Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31ac6de87e8a5d535f7f8046b56dfed4c602b84ec
GraphQL introspection enabled at /graphql Types: 133 (by kind: ENUM: 10, INPUT_OBJECT: 12, OBJECT: 106, SCALAR: 5) Operations: - Query: Query | fields: analytics, assets, authentication, comments, contribute - Mutation: Mutation | fields: analytics, assets, authentication, comments, groups - Subscription: Subscription | fields: loggingLiveTrail Directives: auth, cacheControl, deprecated, include, rateLimit, skip, specifiedBy (total: 7)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31ac6de87e8a5d535f7f8046b56dfed4c602b84ec
GraphQL introspection enabled at /graphql Types: 133 (by kind: ENUM: 10, INPUT_OBJECT: 12, OBJECT: 106, SCALAR: 5) Operations: - Query: Query | fields: analytics, assets, authentication, comments, contribute - Mutation: Mutation | fields: analytics, assets, authentication, comments, groups - Subscription: Subscription | fields: loggingLiveTrail Directives: auth, cacheControl, deprecated, include, rateLimit, skip, specifiedBy (total: 7)
Open service 99.83.185.157:80 · docs.incentivehouse.com.pt
2026-01-09 01:27
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 01:28:13 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7dFZ3MfUy6NGSJo%2Bp74JTbgGl9LcHJgJ72IkJN1W3QM%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767922093"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7dFZ3MfUy6NGSJo%2Bp74JTbgGl9LcHJgJ72IkJN1W3QM%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767922093"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Fri, 09 Jan 2026 01:43:13 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login
Open service 15.197.253.240:443 · docs.incentivehouse.com.pt
2026-01-08 22:11
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Thu, 08 Jan 2026 22:11:13 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=pGhlAP9JbUiEa%2B57doMkWjk3Q%2Fr6yi2GKhLFRYtnYpk%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767910273"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=pGhlAP9JbUiEa%2B57doMkWjk3Q%2Fr6yi2GKhLFRYtnYpk%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767910273"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Thu, 08 Jan 2026 22:26:13 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login
Open service 15.197.253.240:443 · docs.incentivehouse.com.pt
2026-01-02 11:51
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 11:51:21 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=hUEZZzYNjF0klpaOGlXI4vg1Y5niu9jRVChLhRrXYow%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767354681"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=hUEZZzYNjF0klpaOGlXI4vg1Y5niu9jRVChLhRrXYow%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767354681"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Fri, 02 Jan 2026 12:06:21 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login
Open service 99.83.185.157:80 · docs.incentivehouse.com.pt
2026-01-01 21:56
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Thu, 01 Jan 2026 21:56:23 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FeTzJBf%2B8r%2Bq8l%2BDKyW7P6nJ%2FcPe%2Bmg9XQadOTZzsBE%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767304583"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FeTzJBf%2B8r%2Bq8l%2BDKyW7P6nJ%2FcPe%2Bmg9XQadOTZzsBE%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767304583"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Thu, 01 Jan 2026 22:11:23 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login
Open service 99.83.185.157:80 · docs.incentivehouse.com.pt
2025-12-30 06:39
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 06:39:42 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wCueieorYSANRrP1jRyq5oi45zkbxGy1o3SQ0lgole4%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767076782"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wCueieorYSANRrP1jRyq5oi45zkbxGy1o3SQ0lgole4%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767076782"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Tue, 30 Dec 2025 06:54:42 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login
Open service 15.197.253.240:443 · docs.incentivehouse.com.pt
2025-12-22 17:09
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 17:09:52 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=O7P0k%2FsOR7gqinrojldscKPf3QVFHeq8hFq8kyvEoac%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766423392"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=O7P0k%2FsOR7gqinrojldscKPf3QVFHeq8hFq8kyvEoac%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766423392"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Mon, 22 Dec 2025 17:24:52 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login
Open service 99.83.185.157:80 · docs.incentivehouse.com.pt
2025-12-22 14:12
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 14:12:20 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sxz%2BAiFYdRkQnPxIzs9XgJKq9fS7XH45rkuJjTL96fM%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766412740"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sxz%2BAiFYdRkQnPxIzs9XgJKq9fS7XH45rkuJjTL96fM%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766412740"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Mon, 22 Dec 2025 14:27:20 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login
Open service 15.197.253.240:443 · docs.incentivehouse.com.pt
2025-12-20 14:14
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 14:14:27 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=gQIauSjYVQshqSPMi%2BQZP6Cbxf%2FGXzyqHXIgX9JJwD4%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766240067"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=gQIauSjYVQshqSPMi%2BQZP6Cbxf%2FGXzyqHXIgX9JJwD4%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766240067"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Sat, 20 Dec 2025 14:29:27 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login
Open service 99.83.185.157:80 · docs.incentivehouse.com.pt
2025-12-20 14:00
HTTP/1.1 302 Found
Content-Language: en
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 14:00:06 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=C2n4OxE6GsvuZ4aGhBOlQiH7ilF3VMUmFldKEvl%2F17Q%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766239206"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=C2n4OxE6GsvuZ4aGhBOlQiH7ilF3VMUmFldKEvl%2F17Q%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766239206"
Server: Heroku
Set-Cookie: loginRedirect=%2F; Max-Age=900; Path=/; Expires=Sat, 20 Dec 2025 14:15:06 GMT
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
Found. Redirecting to /login