BunnyCDN-DE1-860
tcp/443
BunnyCDN-IL1-845
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa33013a996614d1446c43b9476d2676c3368a330bb
GraphQL introspection enabled at /graphql Types: 602 (by kind: ENUM: 47, INPUT_OBJECT: 105, INTERFACE: 105, OBJECT: 339, SCALAR: 5, UNION: 1) Operations: - Query: RootQuery | fields: accordion, accordionBy, accordionGroup, accordionGroupBy, accordionGroups - Mutation: RootMutation | fields: createAccordion, createAccordionGroup, createBoardMember, createCareer, createCategory Directives: deprecated, include, oneOf, skip (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa33013a996614d1446c43b9476d2676c3368a330bb
GraphQL introspection enabled at /graphql Types: 602 (by kind: ENUM: 47, INPUT_OBJECT: 105, INTERFACE: 105, OBJECT: 339, SCALAR: 5, UNION: 1) Operations: - Query: RootQuery | fields: accordion, accordionBy, accordionGroup, accordionGroupBy, accordionGroups - Mutation: RootMutation | fields: createAccordion, createAccordionGroup, createBoardMember, createCareer, createCategory Directives: deprecated, include, oneOf, skip (total: 4)
Open service 185.93.1.244:443 · nolefturns.org
2026-01-22 21:01
HTTP/1.1 301 Moved Permanently Date: Thu, 22 Jan 2026 21:01:30 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Server: BunnyCDN-IL1-845 CDN-PullZone: 3522226 CDN-RequestCountryCode: CA Cache-Control: public, max-age=0 Location: https://www.nolefturns.org/ X-Frame-Options: sameorigin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=15811200 ; includeSubDomains ; preload Strict-Transport-Security: max-age=31536000; Referrer-Policy: origin-when-cross-origin Referrer-Policy: no-referrer-when-downgrade Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self) X-Redirect-By: WordPress X-Cache-Status: HIT X-Rocket-Nginx-Serving-Static: MISS Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 301 CDN-CachedAt: 01/22/2026 21:01:30 CDN-EdgeStorageId: 1232 CDN-RequestId: 171c37f41ff7c6294284182ab48cbf37 CDN-Cache: BYPASS CDN-Status: 301 CDN-RequestTime: 0
Open service 138.199.37.227:443 · www.nolefturns.org
2026-01-09 06:27
HTTP/1.1 200 OK Date: Fri, 09 Jan 2026 06:27:59 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Server: BunnyCDN-DE1-860 CDN-PullZone: 3522226 CDN-RequestCountryCode: DE Cache-Control: public, max-age=0 X-Frame-Options: sameorigin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=15811200 ; includeSubDomains ; preload Strict-Transport-Security: max-age=31536000; Referrer-Policy: origin-when-cross-origin Referrer-Policy: no-referrer-when-downgrade Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self) Link: <https://www.nolefturns.org/wp-json/>; rel="https://api.w.org/" Link: <https://www.nolefturns.org/wp-json/wp/v2/pages/5889>; rel="alternate"; title="JSON"; type="application/json" Link: <https://wp.me/P9sCZu-1wZ>; rel=shortlink X-Cache-Status: STALE X-Rocket-Nginx-Serving-Static: MISS Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 200 CDN-CachedAt: 01/09/2026 06:27:59 CDN-EdgeStorageId: 1048 CDN-RequestId: f6f132c709dd4214af8be6e875a922ba CDN-Cache: BYPASS CDN-Status: 200 CDN-RequestTime: 0
Open service 185.93.1.244:443 · nolefturns.org
2026-01-09 01:37
HTTP/1.1 301 Moved Permanently Date: Fri, 09 Jan 2026 01:37:23 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Server: BunnyCDN-IL1-845 CDN-PullZone: 3522226 CDN-RequestCountryCode: NL Cache-Control: public, max-age=0 Location: https://www.nolefturns.org/ X-Frame-Options: sameorigin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=15811200 ; includeSubDomains ; preload Strict-Transport-Security: max-age=31536000; Referrer-Policy: origin-when-cross-origin Referrer-Policy: no-referrer-when-downgrade Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self) X-Redirect-By: WordPress X-Cache-Status: HIT X-Rocket-Nginx-Serving-Static: MISS Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 301 CDN-CachedAt: 01/09/2026 01:37:23 CDN-EdgeStorageId: 1232 CDN-RequestId: cbf6beafb4f9cecab42dc00d543de428 CDN-Cache: BYPASS CDN-Status: 301 CDN-RequestTime: 0
Open service 138.199.37.227:443 · www.nolefturns.org
2026-01-02 05:47
HTTP/1.1 200 OK Date: Fri, 02 Jan 2026 05:47:33 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Server: BunnyCDN-DE1-860 CDN-PullZone: 3522226 CDN-RequestCountryCode: CA Cache-Control: public, max-age=0 X-Frame-Options: sameorigin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=15811200 ; includeSubDomains ; preload Strict-Transport-Security: max-age=31536000; Referrer-Policy: origin-when-cross-origin Referrer-Policy: no-referrer-when-downgrade Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self) Link: <https://www.nolefturns.org/wp-json/>; rel="https://api.w.org/" Link: <https://www.nolefturns.org/wp-json/wp/v2/pages/5889>; rel="alternate"; title="JSON"; type="application/json" Link: <https://wp.me/P9sCZu-1wZ>; rel=shortlink X-Cache-Status: STALE X-Rocket-Nginx-Serving-Static: MISS Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 200 CDN-CachedAt: 01/02/2026 05:47:33 CDN-EdgeStorageId: 1048 CDN-RequestId: 742b0a1f6fbfc04b35a7748f6caf72e8 CDN-Cache: BYPASS CDN-Status: 200 CDN-RequestTime: 0
Open service 185.93.1.244:443 · nolefturns.org
2026-01-02 01:59
HTTP/1.1 301 Moved Permanently Date: Fri, 02 Jan 2026 01:59:34 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Server: BunnyCDN-IL1-845 CDN-PullZone: 3522226 CDN-RequestCountryCode: US Cache-Control: public, max-age=0 Location: https://www.nolefturns.org/ X-Frame-Options: sameorigin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=15811200 ; includeSubDomains ; preload Strict-Transport-Security: max-age=31536000; Referrer-Policy: origin-when-cross-origin Referrer-Policy: no-referrer-when-downgrade Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self) X-Redirect-By: WordPress X-Cache-Status: UPDATING X-Rocket-Nginx-Serving-Static: MISS Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 301 CDN-CachedAt: 01/02/2026 01:59:34 CDN-EdgeStorageId: 1232 CDN-RequestId: 3a6c02ff5f453621c7b57e89d8d7e98e CDN-Cache: BYPASS CDN-Status: 301 CDN-RequestTime: 0
Open service 185.93.1.244:443 · nolefturns.org
2025-12-23 00:28
HTTP/1.1 301 Moved Permanently Date: Tue, 23 Dec 2025 00:28:55 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Server: BunnyCDN-IL1-845 CDN-PullZone: 3522226 CDN-RequestCountryCode: GB Cache-Control: public, max-age=0 Location: https://www.nolefturns.org/ X-Frame-Options: sameorigin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=15811200 ; includeSubDomains ; preload Strict-Transport-Security: max-age=31536000; Referrer-Policy: origin-when-cross-origin Referrer-Policy: no-referrer-when-downgrade Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self) X-Redirect-By: WordPress X-Cache-Status: HIT X-Rocket-Nginx-Serving-Static: MISS Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 301 CDN-CachedAt: 12/23/2025 00:28:55 CDN-EdgeStorageId: 1232 CDN-RequestId: 30dcec41384fae4c75bf47334f9aaa58 CDN-Cache: BYPASS CDN-Status: 301 CDN-RequestTime: 0
Open service 138.199.37.227:443 · www.nolefturns.org
2025-12-22 20:19
HTTP/1.1 200 OK Date: Mon, 22 Dec 2025 20:19:49 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Server: BunnyCDN-DE1-860 CDN-PullZone: 3522226 CDN-RequestCountryCode: IN Cache-Control: public, max-age=0 X-Frame-Options: sameorigin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=15811200 ; includeSubDomains ; preload Strict-Transport-Security: max-age=31536000; Referrer-Policy: origin-when-cross-origin Referrer-Policy: no-referrer-when-downgrade Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), usb=(self) Link: <https://www.nolefturns.org/wp-json/>; rel="https://api.w.org/" Link: <https://www.nolefturns.org/wp-json/wp/v2/pages/5889>; rel="alternate"; title="JSON"; type="application/json" Link: <https://wp.me/P9sCZu-1wZ>; rel=shortlink X-Cache-Status: HIT X-Rocket-Nginx-Serving-Static: MISS Content-Security-Policy: default-src * 'unsafe-inline' 'unsafe-eval' data: blob:; CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 200 CDN-CachedAt: 12/22/2025 20:19:49 CDN-EdgeStorageId: 1048 CDN-RequestId: 1ee15ed633a1e105508fc97aa3ae06dd CDN-Cache: BYPASS CDN-Status: 200 CDN-RequestTime: 0