nginx
tcp/443 tcp/80 tcp/8443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ff05210135362883d0be41ac99e672b2d0460e22
GraphQL introspection enabled at /graphql Types: 389 (by kind: ENUM: 28, INPUT_OBJECT: 86, INTERFACE: 20, OBJECT: 250, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa374c2942e74c2942e74c2942e74c2942e74c2942e
GraphQL introspection enabled at /graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2df9b2641df9b2641df9b2641df9b2641df9b2641
GraphQL introspection enabled at /graphql/api Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ff05210135362883d0be41ac99e672b290088381
GraphQL introspection enabled at /graphql Types: 389 (by kind: ENUM: 28, INPUT_OBJECT: 86, INTERFACE: 20, OBJECT: 250, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2
GraphQL introspection enabled at /graphql/api
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f69677aabe73649a6db9fef51d08e005d1bfac85
GraphQL introspection enabled at /graphql/api Types: 389 (by kind: ENUM: 28, INPUT_OBJECT: 86, INTERFACE: 20, OBJECT: 250, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa374c2942e74c2942e74c2942e74c2942e74c2942e
GraphQL introspection enabled at /graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2
GraphQL introspection enabled at /graphql/api
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ff05210135362883d0be41ac99e672b2d0460e22
GraphQL introspection enabled at /graphql Types: 389 (by kind: ENUM: 28, INPUT_OBJECT: 86, INTERFACE: 20, OBJECT: 250, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3)
Open service 94.76.223.34:8443 · leddirect.hypernode.io
2026-01-23 12:04
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Fri, 23 Jan 2026 12:04:29 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Set-Cookie: PHPSESSID=cgqpr3ijpg07112f71apq5pkp8; expires=Fri, 30 Jan 2026 12:04:29 GMT; Max-Age=604800; path=/; domain=leddirect.hypernode.io; secure; HttpOnly; SameSite=Lax
Location: https://www.leddirect.nl/
Report-To: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/monitor.bigbridgedev.nl\/csp"}]}
Content-Security-Policy-Report-Only: font-src fonts.gstatic.com v2.zopim.com data: data: 'self' 'unsafe-inline'; form-action www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com www.youtube.com www.facebook.com v2.zopim.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com i.ytimg.com www.google.nl www.facebook.com widgets.trustedshops.com www.ledlampendirect.nl v2assets.zopim.com v2assets.zopim.io v2.zopim.com v2.zopim.io data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com chimpstatic.com widgets.trustedshops.com www.dwin1.com v2.zopim.com connect.facebook.net static.zdassets.com ekr.zdassets.com www.facebook.com checkout.buckaroo.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com checkout.buckaroo.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com v2.zopim.com www.paypal.com stats.g.doubleclick.net ekr.zdassets.com widget-mediator.zopim.com wss://widget-mediator.zopim.com v2assets.zopim.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Pragma: no-cache
Expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Open service 94.76.223.34:443 · leddirect.hypernode.io
2026-01-23 04:23
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Fri, 23 Jan 2026 04:23:19 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Set-Cookie: PHPSESSID=4v1hocu54vurc11n14vj2ljvjh; expires=Fri, 30 Jan 2026 04:23:19 GMT; Max-Age=604800; path=/; domain=leddirect.hypernode.io; secure; HttpOnly; SameSite=Lax
Location: https://www.leddirect.nl/
Report-To: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/monitor.bigbridgedev.nl\/csp"}]}
Content-Security-Policy-Report-Only: font-src fonts.gstatic.com v2.zopim.com data: data: 'self' 'unsafe-inline'; form-action www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com www.youtube.com www.facebook.com v2.zopim.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com i.ytimg.com www.google.nl www.facebook.com widgets.trustedshops.com www.ledlampendirect.nl v2assets.zopim.com v2assets.zopim.io v2.zopim.com v2.zopim.io data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com chimpstatic.com widgets.trustedshops.com www.dwin1.com v2.zopim.com connect.facebook.net static.zdassets.com ekr.zdassets.com www.facebook.com checkout.buckaroo.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com checkout.buckaroo.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com v2.zopim.com www.paypal.com stats.g.doubleclick.net ekr.zdassets.com widget-mediator.zopim.com wss://widget-mediator.zopim.com v2assets.zopim.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Pragma: no-cache
Expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
Open service 94.76.223.34:8443 · leddirect.hypernode.io
2026-01-12 04:10
HTTP/1.1 429 Too Many Requests Server: nginx Date: Mon, 12 Jan 2026 04:10:40 GMT Content-Type: text/html Content-Length: 162 Connection: close Vary: Accept-Encoding Pragma: no-cache Expires: -1 Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Page title: 429 Too Many Requests <html> <head><title>429 Too Many Requests</title></head> <body> <center><h1>429 Too Many Requests</h1></center> <hr><center>nginx</center> </body> </html>
Open service 94.76.223.34:80 · leddirect.hypernode.io
2026-01-12 04:10
HTTP/1.1 301 Moved Permanently Server: nginx Date: Mon, 12 Jan 2026 04:10:41 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://leddirect.hypernode.io/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 94.76.223.34:443 · leddirect.hypernode.io
2026-01-12 04:10
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Mon, 12 Jan 2026 04:10:40 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Set-Cookie: PHPSESSID=1ldufhlr4a55b2eq9c0rqgn3oi; expires=Mon, 19 Jan 2026 04:10:40 GMT; Max-Age=604800; path=/; domain=leddirect.hypernode.io; secure; HttpOnly; SameSite=Lax
Location: https://www.leddirect.nl/
Report-To: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/monitor.bigbridgedev.nl\/csp"}]}
Content-Security-Policy-Report-Only: font-src fonts.gstatic.com v2.zopim.com data: data: 'self' 'unsafe-inline'; form-action www.facebook.com 'self' 'unsafe-inline'; frame-ancestors *.multisafepay.com https://pay.google.com 'self'; frame-src https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com www.youtube.com www.facebook.com v2.zopim.com 'self' 'unsafe-inline'; img-src data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com https://www.mollie.com i.ytimg.com www.google.nl www.facebook.com widgets.trustedshops.com www.ledlampendirect.nl v2assets.zopim.com v2assets.zopim.io v2.zopim.com v2.zopim.io data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com www.paypalobjects.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ *.multisafepay.com https://pay.google.com js.mollie.com chimpstatic.com widgets.trustedshops.com www.dwin1.com v2.zopim.com connect.facebook.net static.zdassets.com ekr.zdassets.com www.facebook.com checkout.buckaroo.nl 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.multisafepay.com checkout.buckaroo.nl 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com www.paypalobjects.com *.multisafepay.com v2.zopim.com www.paypal.com stats.g.doubleclick.net ekr.zdassets.com widget-mediator.zopim.com wss://widget-mediator.zopim.com v2assets.zopim.io 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://monitor.bigbridgedev.nl/csp; report-to report-endpoint;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Vary: Accept-Encoding
Pragma: no-cache
Expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0