GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d9181c39a346585bfbe2b3f59676f8159676f815
GraphQL introspection enabled at /graphql Types: 12 (by kind: ENUM: 2, OBJECT: 7, SCALAR: 3) Operations: - Query: Query | fields: _empty Directives: deprecated, include, skip (total: 3)
Open service 51.210.105.96:443 · directus-staging.snarshop.com
2026-01-23 10:29
HTTP/1.1 302 Found Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Content-Length: 29 Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' Content-Type: text/plain; charset=utf-8 Date: Fri, 23 Jan 2026 10:30:15 GMT Location: ./admin Vary: Origin, Accept X-Powered-By: Directus Connection: close Found. Redirecting to ./admin
Open service 51.210.105.96:443 · directus-staging.snarshop.com
2026-01-10 00:53
HTTP/1.1 302 Found Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Content-Length: 29 Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' Content-Type: text/plain; charset=utf-8 Date: Sat, 10 Jan 2026 00:54:09 GMT Location: ./admin Vary: Origin, Accept X-Powered-By: Directus Connection: close Found. Redirecting to ./admin
Open service 51.210.105.96:443 · directus-staging.snarshop.com
2026-01-02 19:36
HTTP/1.1 302 Found Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Content-Length: 29 Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' Content-Type: text/plain; charset=utf-8 Date: Fri, 02 Jan 2026 19:36:41 GMT Location: ./admin Vary: Origin, Accept X-Powered-By: Directus Connection: close Found. Redirecting to ./admin
Open service 51.210.105.96:443 · directus-staging.snarshop.com
2025-12-23 01:06
HTTP/1.1 302 Found Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Content-Length: 29 Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://raw.githubusercontent.com https://avatars.githubusercontent.com;media-src 'self';connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' Content-Type: text/plain; charset=utf-8 Date: Tue, 23 Dec 2025 01:06:24 GMT Location: ./admin Vary: Origin, Accept X-Powered-By: Directus Connection: close Found. Redirecting to ./admin