Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43a81ce88f562b774ca7894bf46905fba96905fba9
Public Swagger UI/API detected at path: /swagger.json - sample paths: GET /coupons GET /coupons/hascoupon GET /coupons/verify GET /language
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d63a747c263a747c263a747c263a747c2
Found 1 files trough .DS_Store spidering: /application
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43a81ce88f562b774ca7894bf46905fba96905fba9
Public Swagger UI/API detected at path: /swagger.json - sample paths: GET /coupons GET /coupons/hascoupon GET /coupons/verify GET /language
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d63a747c263a747c263a747c263a747c2
Found 1 files trough .DS_Store spidering: /application
Open service 45.154.183.183:443 · thebakingtruth.com
2026-01-09 09:56
HTTP/1.1 403 Forbidden Date: Fri, 09 Jan 2026 09:56:41 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2273201 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: d5a9af14851844c8028d5a4a525f5c9d Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 45.154.183.183:80 · thebakingtruth.com
2026-01-09 09:56
HTTP/1.1 403 Forbidden Date: Fri, 09 Jan 2026 09:56:40 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2273199 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 0a20277dd017703fe7e2e5da03361c2f Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.135:443 · www.thebakingtruth.com
2025-12-22 07:47
HTTP/1.1 403 Forbidden Date: Mon, 22 Dec 2025 07:47:44 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 6340010 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 4fb02e20fb246490725a821a09637887 Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 45.154.183.183:443 · thebakingtruth.com
2025-12-22 05:31
HTTP/1.1 403 Forbidden Date: Mon, 22 Dec 2025 05:31:28 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 22454997 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 9efb660e808cfc686cde17107be4cfea Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.135:443 · www.thebakingtruth.com
2025-12-20 08:13
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 08:13:52 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 4800975 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: f002b008d35939cf018855d2ccd963bb Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 45.154.183.183:443 · thebakingtruth.com
2025-12-20 05:57
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 05:57:41 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 3433737 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 47df2292002ea43a66447fbbb0d557a1 Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.137:80 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:06 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2146495 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 2ddd0fd214148e0c692a86cf7f58dfd7 Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.173:80 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:06 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2507184 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 7e51f576794e0bb0da8d9cf4755bf81d Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.173:443 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 4381731 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 69b2686c030e4e40f394f8bb63b76a7b Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.170:443 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:06 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2959743 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: b4318dd85ccf66528ae0bb5f9072a857 Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.141:80 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2959737 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 58d76613df0510789574aab8c278f80e Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.139:443 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:06 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 4381735 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 9cffc66e6627943ab71de412bfc8a86c Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.141:443 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2959741 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 8932fa032706763f883da8897e59ce8a Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.166:80 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 4381725 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: d190b92c154e357e7651e3d085f6cbaf Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.166:443 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2740642 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 0c99d4a40560778c94751dfb24345b27 Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.139:80 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 4381729 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: dc2366724c0f4179c9a35a10af568cd0 Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.137:443 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:06 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2740658 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 2880a3791c650afe41795beaa11f2f2f Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.140:443 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2959735 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: fc5ca647711979904beab44c3dfbc0fd Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.134:443 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 4029516 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 60a8193ae4164ab23990f9065c039bcd Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.140:80 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 4381723 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: dc629cc9e4c0940bacc8302821abcd48 Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.134:80 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 4029512 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 8b1df770943fd8f90d8f1edff368bbb6 Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 207.120.36.170:80 · www.thebakingtruth.com
2025-12-20 02:56
HTTP/1.1 403 Forbidden Date: Sat, 20 Dec 2025 02:56:05 GMT Content-Type: text/html Content-Length: 118 Connection: close X-Varnish: 2740637 Age: 0 Via: 1.1 varnish (Varnish/6.3) section-io-cache: Miss section-io-id: 77375ff48c1f84c60f80b300348b3dfe Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>