cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa361c7f59d72efbeff9a74e0f01de2163ee3fea548
GraphQL introspection enabled at /graphql Types: 385 (by kind: ENUM: 28, INPUT_OBJECT: 90, INTERFACE: 20, OBJECT: 242, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e25fd59efe445c8e2ec951816124c8bdb97aecf0e1
GraphQL introspection enabled at /graphql/api Types: 385 (by kind: ENUM: 28, INPUT_OBJECT: 90, INTERFACE: 20, OBJECT: 242, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, oneOf, skip (total: 4)
Open service 104.26.7.184:443 ยท mesoestetic.pl
2026-01-22 19:53
HTTP/1.1 302 Found Date: Thu, 22 Jan 2026 19:53:41 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Location: https://www.mesoestetic.pl/ CF-Ray: 9c21994e0b06a403-BLR CF-Cache-Status: DYNAMIC Access-Control-Allow-Origin: * Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Expires: -1 Server: cloudflare Set-Cookie: PHPSESSID=tvejtbnbcg61rv9hd3fq6shh1t; expires=Thu, 22 Jan 2026 20:53:41 GMT; Max-Age=3600; path=/; domain=mesoestetic.pl; secure; HttpOnly; SameSite=Lax Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Via: 1.1 google Pragma: no-cache access-control-allow-headers: authorization,x-requested-with, Content-Type, origin, accept access-control-allow-methods: POST, GET, OPTIONS, DELETE, PUT