Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6d6f7266f4bfe653dec1f4d939048a6e996486034
GraphQL introspection enabled at /api/graphql Types: 272 (by kind: ENUM: 18, INPUT_OBJECT: 83, INTERFACE: 1, OBJECT: 164, SCALAR: 6) Operations: - Query: RootQueryType | fields: accounts, certificationExam, certificationProgresses, courses, currentAccount - Mutation: RootMutationType | fields: acceptTerms, addCourseAssets, addSimulation, addVrVideoExample, cancelReminder - Subscription: RootSubscriptionType | fields: notificationFeed, seedCourseFeed Directives: include, skip (total: 2)
Open service 75.2.60.68:443 · staging-api.certify-ed.com
2026-01-09 22:56
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 22:56:33 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=tJPY5qfJHBBR3E%2BG9WR6ulxD%2BK58cpcv0fxslzbbLrY%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767999393"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=tJPY5qfJHBBR3E%2BG9WR6ulxD%2BK58cpcv0fxslzbbLrY%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767999393"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: e6013560-bb37-748a-6f38-5788e381ddea
Connection: close
hello
Open service 75.2.60.68:443 · staging-api.certify-ed.com
2025-12-30 12:02
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 12:02:35 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=uA0quY78SxnlL9Gn88BPtf6NMM6%2FoQ2sL0rpwHtPZEo%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767096156"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=uA0quY78SxnlL9Gn88BPtf6NMM6%2FoQ2sL0rpwHtPZEo%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767096156"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: d7c24d31-038d-b156-3797-8f94caa7d9b0
Connection: close
hello
Open service 75.2.60.68:443 · staging-api.certify-ed.com
2025-12-22 13:24
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 13:24:56 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=kH9MN4GTWBCz0mYuSqaNV97pw0LmHVM00eGlZUT%2BeUs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766409896"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=kH9MN4GTWBCz0mYuSqaNV97pw0LmHVM00eGlZUT%2BeUs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766409896"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: 5503b6ed-4cb0-33b5-d059-b7740d9093ec
Connection: close
hello
Open service 75.2.60.68:443 · staging-api.certify-ed.com
2025-12-20 14:09
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers:
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 5
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 14:09:22 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=afYFSE9ojNmOPnbPhACDSzHzHGqrOHW7I86nERCZSC0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766239763"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=afYFSE9ojNmOPnbPhACDSzHzHGqrOHW7I86nERCZSC0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766239763"
Server: Heroku
Strict-Transport-Security: max-age=31536000
Via: 1.1 heroku-router
X-Request-Id: ea6b3f69-404c-280d-8a86-3828e6e93c7a
Connection: close
hello