Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db84e0e3505c719384426908c8ad65c2f2ecfd40ff48ccecc3
GraphQL introspection enabled at /api Types: 23 (by kind: ENUM: 1, INPUT_OBJECT: 2, OBJECT: 14, SCALAR: 6) Operations: - Query: RootQueryType | fields: happenings, happy, whoami - Mutation: RootMutationType | fields: authorize, createAssignment, createHappening, createNeed, createUser Directives: include, skip (total: 2)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db84e0e3505c719384426908c8ad65c2f2ecfd40ff48ccecc3
GraphQL introspection enabled at /api Types: 23 (by kind: ENUM: 1, INPUT_OBJECT: 2, OBJECT: 14, SCALAR: 6) Operations: - Query: RootQueryType | fields: happenings, happy, whoami - Mutation: RootMutationType | fields: authorize, createAssignment, createHappening, createNeed, createUser Directives: include, skip (total: 2)
Open service 15.197.129.158:443 · www.kleinplan.ch
2026-01-10 02:33
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Sat, 10 Jan 2026 02:33:08 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FAsmxzw7mQNMgEOvj4WcTnPtAm0IGsrCZGJj%2Bylt3T0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1768012389"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FAsmxzw7mQNMgEOvj4WcTnPtAm0IGsrCZGJj%2Bylt3T0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1768012389"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: f41eaac1-4849-878a-7fab-74160f4db829
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>
Open service 76.223.11.49:443 · kleinplan.ch
2026-01-09 12:12
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Fri, 09 Jan 2026 12:12:32 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2F3ZYX4jWrntT1%2F4%2BCJH4ZlRyOc4Pkcvni9HxEGLXyD8%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767960753"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2F3ZYX4jWrntT1%2F4%2BCJH4ZlRyOc4Pkcvni9HxEGLXyD8%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767960753"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 7d7cba76-4610-3542-5f25-f736ecf6bfd4
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>
Open service 15.197.129.158:443 · www.kleinplan.ch
2026-01-02 22:58
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Fri, 02 Jan 2026 22:58:56 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Omj0sGqUppwOFudo1vM9Y8ZPLLECDFF3C8nFyFsMJs0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767394736"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Omj0sGqUppwOFudo1vM9Y8ZPLLECDFF3C8nFyFsMJs0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767394736"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0072df35-40e8-7cd7-c86d-b98e0bd0ee90
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>
Open service 76.223.11.49:443 · kleinplan.ch
2026-01-02 02:38
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Fri, 02 Jan 2026 02:38:47 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=koWChDr8zjpXKTHcBxHduW8g0RHUqYHssf5TZZBjVcQ%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767321528"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=koWChDr8zjpXKTHcBxHduW8g0RHUqYHssf5TZZBjVcQ%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767321528"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 9b6a815d-0400-6da0-f8b4-b2575a231992
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>
Open service 76.223.11.49:443 · kleinplan.ch
2025-12-30 10:49
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Tue, 30 Dec 2025 10:49:35 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ikeUFWGCG3Ti4Lnwq6%2FGKFgbq0h3wJk3tNK4q1%2BbZTs%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767091775"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ikeUFWGCG3Ti4Lnwq6%2FGKFgbq0h3wJk3tNK4q1%2BbZTs%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767091775"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: d89a2bad-196d-bcd4-ece7-34fe44e7d3b9
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>
Open service 15.197.129.158:443 · www.kleinplan.ch
2025-12-23 08:07
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Tue, 23 Dec 2025 08:07:47 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=BOvhEocpU2w4p7Y4MVDI%2B%2BUY8AgsNagdbD12owt%2B4IQ%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766477268"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=BOvhEocpU2w4p7Y4MVDI%2B%2BUY8AgsNagdbD12owt%2B4IQ%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766477268"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: edb3f3f6-081a-ba55-c8f9-3de459676281
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>
Open service 76.223.11.49:443 · kleinplan.ch
2025-12-23 00:45
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Tue, 23 Dec 2025 00:45:29 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=253YtbJTGILoZO%2Fisti4VprpLzTHuLc7vowA%2BEK08Hw%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766450730"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=253YtbJTGILoZO%2Fisti4VprpLzTHuLc7vowA%2BEK08Hw%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766450730"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 2781ecc5-bd26-bbeb-0e03-8dafb3149122
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>
Open service 76.223.11.49:443 · kleinplan.ch
2025-12-20 23:02
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Sat, 20 Dec 2025 23:02:13 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=iRCdVhEEpjW5w%2Bi9R95bsP3i9fgvpVFazWVRXrn%2FUG0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766271734"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=iRCdVhEEpjW5w%2Bi9R95bsP3i9fgvpVFazWVRXrn%2FUG0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766271734"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 8b02f9d1-1aca-54e7-6479-ed445c16c9d0
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>
Open service 15.197.129.158:443 · www.kleinplan.ch
2025-12-20 16:55
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 759
Content-Type: text/html; charset=utf-8
Cross-Origin-Window-Policy: deny
Date: Sat, 20 Dec 2025 16:55:18 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=NjOFUyjO%2FgCJf0GSmGbL%2FM1M5KHoaRYpnn8UM6BrRjY%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766249719"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=NjOFUyjO%2FgCJf0GSmGbL%2FM1M5KHoaRYpnn8UM6BrRjY%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766249719"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: f361c9e0-8487-0d4a-2ce6-7571d3727702
X-Xss-Protection: 1; mode=block
Connection: close
Page title: Kleinplan
<!DOCTYPE html>
<html lang="de-ch">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Kleinplan</title>
<link rel="shortcut icon" href="/favicon-72e42faf2a53a401a6bf64b7caf96068.ico?vsn=d" type="image/x-icon" />
<link rel="stylesheet" href="/assets/index-f4c3a582096a9ac14d36659819eb05d2.css?vsn=d">
</head>
<body>
<div id="root"></div>
<script src="/assets/runtime-3c768977c2574a34506ebd0fed7ae101.js?vsn=d"></script>
<script src="/assets/vendor-36a0c424d618b57774c983d1ab3e697b.js?vsn=d"></script>
<script src="/assets/index-67716eeb1509fe28208c6c110cac05f7.js?vsn=d"></script>
</body>
</html>