cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384c0beb6ca8bde26db1be8a7111e956f8c46ab6a
GraphQL introspection enabled at /graphql Types: 417 (by kind: ENUM: 41, INPUT_OBJECT: 92, INTERFACE: 24, OBJECT: 255, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384c0beb6ca8bde26db1be8a7111e956f6a7cd92f
GraphQL introspection enabled at /graphql Types: 417 (by kind: ENUM: 41, INPUT_OBJECT: 92, INTERFACE: 24, OBJECT: 255, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2d716fc91de1c05531213d472644124886e1c1cb0
GraphQL introspection enabled at /graphql/api Types: 417 (by kind: ENUM: 41, INPUT_OBJECT: 92, INTERFACE: 24, OBJECT: 255, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384c0beb6ca8bde26db1be8a7111e956f8c46ab6a
GraphQL introspection enabled at /graphql Types: 417 (by kind: ENUM: 41, INPUT_OBJECT: 92, INTERFACE: 24, OBJECT: 255, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384c0beb6ca8bde26db1be8a7111e956f6a7cd92f
GraphQL introspection enabled at /graphql Types: 417 (by kind: ENUM: 41, INPUT_OBJECT: 92, INTERFACE: 24, OBJECT: 255, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2d716fc91de1c05531213d472644124886e1c1cb0
GraphQL introspection enabled at /graphql/api Types: 417 (by kind: ENUM: 41, INPUT_OBJECT: 92, INTERFACE: 24, OBJECT: 255, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, skip (total: 3)
Open service 188.114.97.3:443 · purelydemos.com
2026-01-23 11:12
HTTP/1.1 200 OK
Date: Fri, 23 Jan 2026 11:12:46 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
X-Powered-By: PHP/8.2.30
X-Powered-By: PleskLin
X-Magento-Cache-Control: max-age=86400, public, s-maxage=86400
X-Magento-Tags: cat_c,store,cms_b,cms_p_2,cat_p,FPC
Pragma: no-cache
Cache-Control: max-age=0, must-revalidate, no-cache, no-store
Expires: Thu, 23 Jan 2025 11:12:45 GMT
X-Magento-Cache-Debug: HIT
Content-Security-Policy-Report-Only: font-src data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com secure.nochex.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com secure.nochex.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com 'self' 'unsafe-inline'; object-src secure.nochex.com 'self' 'unsafe-inline'; media-src *.adobe.com secure.nochex.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com secure.nochex.com 'self' 'unsafe-inline'; child-src secure.nochex.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Frame-Options: SAMEORIGIN
Set-Cookie: PHPSESSID=cfuooptn1h6m5r9ekj0q3i3ckj; expires=Fri, 23 Jan 2026 12:12:46 GMT; Max-Age=3600; path=/; domain=purelydemos.com; HttpOnly; SameSite=Lax
Vary: Accept-Encoding
X-UA-Compatible: IE=edge
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=3KwXcb3BV0q9dOXPtsyCRT%2FqWe%2FDlaGNImZ0FqC2Z%2BKBZCu1PNR17v4ZfPs2rpAtJxWFszGC%2FQ1AHYhEXR64b1FJa7jzSTtIqFDA4XI2bA%3D%3D"}]}
cf-cache-status: DYNAMIC
CF-RAY: 9c26dba3bfefdc4c-FRA
alt-svc: h3=":443"; ma=86400
Open service 104.21.80.1:443 · wp.purelydemos.com
2026-01-23 07:33
HTTP/1.1 200 OK
Date: Fri, 23 Jan 2026 07:33:34 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
X-Powered-By: PHP/8.3.30
X-Powered-By: PleskLin
Link: <https://wp.purelydemos.com/index.php?rest_route=/>; rel="https://api.w.org/"
Vary: Accept-Encoding
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=8,cfOrigin;dur=1469
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=Yua%2FYR8RftYozXBCMRo7Hv5NBzg0wJebvTvcFP88OvH2OP71zOzlToJ9CKBPmS3v%2FOjyWURx%2BFAnidbpCpeGcVj7FqaAszJfYQ7j1aFrlIcMaQ%3D%3D"}]}
cf-cache-status: DYNAMIC
CF-RAY: 9c259a836fadeb22-SJC
alt-svc: h3=":443"; ma=86400