cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa374c2942e74c2942e74c2942e74c2942e74c2942e
GraphQL introspection enabled at /graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2df9b2641df9b2641df9b2641df9b2641df9b2641
GraphQL introspection enabled at /graphql/api Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a7edf4f1b1e35dd9d9b3c9a7b2b4097b0a1b0df
GraphQL introspection enabled at /graphql Types: 1018 (by kind: ENUM: 81, INPUT_OBJECT: 256, INTERFACE: 34, OBJECT: 637, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: MpRewardConfig, MpRewardIcon, MpRewardShoppingCartSpendingRules, NewestBlogPosts, RelatedBlogPosts - Mutation: Mutation | fields: AmxnotifStockSubscribe, MpRewardInvite, MpRewardRefer, MpRewardSpendingPoint, MpRewardSubscribe Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2
GraphQL introspection enabled at /graphql/api
Open service 188.114.97.3:443 · si.staging24.gymbeam.dev
2026-01-23 02:24
HTTP/1.1 200 OK
Date: Fri, 23 Jan 2026 02:24:14 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=bTkCyYDd7e2CKXf0QSdsmm%2FG7znRbcvS6oDunQ7fL86eyYfd5Vfg7I4niucsmT7fugjM3Pm5WU1WWR6hgs1D8gFRvWap7KtefJ5X3ptx5GNxIPBA7N15"}]}
cross-origin-opener-policy: same-origin-allow-popups
cross-origin-resource-policy: same-origin
link: <https://si.staging24.gymbeam.dev/media/gymbeam/bannerslider/s/i/si-slider-mobile_copy_7.jpg>; rel=preload; as="image"; fetchpriority="high", <https://si.staging24.gymbeam.dev/media/gymbeam/bannerslider/s/i/si-slider-desktop_copy_7.jpg>; rel=preload; as="image"; fetchpriority="high", <https://gymbeam.sk/media/.renditions/wysiwyg/schudnut.jpg?v=1>; rel=preload; as="image"; imagesizes="(max-width: 640px) 173px%2C (max-width: 1024px) 216px%2C 260px"; fetchpriority="high", <https://gymbeam.sk/media/.renditions/wysiwyg/budovatSvalovuHmotu.png?v=1>; rel=preload; as="image"; imagesizes="(max-width: 640px) 173px%2C (max-width: 1024px) 216px%2C 260px"; fetchpriority="high", <https://gymbeam.sk/media/.renditions/wysiwyg/podporitRegeneraciu.jpg?v=1>; rel=preload; as="image"; imagesizes="(max-width: 640px) 173px%2C (max-width: 1024px) 216px%2C 260px"; fetchpriority="high", <https://gymbeam.sk/media/.renditions/wysiwyg/zlepsitVyhon.jpg?v=1>; rel=preload; as="image"; imagesizes="(max-width: 640px) 173px%2C (max-width: 1024px) 216px%2C 260px"; fetchpriority="high", <https://gymbeam.sk/media/.renditions/wysiwyg/zdravsieMaskrtit.jpg?v=1>; rel=preload; as="image"; imagesizes="(max-width: 640px) 173px%2C (max-width: 1024px) 216px%2C 260px"; fetchpriority="high", <https://gymbeam.sk/media/.renditions/wysiwyg/zacatCvicitDoma.jpg?v=1>; rel=preload; as="image"; imagesizes="(max-width: 640px) 173px%2C (max-width: 1024px) 216px%2C 260px"; fetchpriority="high", <https://gymbeam.sk/media/.renditions/wysiwyg/podporitImunitu.jpg?v=1>; rel=preload; as="image"; imagesizes="(max-width: 640px) 173px%2C (max-width: 1024px) 216px%2C 260px"; fetchpriority="high", <https://gymbeam.sk/media/.renditions/wysiwyg/sportoveOblecenie.jpg?v=1>; rel=preload; as="image"; imagesizes="(max-width: 640px) 173px%2C (max-width: 1024px) 216px%2C 260px"; fetchpriority="high"
origin-agent-cluster: ?1
referrer-policy: strict-origin-when-cross-origin
Set-Cookie: NEXT_LOCALE=sl; Path=/; SameSite=lax
store: gymbeamsi
strict-transport-security: max-age=631138519; includeSubDomains
user-agent: Mozilla/5.0 (l9scan/2.0.33e27393e2431313e2838313; +https://leakix.net)
vary: Accept-Encoding
vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, Accept-Encoding
x-content-type-options: nosniff
x-customer-segment: 0db377921f4ce762c62526131097968f
x-download-options: noopen
x-forwarded-url: https://si.staging24.gymbeam.dev/
x-frame-options: SAMEORIGIN
x-magento-tags: store,cms_b,mp_smtp_script,cat_c,cms_b_footer_block_link_customer_service,cms_b_footer_block_link_social_media,cms_b_footer_block_link_certifications,cms_b_footer_block_link_contact,cms_p_8246,react_homepage
x-middleware-rewrite: /sl
x-permitted-cross-domain-policies: none
x-powered-by: Next.js
x-request-start-time: 1769135054341
x-trace-id: -
x-xss-protection: 0
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=11,cfOrigin;dur=82
CF-RAY: 9c23d56968cd641b-LHR
Open service 188.114.97.3:443 · si.staging24.gymbeam.dev
2026-01-09 13:44
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 13:45:00 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=EPlL%2Bw1z6EN6hGRaycNXXC17FlOG3wMi%2FCxux%2BsDXzKV6mLogHjZqHtbCNXpkXolxA%2BsY6kEBV6vuJxtLeOTkPjmjG24Hu9M1WmMTwjgyXZa1toJjK2J"}]}
cross-origin-opener-policy: same-origin-allow-popups
cross-origin-resource-policy: same-origin
origin-agent-cluster: ?1
referrer-policy: strict-origin-when-cross-origin
store: gymbeamsi
strict-transport-security: max-age=631138519; includeSubDomains
user-agent: Mozilla/5.0 (l9scan/2.0.33e27393e2431313e2838313; +https://leakix.net)
vary: Accept-Encoding
vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
x-content-type-options: nosniff
x-customer-segment: 0db377921f4ce762c62526131097968f
x-download-options: noopen
x-forwarded-url: https://si.staging24.gymbeam.dev/
x-frame-options: SAMEORIGIN
x-magento-tags: store,cms_b,mp_smtp_script,cat_c,cms_b_footer_block_link_customer_service,cms_b_footer_block_link_social_media,cms_b_footer_block_link_certifications,cms_b_footer_block_link_contact,cms_p_8246,react_homepage
x-middleware-rewrite: /sl
x-permitted-cross-domain-policies: none
x-powered-by: Next.js
x-trace-id: r6Fw5xUZW5emWGzxaZApq
x-xss-protection: 0
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=6,cfOrigin;dur=213
CF-RAY: 9bb45f5e2a36b549-EWR
Open service 188.114.97.3:443 · si.staging24.gymbeam.dev
2026-01-02 13:35
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 13:35:05 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=WqhbzFsJI4sBplndcQmrM%2BH7%2BpUHSM2y88KsuWBvTKb7A7etSxyogFlJUOZI2anIHRRBULO9qL9v2mfL%2BA2bapkjNOro0XZ0Ibe6a3I0EZJep8bN5vgk"}]}
cross-origin-opener-policy: same-origin-allow-popups
cross-origin-resource-policy: same-origin
origin-agent-cluster: ?1
referrer-policy: strict-origin-when-cross-origin
store: gymbeamsi
strict-transport-security: max-age=631138519; includeSubDomains
user-agent: Mozilla/5.0 (l9scan/2.0.33e27393e2431313e2838313; +https://leakix.net)
vary: Accept-Encoding
vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
x-content-type-options: nosniff
x-customer-segment: 0db377921f4ce762c62526131097968f
x-download-options: noopen
x-forwarded-url: https://si.staging24.gymbeam.dev/
x-frame-options: SAMEORIGIN
x-magento-tags: store,cms_b,mp_smtp_script,cat_c,cms_b_footer_block_link_customer_service,cms_b_footer_block_link_social_media,cms_b_footer_block_link_certifications,cms_b_footer_block_link_contact,cms_p_8246,react_homepage
x-middleware-rewrite: /sl
x-permitted-cross-domain-policies: none
x-powered-by: Next.js
x-trace-id: bIV-GDS4n5VyqGkbCeEw-
x-xss-protection: 0
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=7,cfOrigin;dur=218
CF-RAY: 9b7aa33779f435ae-YYZ
Open service 188.114.97.3:443 · si.staging24.gymbeam.dev
2025-12-23 06:58
HTTP/1.1 200 OK
Date: Tue, 23 Dec 2025 06:58:03 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=3uFUJ7OZKstE4ZVFr5wTfBWsldHBEnVUXbarXb4DVoFhRHkEKp72Q%2Bk6GR4dcG%2F5u%2FV6U3iPnLQDbyX9FASmpJwg7k0s%2F07AOBJEbcsixIwtY%2B91xQ%3D%3D"}]}
cross-origin-opener-policy: same-origin-allow-popups
cross-origin-resource-policy: same-origin
origin-agent-cluster: ?1
referrer-policy: strict-origin-when-cross-origin
store: gymbeamsi
strict-transport-security: max-age=631138519; includeSubDomains
user-agent: Mozilla/5.0 (l9scan/2.0.33e27393e2431313e2838313; +https://leakix.net)
vary: Accept-Encoding
vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Accept-Encoding
x-content-type-options: nosniff
x-customer-segment: 0db377921f4ce762c62526131097968f
x-download-options: noopen
x-forwarded-url: https://si.staging24.gymbeam.dev/
x-frame-options: SAMEORIGIN
x-magento-tags: store,cms_b,mp_smtp_script,cat_c,cms_b_footer_block_link_customer_service,cms_b_footer_block_link_social_media,cms_b_footer_block_link_certifications,cms_b_footer_block_link_contact,cms_p_8246,react_homepage
x-middleware-rewrite: /sl
x-permitted-cross-domain-policies: none
x-powered-by: Next.js
x-trace-id: mSCY48lBQmkt8SLoJsgWo
x-xss-protection: 0
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=9,cfOrigin;dur=143
CF-RAY: 9b25f7e18b0e0c90-EWR