44-ee3e-4bbd-a674-e4e7be4ad528
Connection: close
hello
Open service 75.2.60.68:443 · development-api.certify-ed.com
2025-12-20 14:10
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 14:10:53 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=IrA9HT6BhUkN5Llvd07I92uqkyTbc7izJdbCmZEUa6I%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766239854"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=IrA9HT6BhUkN5Llvd07I92uqkyTbc7izJdbCmZEUa6I%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766239854"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 2f77177e-eed3-9a39-75dc-d1b7a3254de9
Connection: close
hello