Vercel
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d677d4e73ea63624ee0529661c59aa019176181f8c
GraphQL introspection enabled at /api/graphql Types: 437 (by kind: ENUM: 86, INPUT_OBJECT: 36, OBJECT: 295, SCALAR: 9, UNION: 11) Operations: - Query: SchemaExternalQuery | fields: activeStorageBlobsExternal, authenticateCreatorInstagramLink, campaignSuperfiliateMicrosite, campaignUtmParams, contentBrief - Mutation: SchemaExternalMutation | fields: externalCreateMedia, externalMicrositeClaimGift, externalMicrositeFindOrCreateGiftingShippingDiscount, externalMicrositeUpdateMicrositeCustomerSettings, externalMicrositeValidateExternalInvite - Subscription: SchemaExternalSubscription | fields: personalizationDraftChanged Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d644f07c12ab9ed2e2bac10ab0b7ff243d4149e7c0
GraphQL introspection enabled at /api/graphql Types: 433 (by kind: ENUM: 84, INPUT_OBJECT: 36, OBJECT: 293, SCALAR: 9, UNION: 11) Operations: - Query: SchemaExternalQuery | fields: activeStorageBlobsExternal, authenticateCreatorInstagramLink, campaignSuperfiliateMicrosite, campaignUtmParams, contentBrief - Mutation: SchemaExternalMutation | fields: externalCreateMedia, externalMicrositeClaimGift, externalMicrositeFindOrCreateGiftingShippingDiscount, externalMicrositeUpdateMicrositeCustomerSettings, externalMicrositeValidateExternalInvite - Subscription: SchemaExternalSubscription | fields: personalizationDraftChanged Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6e135c6b2967cc74211b291d0524c8f1d6a1adae0
GraphQL introspection enabled at /api/graphql Types: 432 (by kind: ENUM: 84, INPUT_OBJECT: 36, OBJECT: 292, SCALAR: 9, UNION: 11) Operations: - Query: SchemaExternalQuery | fields: activeStorageBlobsExternal, authenticateCreatorInstagramLink, campaignSuperfiliateMicrosite, campaignUtmParams, contentBrief - Mutation: SchemaExternalMutation | fields: externalCreateMedia, externalMicrositeClaimGift, externalMicrositeFindOrCreateGiftingShippingDiscount, externalMicrositeUpdateMicrositeCustomerSettings, externalMicrositeValidateExternalInvite - Subscription: SchemaExternalSubscription | fields: personalizationDraftChanged Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d624d9d7ee4afeb31e0ebd430cc3f55c811589379c
GraphQL introspection enabled at /api/graphql Types: 431 (by kind: ENUM: 84, INPUT_OBJECT: 36, OBJECT: 291, SCALAR: 9, UNION: 11) Operations: - Query: SchemaExternalQuery | fields: activeStorageBlobsExternal, authenticateCreatorInstagramLink, campaignSuperfiliateMicrosite, campaignUtmParams, contentBrief - Mutation: SchemaExternalMutation | fields: externalCreateMedia, externalMicrositeClaimGift, externalMicrositeFindOrCreateGiftingShippingDiscount, externalMicrositeUpdateMicrositeCustomerSettings, externalMicrositeValidateExternalInvite - Subscription: SchemaExternalSubscription | fields: personalizationDraftChanged Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d650edf58a6fe9ac3aa7583118a716002538f7bc48
GraphQL introspection enabled at /api/graphql Types: 423 (by kind: ENUM: 80, INPUT_OBJECT: 36, OBJECT: 287, SCALAR: 9, UNION: 11) Operations: - Query: SchemaExternalQuery | fields: activeStorageBlobsExternal, authenticateCreatorInstagramLink, campaignSuperfiliateMicrosite, campaignUtmParams, contentBrief - Mutation: SchemaExternalMutation | fields: externalCreateMedia, externalMicrositeClaimGift, externalMicrositeFindOrCreateGiftingShippingDiscount, externalMicrositeUpdateMicrositeCustomerSettings, externalMicrositeValidateExternalInvite - Subscription: SchemaExternalSubscription | fields: personalizationDraftChanged Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 216.150.1.129:80 · shop.jetsetcandy.com
2026-01-11 14:05
HTTP/1.0 308 Permanent Redirect Content-Type: text/plain Location: https://shop.jetsetcandy.com/ Refresh: 0;url=https://shop.jetsetcandy.com/ server: Vercel Redirecting...
Open service 216.150.1.65:443 · shop.jetsetcandy.com
2026-01-11 14:05
HTTP/1.1 307 Temporary Redirect Cache-Control: public, max-age=0, must-revalidate Content-Security-Policy: upgrade-insecure-requests Content-Type: text/plain Date: Sun, 11 Jan 2026 14:05:41 GMT Location: /portal Permissions-Policy: camera=(), microphone=(), payment=(), autoplay=* Server: Vercel Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Vercel-Id: lhr1::2zmmv-1768140341544-46a079f82c39 Connection: close Transfer-Encoding: chunked Redirecting...
Open service 216.150.1.129:443 · shop.jetsetcandy.com
2026-01-11 14:05
HTTP/1.1 307 Temporary Redirect Cache-Control: public, max-age=0, must-revalidate Content-Security-Policy: upgrade-insecure-requests Content-Type: text/plain Date: Sun, 11 Jan 2026 14:05:41 GMT Location: /portal Permissions-Policy: camera=(), microphone=(), payment=(), autoplay=* Server: Vercel Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Vercel-Id: fra1::wnhlk-1768140341539-f0662a287dad Connection: close Transfer-Encoding: chunked Redirecting...
Open service 216.150.1.65:80 · shop.jetsetcandy.com
2026-01-11 14:05
HTTP/1.0 308 Permanent Redirect Content-Type: text/plain Location: https://shop.jetsetcandy.com/ Refresh: 0;url=https://shop.jetsetcandy.com/ server: Vercel Redirecting...
Open service 216.150.1.65:443 · shop.jetsetcandy.com
2026-01-09 01:02
HTTP/1.1 307 Temporary Redirect Cache-Control: public, max-age=0, must-revalidate Content-Security-Policy: upgrade-insecure-requests Content-Type: text/plain Date: Fri, 09 Jan 2026 01:02:24 GMT Location: /portal Permissions-Policy: camera=(), microphone=(), payment=(), autoplay=* Server: Vercel Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Vercel-Id: iad1::jfs29-1767920544034-90f6f2c53275 Connection: close Transfer-Encoding: chunked Redirecting...
Open service 216.150.1.65:443 · shop.jetsetcandy.com
2026-01-02 03:35
HTTP/1.1 307 Temporary Redirect Cache-Control: public, max-age=0, must-revalidate Content-Security-Policy: upgrade-insecure-requests Content-Type: text/plain Date: Fri, 02 Jan 2026 03:35:52 GMT Location: /portal Permissions-Policy: camera=(), microphone=(), payment=(), autoplay=* Server: Vercel Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Vercel-Id: fra1::zdlnm-1767324952906-decae5c4c573 Connection: close Transfer-Encoding: chunked Redirecting...
Open service 216.150.1.65:443 · shop.jetsetcandy.com
2025-12-30 10:52
HTTP/1.1 307 Temporary Redirect Cache-Control: public, max-age=0, must-revalidate Content-Security-Policy: upgrade-insecure-requests Content-Type: text/plain Date: Tue, 30 Dec 2025 10:52:39 GMT Location: /portal Permissions-Policy: camera=(), microphone=(), payment=(), autoplay=* Server: Vercel Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Vercel-Id: iad1::8hkc2-1767091959019-1bfce13bdcdb Connection: close Transfer-Encoding: chunked Redirecting...
Open service 216.150.1.65:443 · shop.jetsetcandy.com
2025-12-22 16:12
HTTP/1.1 307 Temporary Redirect Cache-Control: public, max-age=0, must-revalidate Content-Security-Policy: upgrade-insecure-requests Content-Type: text/plain Date: Mon, 22 Dec 2025 16:12:40 GMT Location: /portal Permissions-Policy: camera=(), microphone=(), payment=(), autoplay=* Server: Vercel Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Vercel-Id: sin1::4rlbg-1766419960492-10f6fc9a3ec5 Connection: close Transfer-Encoding: chunked Redirecting...
Open service 216.150.1.65:443 · shop.jetsetcandy.com
2025-12-20 16:46
HTTP/1.1 307 Temporary Redirect Cache-Control: public, max-age=0, must-revalidate Content-Security-Policy: upgrade-insecure-requests Content-Type: text/plain Date: Sat, 20 Dec 2025 16:46:15 GMT Location: /portal Permissions-Policy: camera=(), microphone=(), payment=(), autoplay=* Server: Vercel Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Vercel-Id: iad1::dvw87-1766249175254-cd5773e659eb Connection: close Transfer-Encoding: chunked Redirecting...