cloudflare
tcp/443 tcp/80 tcp/8443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18cfa8f453b1d421c24de2e2e6cf00f4315
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/billing/balance
ANY /v1/admin/document/list
ANY /v1/annotations/email
ANY /v1/billing/buy-credits
ANY /v1/billing/credit-consumption
ANY /v1/billing/credit-consumption/download
ANY /v1/billing/plans/company
ANY /v1/companies/change/{company}
ANY /v1/companies/comms-language
ANY /v1/companies/customisations
ANY /v1/companies/customisations/{company}
ANY /v1/companies/documents/{type}
ANY /v1/companies/managed
ANY /v1/company-users/companies/{company}
ANY /v1/company-users/invite
ANY /v1/company-users/invite/email-confirmation/{token}
ANY /v1/company-users/users/{email}
ANY /v1/costcenters
ANY /v1/custom/objects/qb-terms/companies/{company}
ANY /v1/custom/twinfield/customer/{company}/{email}
ANY /v1/dimensions/costcenters/code/{code}
ANY /v1/dimensions/costcenters/companies/{company}
ANY /v1/dimensions/glaccounts/code/{code}
ANY /v1/dimensions/glaccounts/companies/{company}
ANY /v1/dimensions/glaccounts/periods/companies/{company}
ANY /v1/dimensions/glaccounts/years/companies/{company}
ANY /v1/dimensions/projects/code/{code}
ANY /v1/dimensions/projects/companies/{company}
ANY /v1/dimensions/vatcodes/code/{code}
ANY /v1/dimensions/vatcodes/companies/{company}
ANY /v1/dimensions/{dimension}/export/{format}
ANY /v1/dimensions/{dimension}/import
ANY /v1/dimensions/{dimension}/import/map
ANY /v1/doc
ANY /v1/documents
ANY /v1/documents/archived/company/{company}
ANY /v1/documents/archived/id/company/{company}
ANY /v1/documents/assistant
ANY /v1/documents/assistant-id/{assistantID}
ANY /v1/documents/assistant/resend
ANY /v1/documents/boundaries/{assistantID}
ANY /v1/documents/bulk/download
ANY /v1/documents/bulk/owner
ANY /v1/documents/bulk/status
ANY /v1/documents/company/{company}
ANY /v1/documents/delete
ANY /v1/documents/delete/duplicates
ANY /v1/documents/export/bulk/{type}
ANY /v1/documents/export/email/{type}
ANY /v1/documents/export/file/{filename}
ANY /v1/documents/export/gstock
ANY /v1/documents/export/list/{company}
ANY /v1/documents/export/mapping/{deliveryFormat}
ANY /v1/documents/export/{format}/{assistantID}
ANY /v1/documents/id/company/{company}
ANY /v1/documents/line-boundaries
ANY /v1/documents/lines/export/{id}
ANY /v1/documents/owner
ANY /v1/documents/reprocess
ANY /v1/documents/status
ANY /v1/documents/upload/internal
ANY /v1/documents/upload/split
ANY /v1/documents/upload/split/ai/{document}
ANY /v1/documents/upload/split/bulk
ANY /v1/documents/uploads/email/logs
ANY /v1/documents/url
ANY /v1/documents/xml/{assistantID}
ANY /v1/documents/zapier
ANY /v1/downloads/dashboard/{company}
ANY /v1/downloads/partner-stats
ANY /v1/email/parse
ANY /v1/email/parse/text
ANY /v1/fields/new
ANY /v1/fields/new/training
ANY /v1/fields/{entity}/{company}
ANY /v1/files/attachments/{name}
ANY /v1/files/documents/signed/{document}
ANY /v1/files/documents/{document}
ANY /v1/files/invoices/images/company/{company}/transaction/{transaction}
ANY /v1/files/invoices/images/transaction/{transaction}
ANY /v1/glaccounts
ANY /v1/integrations
ANY /v1/integrations/api/assistant/manage/{company}
ANY /v1/integrations/api/connection
ANY /v1/integrations/bc/email
ANY /v1/integrations/bc/manage/{company}
ANY /v1/integrations/details
ANY /v1/integrations/email/deliver/allowed
ANY /v1/integrations/email/deliver/format
ANY /v1/integrations/email/receive/allowed
ANY /v1/integrations/gdrive/connection/{company}
ANY /v1/integrations/gdrive/notify/webhook
ANY /v1/integrations/gdrive/oauth2/callback
ANY /v1/integrations/gdrive/{company}
ANY /v1/integrations/gstock/connection/{company}
ANY /v1/integrations/gstock/sync
ANY /v1/integrations/gstock/{company}
ANY /v1/integrations/hacienda
ANY /v1/integrations/hacienda/close-period
ANY /v1/integrations/hacienda/closing-periods/{company}
ANY /v1/integrations/hacienda/details
ANY /v1/integrations/holded/connection/{company}
ANY /v1/integrations/holded/{company}
ANY /v1/integrations/mapping
ANY /v1/integrations/notify
ANY /v1/integrations/quickbooks/connection/{company}
ANY /v1/integrations/quickbooks/oauth2/callback
ANY /v1/integrations/quickbooks/vendor
ANY /v1/integrations/quickbooks/{company}
ANY /v1/integrations/request
ANY /v1/integrations/sftp/connection/{type}
ANY /v1/integrations/sftp/dimension/sync
ANY /v1/integrations/sftp/{type}
ANY /v1/integrations/sync-dimensions/holded/{company}
ANY /v1/integrations/twinfield
ANY /v1/integrations/twinfield/token/callback
ANY /v1/integrations/twinfield/{company}
ANY /v1/integrations/update
ANY /v1/integrations/{app}/api
ANY /v1/invoices/{id}/actions/spread
ANY /v1/offices
ANY /v1/offices/{code}
ANY /v1/partners/customers
ANY /v1/processes/webhook
ANY /v1/processes/{code}/status
ANY /v1/products/import/gstock
ANY /v1/projects
ANY /v1/stats/graph
ANY /v1/stats/overview
ANY /v1/subscriptions/cancel
ANY /v1/subscriptions/cards/change
ANY /v1/subscriptions/cards/customers
ANY /v1/subscriptions/customers
ANY /v1/subscriptions/customers/contact
ANY /v1/subscriptions/customers/extra
ANY /v1/subscriptions/dunning
ANY /v1/subscriptions/invoices
ANY /v1/subscriptions/invoices/{id}
ANY /v1/subscriptions/payment-failure
ANY /v1/subscriptions/payment-success
ANY /v1/subscriptions/renewal
ANY /v1/subscriptions/renewal-failure
ANY /v1/subscriptions/verify/{company}
ANY /v1/suppliers
ANY /v1/suppliers/export/{company}
ANY /v1/suppliers/find/all/{company}
ANY /v1/suppliers/get/all/{company}
ANY /v1/suppliers/import/gstock
ANY /v1/suppliers/{creditorCode}
ANY /v1/users/stats
ANY /v1/users/stats/db
ANY /v1/vatcodes
ANY /v1/workflows/{workflow}/status
ANY /v1/workflows/{workflow}/structure
ANY /v2/document-types
ANY /v2/document-types/all/brand
ANY /v2/document-types/all/import
ANY /v2/document-types/companies/{company}
ANY /v2/document-types/create/fields/llm
ANY /v2/document-types/create/process/docs
ANY /v2/document-types/fields
ANY /v2/document-types/file/{documentType}
ANY /v2/document-types/llm/field-details
ANY /v2/document-types/llm/recent-files
ANY /v2/document-types/mark/default
ANY /v2/document-types/min/company
ANY /v2/document-types/signup/{company}
ANY /v2/document-types/{documentType}
ANY /v2/document-types/{documentType}/{company}
ANY /v2/document-types/{documentType}/{section}/fields/{field}
ANY /v2/documents/boundaries/{id}
ANY /v2/documents/bulk/owner
ANY /v2/documents/bulk/status
ANY /v2/documents/company
ANY /v2/documents/export/bulk/{type}
ANY /v2/documents/export/email/{type}
ANY /v2/documents/export/{format}/{id}
ANY /v2/documents/id/{id}
ANY /v2/documents/ids/company
ANY /v2/documents/llm/{docID}
ANY /v2/documents/owner
ANY /v2/documents/status
ANY /v2/documents/xml/{id}
ANY /v2/fields/doc-types/generate/description
ANY /v2/fields/doc-types/{docType}/sections/{section}/{company}
ANY /v2/fields/doc-types/{docType}/{company}
ANY /v2/projects
ANY /v2/projects/workflows/company/min/{company}
ANY /v2/projects/workflows/company/{company}
ANY /v2/projects/{project}
ANY /v2/projects/{project}/workflows
ANY /v2/projects/{project}/workflows/{workflow}
ANY /v2/suppliers/{creditorCode}/{company}
ANY /v2/workflows/{workflowID}/component/{componentType}
ANY /v2/workflows/{workflowID}/{id}
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18cfa8f453b1d421c24de2e2e6c8bd2ce5c
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/billing/balance
ANY /v1/admin/document/list
ANY /v1/annotations/email
ANY /v1/billing/buy-credits
ANY /v1/billing/credit-consumption
ANY /v1/billing/credit-consumption/download
ANY /v1/billing/plans/company
ANY /v1/companies/change/{company}
ANY /v1/companies/comms-language
ANY /v1/companies/customisations
ANY /v1/companies/customisations/{company}
ANY /v1/companies/documents/{type}
ANY /v1/companies/managed
ANY /v1/company-users/companies/{company}
ANY /v1/company-users/invite
ANY /v1/company-users/invite/email-confirmation/{token}
ANY /v1/company-users/users/{email}
ANY /v1/costcenters
ANY /v1/custom/objects/qb-terms/companies/{company}
ANY /v1/custom/twinfield/customer/{company}/{email}
ANY /v1/dimensions/costcenters/code/{code}
ANY /v1/dimensions/costcenters/companies/{company}
ANY /v1/dimensions/glaccounts/code/{code}
ANY /v1/dimensions/glaccounts/companies/{company}
ANY /v1/dimensions/glaccounts/periods/companies/{company}
ANY /v1/dimensions/glaccounts/years/companies/{company}
ANY /v1/dimensions/projects/code/{code}
ANY /v1/dimensions/projects/companies/{company}
ANY /v1/dimensions/vatcodes/code/{code}
ANY /v1/dimensions/vatcodes/companies/{company}
ANY /v1/dimensions/{dimension}/export/{format}
ANY /v1/dimensions/{dimension}/import
ANY /v1/dimensions/{dimension}/import/map
ANY /v1/doc
ANY /v1/documents
ANY /v1/documents/archived/company/{company}
ANY /v1/documents/archived/id/company/{company}
ANY /v1/documents/assistant
ANY /v1/documents/assistant-id/{assistantID}
ANY /v1/documents/assistant/resend
ANY /v1/documents/boundaries/{assistantID}
ANY /v1/documents/bulk/download
ANY /v1/documents/bulk/owner
ANY /v1/documents/bulk/status
ANY /v1/documents/company/{company}
ANY /v1/documents/delete
ANY /v1/documents/delete/duplicates
ANY /v1/documents/export/bulk/{type}
ANY /v1/documents/export/email/{type}
ANY /v1/documents/export/file/{filename}
ANY /v1/documents/export/gstock
ANY /v1/documents/export/list/{company}
ANY /v1/documents/export/mapping/{deliveryFormat}
ANY /v1/documents/export/{format}/{assistantID}
ANY /v1/documents/id/company/{company}
ANY /v1/documents/line-boundaries
ANY /v1/documents/lines/export/{id}
ANY /v1/documents/owner
ANY /v1/documents/status
ANY /v1/documents/upload/split
ANY /v1/documents/upload/split/ai/{document}
ANY /v1/documents/upload/split/bulk
ANY /v1/documents/uploads/email/logs
ANY /v1/documents/url
ANY /v1/documents/xml/{assistantID}
ANY /v1/documents/zapier
ANY /v1/downloads/dashboard/{company}
ANY /v1/downloads/partner-stats
ANY /v1/email/parse
ANY /v1/email/parse/text
ANY /v1/fields/new
ANY /v1/fields/new/training
ANY /v1/fields/{entity}/{company}
ANY /v1/files/attachments/{name}
ANY /v1/files/documents/signed/{document}
ANY /v1/files/documents/{document}
ANY /v1/files/invoices/images/company/{company}/transaction/{transaction}
ANY /v1/files/invoices/images/transaction/{transaction}
ANY /v1/glaccounts
ANY /v1/integrations
ANY /v1/integrations/api/assistant/manage/{company}
ANY /v1/integrations/api/connection
ANY /v1/integrations/bc/email
ANY /v1/integrations/bc/manage/{company}
ANY /v1/integrations/details
ANY /v1/integrations/email/deliver/allowed
ANY /v1/integrations/email/deliver/format
ANY /v1/integrations/email/receive/allowed
ANY /v1/integrations/gdrive/connection/{company}
ANY /v1/integrations/gdrive/notify/webhook
ANY /v1/integrations/gdrive/oauth2/callback
ANY /v1/integrations/gdrive/{company}
ANY /v1/integrations/gstock/connection/{company}
ANY /v1/integrations/gstock/sync
ANY /v1/integrations/gstock/{company}
ANY /v1/integrations/hacienda
ANY /v1/integrations/hacienda/close-period
ANY /v1/integrations/hacienda/closing-periods/{company}
ANY /v1/integrations/hacienda/details
ANY /v1/integrations/holded/connection/{company}
ANY /v1/integrations/holded/{company}
ANY /v1/integrations/mapping
ANY /v1/integrations/notify
ANY /v1/integrations/quickbooks/connection/{company}
ANY /v1/integrations/quickbooks/oauth2/callback
ANY /v1/integrations/quickbooks/vendor
ANY /v1/integrations/quickbooks/{company}
ANY /v1/integrations/request
ANY /v1/integrations/sftp/connection/{type}
ANY /v1/integrations/sftp/dimension/sync
ANY /v1/integrations/sftp/{type}
ANY /v1/integrations/sync-dimensions/holded/{company}
ANY /v1/integrations/twinfield
ANY /v1/integrations/twinfield/token/callback
ANY /v1/integrations/twinfield/{company}
ANY /v1/integrations/update
ANY /v1/integrations/{app}/api
ANY /v1/invoices/{id}/actions/spread
ANY /v1/offices
ANY /v1/offices/{code}
ANY /v1/partners/customers
ANY /v1/processes/webhook
ANY /v1/processes/{code}/status
ANY /v1/products/import/gstock
ANY /v1/projects
ANY /v1/stats/graph
ANY /v1/stats/overview
ANY /v1/subscriptions/cancel
ANY /v1/subscriptions/cards/change
ANY /v1/subscriptions/cards/customers
ANY /v1/subscriptions/customers
ANY /v1/subscriptions/customers/contact
ANY /v1/subscriptions/customers/extra
ANY /v1/subscriptions/dunning
ANY /v1/subscriptions/invoices
ANY /v1/subscriptions/invoices/{id}
ANY /v1/subscriptions/payment-failure
ANY /v1/subscriptions/payment-success
ANY /v1/subscriptions/renewal
ANY /v1/subscriptions/renewal-failure
ANY /v1/subscriptions/verify/{company}
ANY /v1/suppliers
ANY /v1/suppliers/export/{company}
ANY /v1/suppliers/find/all/{company}
ANY /v1/suppliers/get/all/{company}
ANY /v1/suppliers/import/gstock
ANY /v1/suppliers/{creditorCode}
ANY /v1/users/stats
ANY /v1/users/stats/db
ANY /v1/vatcodes
ANY /v1/workflows/{workflow}/status
ANY /v1/workflows/{workflow}/structure
ANY /v2/document-types
ANY /v2/document-types/all/brand
ANY /v2/document-types/all/import
ANY /v2/document-types/companies/{company}
ANY /v2/document-types/fields
ANY /v2/document-types/file/{documentType}
ANY /v2/document-types/llm/field-details
ANY /v2/document-types/llm/recent-files
ANY /v2/document-types/mark/default
ANY /v2/document-types/min/company
ANY /v2/document-types/signup/{company}
ANY /v2/document-types/{documentType}
ANY /v2/document-types/{documentType}/{company}
ANY /v2/document-types/{documentType}/{section}/fields/{field}
ANY /v2/documents/boundaries/{id}
ANY /v2/documents/bulk/owner
ANY /v2/documents/bulk/status
ANY /v2/documents/company
ANY /v2/documents/export/bulk/{type}
ANY /v2/documents/export/email/{type}
ANY /v2/documents/export/{format}/{id}
ANY /v2/documents/id/{id}
ANY /v2/documents/ids/company
ANY /v2/documents/llm/{docID}
ANY /v2/documents/owner
ANY /v2/documents/status
ANY /v2/documents/xml/{id}
ANY /v2/fields/doc-types/generate/description
ANY /v2/fields/doc-types/{docType}/sections/{section}/{company}
ANY /v2/fields/doc-types/{docType}/{company}
ANY /v2/projects
ANY /v2/projects/workflows/company/min/{company}
ANY /v2/projects/workflows/company/{company}
ANY /v2/projects/{project}
ANY /v2/projects/{project}/workflows
ANY /v2/projects/{project}/workflows/{workflow}
ANY /v2/suppliers/{creditorCode}/{company}
ANY /v2/workflows/{workflowID}/component/{componentType}
ANY /v2/workflows/{workflowID}/{id}
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18cfa8f453b1d421c24de2e2e6cec03e64e
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/billing/balance
ANY /v1/admin/document/list
ANY /v1/annotations/email
ANY /v1/billing/buy-credits
ANY /v1/billing/credit-consumption
ANY /v1/billing/credit-consumption/download
ANY /v1/billing/plans/company
ANY /v1/companies/change/{company}
ANY /v1/companies/comms-language
ANY /v1/companies/customisations
ANY /v1/companies/customisations/{company}
ANY /v1/companies/documents/{type}
ANY /v1/companies/managed
ANY /v1/company-users/companies/{company}
ANY /v1/company-users/invite
ANY /v1/company-users/invite/email-confirmation/{token}
ANY /v1/company-users/users/{email}
ANY /v1/costcenters
ANY /v1/custom/objects/qb-terms/companies/{company}
ANY /v1/custom/twinfield/customer/{company}/{email}
ANY /v1/dimensions/costcenters/code/{code}
ANY /v1/dimensions/costcenters/companies/{company}
ANY /v1/dimensions/glaccounts/code/{code}
ANY /v1/dimensions/glaccounts/companies/{company}
ANY /v1/dimensions/glaccounts/periods/companies/{company}
ANY /v1/dimensions/glaccounts/years/companies/{company}
ANY /v1/dimensions/projects/code/{code}
ANY /v1/dimensions/projects/companies/{company}
ANY /v1/dimensions/vatcodes/code/{code}
ANY /v1/dimensions/vatcodes/companies/{company}
ANY /v1/dimensions/{dimension}/export/{format}
ANY /v1/dimensions/{dimension}/import
ANY /v1/dimensions/{dimension}/import/map
ANY /v1/doc
ANY /v1/documents
ANY /v1/documents/archived/company/{company}
ANY /v1/documents/archived/id/company/{company}
ANY /v1/documents/assistant
ANY /v1/documents/assistant-id/{assistantID}
ANY /v1/documents/assistant/resend
ANY /v1/documents/boundaries/{assistantID}
ANY /v1/documents/bulk/download
ANY /v1/documents/bulk/owner
ANY /v1/documents/bulk/status
ANY /v1/documents/company/{company}
ANY /v1/documents/delete
ANY /v1/documents/delete/duplicates
ANY /v1/documents/export/bulk/{type}
ANY /v1/documents/export/email/{type}
ANY /v1/documents/export/file/{filename}
ANY /v1/documents/export/gstock
ANY /v1/documents/export/list/{company}
ANY /v1/documents/export/mapping/{deliveryFormat}
ANY /v1/documents/export/{format}/{assistantID}
ANY /v1/documents/id/company/{company}
ANY /v1/documents/line-boundaries
ANY /v1/documents/lines/export/{id}
ANY /v1/documents/owner
ANY /v1/documents/status
ANY /v1/documents/upload/split
ANY /v1/documents/upload/split/ai/{document}
ANY /v1/documents/upload/split/bulk
ANY /v1/documents/uploads/email/logs
ANY /v1/documents/url
ANY /v1/documents/xml/{assistantID}
ANY /v1/documents/zapier
ANY /v1/downloads/dashboard/{company}
ANY /v1/downloads/partner-stats
ANY /v1/email/parse
ANY /v1/email/parse/text
ANY /v1/fields/new
ANY /v1/fields/new/training
ANY /v1/fields/{entity}/{company}
ANY /v1/files/attachments/{name}
ANY /v1/files/documents/signed/{document}
ANY /v1/files/documents/{document}
ANY /v1/files/invoices/images/company/{company}/transaction/{transaction}
ANY /v1/files/invoices/images/transaction/{transaction}
ANY /v1/glaccounts
ANY /v1/integrations
ANY /v1/integrations/api/assistant/manage/{company}
ANY /v1/integrations/bc/email
ANY /v1/integrations/bc/manage/{company}
ANY /v1/integrations/details
ANY /v1/integrations/email/deliver/allowed
ANY /v1/integrations/email/deliver/format
ANY /v1/integrations/email/receive/allowed
ANY /v1/integrations/gdrive/connection/{company}
ANY /v1/integrations/gdrive/notify/webhook
ANY /v1/integrations/gdrive/oauth2/callback
ANY /v1/integrations/gdrive/{company}
ANY /v1/integrations/gstock/connection/{company}
ANY /v1/integrations/gstock/sync
ANY /v1/integrations/gstock/{company}
ANY /v1/integrations/hacienda
ANY /v1/integrations/hacienda/close-period
ANY /v1/integrations/hacienda/closing-periods/{company}
ANY /v1/integrations/hacienda/details
ANY /v1/integrations/holded/connection/{company}
ANY /v1/integrations/holded/{company}
ANY /v1/integrations/mapping
ANY /v1/integrations/notify
ANY /v1/integrations/quickbooks/connection/{company}
ANY /v1/integrations/quickbooks/oauth2/callback
ANY /v1/integrations/quickbooks/vendor
ANY /v1/integrations/quickbooks/{company}
ANY /v1/integrations/request
ANY /v1/integrations/sftp/connection/{type}
ANY /v1/integrations/sftp/dimension/sync
ANY /v1/integrations/sftp/{type}
ANY /v1/integrations/sync-dimensions/holded/{company}
ANY /v1/integrations/twinfield
ANY /v1/integrations/twinfield/token/callback
ANY /v1/integrations/twinfield/{company}
ANY /v1/integrations/update
ANY /v1/integrations/{app}/api
ANY /v1/invoices/{id}/actions/spread
ANY /v1/offices
ANY /v1/offices/{code}
ANY /v1/partners/customers
ANY /v1/processes/webhook
ANY /v1/processes/{code}/status
ANY /v1/products/import/gstock
ANY /v1/projects
ANY /v1/stats/graph
ANY /v1/stats/overview
ANY /v1/subscriptions/cancel
ANY /v1/subscriptions/cards/change
ANY /v1/subscriptions/cards/customers
ANY /v1/subscriptions/customers
ANY /v1/subscriptions/customers/contact
ANY /v1/subscriptions/customers/extra
ANY /v1/subscriptions/dunning
ANY /v1/subscriptions/invoices
ANY /v1/subscriptions/invoices/{id}
ANY /v1/subscriptions/payment-failure
ANY /v1/subscriptions/payment-success
ANY /v1/subscriptions/renewal
ANY /v1/subscriptions/renewal-failure
ANY /v1/subscriptions/verify/{company}
ANY /v1/suppliers
ANY /v1/suppliers/export/{company}
ANY /v1/suppliers/find/all/{company}
ANY /v1/suppliers/get/all/{company}
ANY /v1/suppliers/import/gstock
ANY /v1/suppliers/{creditorCode}
ANY /v1/users/stats
ANY /v1/users/stats/db
ANY /v1/vatcodes
ANY /v1/workflows/{workflow}/status
ANY /v1/workflows/{workflow}/structure
ANY /v2/document-types
ANY /v2/document-types/all/brand
ANY /v2/document-types/all/import
ANY /v2/document-types/companies/{company}
ANY /v2/document-types/fields
ANY /v2/document-types/file/{documentType}
ANY /v2/document-types/llm/field-details
ANY /v2/document-types/llm/recent-files
ANY /v2/document-types/mark/default
ANY /v2/document-types/min/company
ANY /v2/document-types/signup/{company}
ANY /v2/document-types/{documentType}
ANY /v2/document-types/{documentType}/{company}
ANY /v2/document-types/{documentType}/{section}/fields/{field}
ANY /v2/documents/boundaries/{id}
ANY /v2/documents/bulk/owner
ANY /v2/documents/bulk/status
ANY /v2/documents/company
ANY /v2/documents/export/bulk/{type}
ANY /v2/documents/export/email/{type}
ANY /v2/documents/export/{format}/{id}
ANY /v2/documents/id/{id}
ANY /v2/documents/ids/company
ANY /v2/documents/llm/{docID}
ANY /v2/documents/owner
ANY /v2/documents/status
ANY /v2/documents/xml/{id}
ANY /v2/fields/doc-types/generate/description
ANY /v2/fields/doc-types/{docType}/sections/{section}/{company}
ANY /v2/fields/doc-types/{docType}/{company}
ANY /v2/projects
ANY /v2/projects/workflows/company/min/{company}
ANY /v2/projects/workflows/company/{company}
ANY /v2/projects/{project}
ANY /v2/projects/{project}/workflows
ANY /v2/projects/{project}/workflows/{workflow}
ANY /v2/suppliers/{creditorCode}/{company}
ANY /v2/workflows/{workflowID}/component/{componentType}
ANY /v2/workflows/{workflowID}/{id}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18ce9f09c3088a0ea5b63fc9f8ff9f608b3
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/billing/logs
ANY /v1/admin/billing/purshase-history
ANY /v1/admin/billing/purshase-history/list
ANY /v1/admin/billing/purshase-history/{company}
ANY /v1/admin/companies
ANY /v1/admin/companies/customisations/manage
ANY /v1/admin/companies/{company}
ANY /v1/admin/companies/{company}/billing-purchases
ANY /v1/admins
ANY /v1/admins/2fa/totp
ANY /v1/admins/2fa/validate
ANY /v1/admins/ap-permissions
ANY /v1/admins/ap-permissions/ap-roles
ANY /v1/admins/ap-permissions/{id}
ANY /v1/admins/ap-permissions/{id}/ap-roles
ANY /v1/admins/ap-roles
ANY /v1/admins/ap-roles/ap-permissions
ANY /v1/admins/ap-roles/{id}
ANY /v1/admins/ap-roles/{id}/ap-permissions
ANY /v1/admins/auth/login
ANY /v1/admins/auth/refresh
ANY /v1/admins/change-password
ANY /v1/admins/create/new
ANY /v1/admins/reset-password
ANY /v1/admins/reset-password/confirmation
ANY /v1/admins/reset-password/save
ANY /v1/admins/tokens/validate
ANY /v1/admins/{id}
ANY /v1/auth/2fa/totp
ANY /v1/auth/2fa/totp/validate
ANY /v1/auth/change-password
ANY /v1/auth/email-confirmation/{token}
ANY /v1/auth/google/signin
ANY /v1/auth/refresh-token
ANY /v1/auth/register
ANY /v1/auth/register-partner
ANY /v1/auth/register/partner/sub-company
ANY /v1/auth/reset-password/email-confirmation/{token}
ANY /v1/auth/reset-password/init/{email}
ANY /v1/auth/reset-password/save
ANY /v1/auth/signin
ANY /v1/auth/signup/resend
ANY /v1/auth/tokens/access-token/{token}
ANY /v1/auth/tokens/refresh-token/{token}
ANY /v1/auth/tokens/validate
ANY /v1/auth/user-details
ANY /v1/billing/plan-types
ANY /v1/billing/plan-types/{code}
ANY /v1/billing/plans
ANY /v1/billing/plans/companies/{company}
ANY /v1/billing/plans/enterprise/allocate-credits/{company}
ANY /v1/billing/plans/enterprise/assign
ANY /v1/billing/plans/enterprise/assign/{company}
ANY /v1/billing/plans/enterprise/companies/{company}
ANY /v1/billing/plans/enterprise/create
ANY /v1/billing/plans/enterprise/credit-factor/{company}
ANY /v1/billing/plans/migrate
ANY /v1/billing/plans/{id}
ANY /v1/companies
ANY /v1/companies/admin/delete
ANY /v1/companies/billing/{company}
ANY /v1/companies/convert/main
ANY /v1/companies/customer/tour
ANY /v1/companies/duplicate
ANY /v1/companies/switch/parent
ANY /v1/company-and-user
ANY /v1/company-and-user/details
ANY /v1/external/emails/parse/{company}
ANY /v1/external/super-user
ANY /v1/external/user-count
ANY /v1/external/user-count/{company}
ANY /v1/external/user-details
ANY /v1/external/users/avatar-image
ANY /v1/external/users/avatar/{image}
ANY /v1/external/users/companies/{company}
ANY /v1/external/users/creator
ANY /v1/external/users/email-confirmation/{token}
ANY /v1/external/users/register
ANY /v1/external/users/{id}
ANY /v1/fields/receivers/custom
ANY /v1/fields/request/{entity}/{company}
ANY /v1/fields/{entity}/{company}
ANY /v1/files/images/{image}
ANY /v1/meta/hasSeenNewUI
ANY /v1/op/send-email
ANY /v1/signup/partner/token
ANY /v1/signup/partner/{partner}/token
ANY /v1/subscriptions/custom
ANY /v1/users/add/revoke
ANY /v1/users/delete
ANY /v1/users/remove
ANY /v1/users/restore
ANY /v1/users/roles
ANY /v1/users/roles/permissions
ANY /v2/auth/signup
ANY /v2/auth/signup/ws
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18ce9f09c304ed4a2aefd9f6aea29c21f26
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/billing/logs
ANY /v1/admin/companies
ANY /v1/admin/companies/customisations/manage
ANY /v1/admin/companies/{company}
ANY /v1/admin/companies/{company}/billing-purchases
ANY /v1/auth/2fa/totp
ANY /v1/auth/2fa/totp/validate
ANY /v1/auth/change-password
ANY /v1/auth/email-confirmation/{token}
ANY /v1/auth/google/signin
ANY /v1/auth/refresh-token
ANY /v1/auth/register
ANY /v1/auth/register-partner
ANY /v1/auth/register/partner/sub-company
ANY /v1/auth/reset-password/email-confirmation/{token}
ANY /v1/auth/reset-password/init/{email}
ANY /v1/auth/reset-password/save
ANY /v1/auth/signin
ANY /v1/auth/signup/resend
ANY /v1/auth/tokens/access-token/{token}
ANY /v1/auth/tokens/refresh-token/{token}
ANY /v1/auth/tokens/validate
ANY /v1/auth/user-details
ANY /v1/billing/plan-types
ANY /v1/billing/plan-types/{code}
ANY /v1/billing/plans
ANY /v1/billing/plans/companies/{company}
ANY /v1/billing/plans/enterprise/allocate/{company}
ANY /v1/billing/plans/enterprise/assign
ANY /v1/billing/plans/enterprise/assign/{company}
ANY /v1/billing/plans/enterprise/companies/{company}
ANY /v1/billing/plans/enterprise/create
ANY /v1/billing/plans/enterprise/credit-factor/{company}
ANY /v1/billing/plans/migrate
ANY /v1/billing/plans/{id}
ANY /v1/companies
ANY /v1/companies/admin/delete
ANY /v1/companies/billing/{company}
ANY /v1/companies/convert/main
ANY /v1/companies/customer/tour
ANY /v1/companies/duplicate
ANY /v1/companies/switch/parent
ANY /v1/company-and-user
ANY /v1/company-and-user/details
ANY /v1/external/emails/parse/{company}
ANY /v1/external/super-user
ANY /v1/external/user-count
ANY /v1/external/user-count/{company}
ANY /v1/external/user-details
ANY /v1/external/users/avatar-image
ANY /v1/external/users/avatar/{image}
ANY /v1/external/users/companies/{company}
ANY /v1/external/users/creator
ANY /v1/external/users/email-confirmation/{token}
ANY /v1/external/users/register
ANY /v1/external/users/{id}
ANY /v1/fields/receivers/custom
ANY /v1/fields/request/{entity}/{company}
ANY /v1/fields/{entity}/{company}
ANY /v1/files/images/{image}
ANY /v1/meta/hasSeenNewUI
ANY /v1/op/send-email
ANY /v1/signup/partner/token
ANY /v1/signup/partner/{partner}/token
ANY /v1/subscriptions/custom
ANY /v1/users/add/revoke
ANY /v1/users/delete
ANY /v1/users/remove
ANY /v1/users/restore
ANY /v1/users/roles
ANY /v1/users/roles/permissions
ANY /v2/auth/signup
ANY /v2/auth/signup/ws
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18ce9f09c304ed4a2aefd9f6aea4b4d8518
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/billing/logs
ANY /v1/admin/companies
ANY /v1/admin/companies/customisations/manage
ANY /v1/admin/companies/{company}
ANY /v1/admin/companies/{company}/billing-purchases
ANY /v1/auth/2fa/totp
ANY /v1/auth/2fa/totp/validate
ANY /v1/auth/change-password
ANY /v1/auth/email-confirmation/{token}
ANY /v1/auth/google/signin
ANY /v1/auth/refresh-token
ANY /v1/auth/register
ANY /v1/auth/register-partner
ANY /v1/auth/register/partner/sub-company
ANY /v1/auth/reset-password/email-confirmation/{token}
ANY /v1/auth/reset-password/init/{email}
ANY /v1/auth/reset-password/save
ANY /v1/auth/signin
ANY /v1/auth/signup/resend
ANY /v1/auth/tokens/access-token/{token}
ANY /v1/auth/tokens/refresh-token/{token}
ANY /v1/auth/tokens/validate
ANY /v1/auth/user-details
ANY /v1/billing/plan-types
ANY /v1/billing/plan-types/{code}
ANY /v1/billing/plans
ANY /v1/billing/plans/companies/{company}
ANY /v1/billing/plans/enterprise/allocate/{company}
ANY /v1/billing/plans/enterprise/assign
ANY /v1/billing/plans/enterprise/assign/{company}
ANY /v1/billing/plans/enterprise/companies/{company}
ANY /v1/billing/plans/enterprise/create
ANY /v1/billing/plans/enterprise/credit-factor/{company}
ANY /v1/billing/plans/migrate
ANY /v1/billing/plans/{id}
ANY /v1/companies
ANY /v1/companies/admin/delete
ANY /v1/companies/billing/{company}
ANY /v1/companies/convert/main
ANY /v1/companies/duplicate
ANY /v1/companies/switch/parent
ANY /v1/company-and-user
ANY /v1/company-and-user/details
ANY /v1/external/emails/parse/{company}
ANY /v1/external/super-user
ANY /v1/external/user-count
ANY /v1/external/user-count/{company}
ANY /v1/external/user-details
ANY /v1/external/users/avatar-image
ANY /v1/external/users/avatar/{image}
ANY /v1/external/users/companies/{company}
ANY /v1/external/users/creator
ANY /v1/external/users/email-confirmation/{token}
ANY /v1/external/users/register
ANY /v1/external/users/{id}
ANY /v1/fields/receivers/custom
ANY /v1/fields/request/{entity}/{company}
ANY /v1/fields/{entity}/{company}
ANY /v1/files/images/{image}
ANY /v1/meta/hasSeenNewUI
ANY /v1/op/send-email
ANY /v1/signup/partner/token
ANY /v1/signup/partner/{partner}/token
ANY /v1/subscriptions/custom
ANY /v1/users/add/revoke
ANY /v1/users/delete
ANY /v1/users/remove
ANY /v1/users/restore
ANY /v1/users/roles
ANY /v1/users/roles/permissions
ANY /v2/auth/signup
ANY /v2/auth/signup/ws
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18ce9f09c304ed4a2aefd9f6aea13c2a5c8
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/billing/logs
ANY /v1/admin/companies
ANY /v1/admin/companies/customisations/manage
ANY /v1/admin/companies/{company}
ANY /v1/admin/companies/{company}/billing-purchases
ANY /v1/auth/2fa/totp
ANY /v1/auth/2fa/totp/validate
ANY /v1/auth/change-password
ANY /v1/auth/email-confirmation/{token}
ANY /v1/auth/google/signin
ANY /v1/auth/refresh-token
ANY /v1/auth/register
ANY /v1/auth/register-partner
ANY /v1/auth/register/partner/sub-company
ANY /v1/auth/reset-password/email-confirmation/{token}
ANY /v1/auth/reset-password/init/{email}
ANY /v1/auth/reset-password/save
ANY /v1/auth/signin
ANY /v1/auth/signup/resend
ANY /v1/auth/tokens/access-token/{token}
ANY /v1/auth/tokens/refresh-token/{token}
ANY /v1/auth/tokens/validate
ANY /v1/auth/user-details
ANY /v1/billing/plan-types
ANY /v1/billing/plan-types/{code}
ANY /v1/billing/plans
ANY /v1/billing/plans/companies/{company}
ANY /v1/billing/plans/enterprise/allocate/{company}
ANY /v1/billing/plans/enterprise/assign
ANY /v1/billing/plans/enterprise/assign/{company}
ANY /v1/billing/plans/enterprise/companies/{company}
ANY /v1/billing/plans/enterprise/create
ANY /v1/billing/plans/enterprise/credit-factor/{company}
ANY /v1/billing/plans/migrate
ANY /v1/billing/plans/{id}
ANY /v1/companies
ANY /v1/companies/admin/delete
ANY /v1/companies/billing/{company}
ANY /v1/companies/convert/main
ANY /v1/companies/switch/parent
ANY /v1/company-and-user
ANY /v1/company-and-user/details
ANY /v1/external/emails/parse/{company}
ANY /v1/external/super-user
ANY /v1/external/user-count
ANY /v1/external/user-count/{company}
ANY /v1/external/user-details
ANY /v1/external/users/avatar-image
ANY /v1/external/users/avatar/{image}
ANY /v1/external/users/companies/{company}
ANY /v1/external/users/creator
ANY /v1/external/users/email-confirmation/{token}
ANY /v1/external/users/register
ANY /v1/external/users/{id}
ANY /v1/fields/receivers/custom
ANY /v1/fields/request/{entity}/{company}
ANY /v1/fields/{entity}/{company}
ANY /v1/files/images/{image}
ANY /v1/meta/hasSeenNewUI
ANY /v1/op/send-email
ANY /v1/signup/partner/token
ANY /v1/signup/partner/{partner}/token
ANY /v1/subscriptions/custom
ANY /v1/users/add/revoke
ANY /v1/users/delete
ANY /v1/users/remove
ANY /v1/users/restore
ANY /v1/users/roles
ANY /v1/users/roles/permissions
ANY /v2/auth/signup
ANY /v2/auth/signup/ws
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18c708a519ca7245a804368dad33c35bcb6
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/applications
ANY /v1/admin/applications/{name}
ANY /v1/admin/client/details
ANY /v1/admin/clients/all
ANY /v1/admin/companies
ANY /v1/admin/companies/lock
ANY /v1/admin/companies/subscriptions/change
ANY /v1/admin/companies/validate/name/{name}
ANY /v1/admin/companies/validate/vat
ANY /v1/admin/companies/{name}
ANY /v1/admin/dashboard
ANY /v1/admin/entity-fields
ANY /v1/admin/entity-fields/{entity}/{key}
ANY /v1/admin/fields
ANY /v1/admin/fields/{name}
ANY /v1/admin/languages
ANY /v1/admin/languages/json/{type}/{language}
ANY /v1/admin/languages/sync/{type}
ANY /v1/admin/lock-user
ANY /v1/admin/logs/assistant
ANY /v1/admin/logs/invoice
ANY /v1/admin/logs/invoice/company/{company}
ANY /v1/admin/logs/invoice/upload/company/{company}
ANY /v1/admin/logs/invoice/{id}
ANY /v1/admin/logs/invoices/{id}
ANY /v1/admin/logs/supplier/all
ANY /v1/admin/logs/supplier/code/{company}/{supplierCode}
ANY /v1/admin/logs/supplier/company/{company}
ANY /v1/admin/logs/supplier/{id}
ANY /v1/admin/logs/twinfield
ANY /v1/admin/roles
ANY /v1/admin/roles/{id}
ANY /v1/admin/stats/clients
ANY /v1/admin/stats/detail
ANY /v1/admin/stats/login/details
ANY /v1/admin/stats/overall
ANY /v1/admin/stats/signup/details
ANY /v1/admin/subscriptions/
ANY /v1/admin/users
ANY /v1/admin/users/all
ANY /v1/admin/{company}/delete
ANY /v1/admin/{company}/details
ANY /v1/admin/{company}/document-analytics
ANY /v1/admin/{company}/edit-details
ANY /v1/admin/{company}/purchase-details
ANY /v1/api-doc/{domain}
ANY /v1/brands
ANY /v1/brands/config/{domain}
ANY /v1/brands/status
ANY /v1/brands/{type}/{domain}
ANY /v1/company-subscription
ANY /v1/dimensions/{dimension}/all
ANY /v1/dimensions/{dimension}/company/{company}
ANY /v1/dimensions/{dimension}/company/{company}/{code}
ANY /v1/dimensions/{dimension}/{id}
ANY /v1/integrations/gstock/connection/{company}
ANY /v1/integrations/gstock/deliver
ANY /v1/integrations/test/api/{app}
ANY /v1/integrations/test/basic/{app}
ANY /v1/integrations/test/bearer/{app}
ANY /v1/logs/feedback
ANY /v1/statistics/dashboard
ANY /v1/workflows/engine-preferences
ANY /v1/workflows/engine-preferences/{type}/{id}
ANY /v2/admin/entity-fields
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18c708a519ca7245a804368dad32a7007a8
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/applications
ANY /v1/admin/applications/{name}
ANY /v1/admin/client/details
ANY /v1/admin/clients/all
ANY /v1/admin/companies
ANY /v1/admin/companies/lock
ANY /v1/admin/companies/subscriptions/change
ANY /v1/admin/companies/validate/name/{name}
ANY /v1/admin/companies/validate/vat
ANY /v1/admin/companies/{name}
ANY /v1/admin/dashboard
ANY /v1/admin/entity-fields
ANY /v1/admin/entity-fields/{entity}/{key}
ANY /v1/admin/fields
ANY /v1/admin/fields/{name}
ANY /v1/admin/languages
ANY /v1/admin/languages/json/{type}/{language}
ANY /v1/admin/languages/sync/{type}
ANY /v1/admin/lock-user
ANY /v1/admin/logs/assistant
ANY /v1/admin/logs/invoice
ANY /v1/admin/logs/invoice/company/{company}
ANY /v1/admin/logs/invoice/upload/company/{company}
ANY /v1/admin/logs/invoice/{id}
ANY /v1/admin/logs/invoices/{id}
ANY /v1/admin/logs/supplier/all
ANY /v1/admin/logs/supplier/code/{company}/{supplierCode}
ANY /v1/admin/logs/supplier/company/{company}
ANY /v1/admin/logs/supplier/{id}
ANY /v1/admin/logs/twinfield
ANY /v1/admin/roles
ANY /v1/admin/roles/{id}
ANY /v1/admin/subscriptions/
ANY /v1/admin/users
ANY /v1/admin/users/all
ANY /v1/admin/{company}/delete
ANY /v1/admin/{company}/details
ANY /v1/admin/{company}/document-analytics
ANY /v1/admin/{company}/edit-details
ANY /v1/admin/{company}/purchase-details
ANY /v1/api-doc/{domain}
ANY /v1/brands
ANY /v1/brands/config/{domain}
ANY /v1/brands/status
ANY /v1/brands/{type}/{domain}
ANY /v1/company-subscription
ANY /v1/dimensions/{dimension}/all
ANY /v1/dimensions/{dimension}/company/{company}
ANY /v1/dimensions/{dimension}/company/{company}/{code}
ANY /v1/dimensions/{dimension}/{id}
ANY /v1/integrations/gstock/connection/{company}
ANY /v1/integrations/gstock/deliver
ANY /v1/integrations/test/api/{app}
ANY /v1/integrations/test/basic/{app}
ANY /v1/integrations/test/bearer/{app}
ANY /v1/logs/feedback
ANY /v1/statistics/dashboard
ANY /v1/workflows/engine-preferences
ANY /v1/workflows/engine-preferences/{type}/{id}
ANY /v2/admin/entity-fields
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4305c2e18c708a519ca7245a80f482dbfe9798877a
Public Swagger UI/API detected at path: /swagger.json - sample paths:
ANY /
ANY /v1/admin/applications
ANY /v1/admin/applications/{name}
ANY /v1/admin/companies
ANY /v1/admin/companies/lock
ANY /v1/admin/companies/subscriptions/change
ANY /v1/admin/companies/validate/name/{name}
ANY /v1/admin/companies/validate/vat
ANY /v1/admin/companies/{name}
ANY /v1/admin/dashboard
ANY /v1/admin/entity-fields
ANY /v1/admin/entity-fields/{entity}/{key}
ANY /v1/admin/fields
ANY /v1/admin/fields/{name}
ANY /v1/admin/languages
ANY /v1/admin/languages/json/{type}/{language}
ANY /v1/admin/languages/sync/{type}
ANY /v1/admin/lock-user
ANY /v1/admin/logs/assistant
ANY /v1/admin/logs/invoice
ANY /v1/admin/logs/invoice/company/{company}
ANY /v1/admin/logs/invoice/upload/company/{company}
ANY /v1/admin/logs/invoice/{id}
ANY /v1/admin/logs/invoices/{id}
ANY /v1/admin/logs/supplier/all
ANY /v1/admin/logs/supplier/code/{company}/{supplierCode}
ANY /v1/admin/logs/supplier/company/{company}
ANY /v1/admin/logs/supplier/{id}
ANY /v1/admin/logs/twinfield
ANY /v1/admin/roles
ANY /v1/admin/roles/{id}
ANY /v1/admin/subscriptions/
ANY /v1/admin/users
ANY /v1/admin/users/all
ANY /v1/api-doc/{domain}
ANY /v1/brands
ANY /v1/brands/config/{domain}
ANY /v1/brands/status
ANY /v1/brands/{type}/{domain}
ANY /v1/company-subscription
ANY /v1/dimensions/{dimension}/all
ANY /v1/dimensions/{dimension}/company/{company}
ANY /v1/dimensions/{dimension}/company/{company}/{code}
ANY /v1/dimensions/{dimension}/{id}
ANY /v1/integrations/gstock/connection/{company}
ANY /v1/integrations/gstock/deliver
ANY /v1/integrations/test/api/{app}
ANY /v1/integrations/test/basic/{app}
ANY /v1/integrations/test/bearer/{app}
ANY /v1/logs/feedback
ANY /v1/statistics/dashboard
ANY /v2/admin/entity-fields
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652272d5bbb2
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://franz734@bitbucket.org/franz734/horizont.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "develop"] remote = origin merge = refs/heads/develop
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e076bea79336bea79336bea79336bea79336bea7933
Symfony profiler enabled: https://airhorizont.ticnine.com/_profiler/empty/search/results
Open service 34.32.211.156:443 · app-api.ticnine.com
2026-01-09 22:58
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 22:58:25 GMT
Content-Type: application/json
Content-Length: 67
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"PROCYS-SERVICE-API v8.10.10 Running..","success":true}
Open service 104.26.2.241:443 · www.ticnine.com
2026-01-09 11:43
HTTP/1.1 301 Moved Permanently
Date: Fri, 09 Jan 2026 11:43:49 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9bb3adda3be164e8-FRA
x-powered-by: PHP/8.3.29
x-powered-by: PleskLin
expires: Fri, 09 Jan 2026 12:27:44 GMT
Cache-Control: max-age=3600
x-redirect-by: WordPress
location: https://ticnine.com/
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2B1g90kUyxawv32f%2FSEY4FKwA4flvOdQuuu%2F0hBGxFB6M7ZE6F%2B11q9VWuNc6XKckmK1HCnHnjxX%2B3eZ0jSVAw4rNjSMlQwo4z2C4KTLlX%2BQq9m1KfXvFvEebWnUwTtogGw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 34.32.211.156:443 · provider.ticnine.com
2026-01-09 11:40
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 11:40:57 GMT
Content-Type: application/json
Content-Length: 71
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"OP-PROVIDER-SERVICE-API v8.10.3 Running..","success":true}
Open service 104.26.2.241:443 · ticnine.com
2026-01-09 07:19
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 07:19:28 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9bb22aa10fa49ff0-AMS
x-powered-by: PHP/8.3.29
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
cf-cache-status: DYNAMIC
vary: accept-encoding
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BTVhD4HSFtf6U7n4XuxnrXdxSucDddY4e9gpw3aKn9%2B7MugoUrD6YaYzmHF2cEIUe2kFbx5LtFHRGLAy08CNFWJra4oatutTup3tAzCh2ot0L2QvE3hqP1sOOn92"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 34.32.211.156:443 · auth.ticnine.com
2026-01-09 05:01
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 05:01:23 GMT
Content-Type: application/json
Content-Length: 65
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"LOGIN-SERVICE-API v8.10.8 Running..","success":true}
Open service 104.26.2.241:443 · www.ticnine.com
2026-01-02 21:03
HTTP/1.1 301 Moved Permanently
Date: Fri, 02 Jan 2026 21:03:41 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b7d34571e1ade9a-EWR
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
expires: Fri, 02 Jan 2026 21:47:51 GMT
Cache-Control: max-age=3600
x-redirect-by: WordPress
location: https://ticnine.com/
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=R%2BWcardaYcMh1Ml5RKQBW6zdJ%2BTp5ygTWSd93sUIrWjwHlIt4y%2FdxA2rDpyJIRAE9PAcH98aRrETPjUL6KOoIJ5MJqbABa3YqV6UvbzboX7JNh%2BcaFEhGMa%2BLiRnLJId%2Fw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 34.32.211.156:443 · auth.ticnine.com
2026-01-02 09:49
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 09:49:25 GMT
Content-Type: application/json
Content-Length: 65
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"LOGIN-SERVICE-API v8.10.5 Running..","success":true}
Open service 104.26.2.241:443 · ticnine.com
2026-01-02 06:24
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 06:24:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b782c151a7a9c1b-SIN
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
vary: accept-encoding
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ip186d8R%2Fw9wZ8P%2Fw5bI5BznjQ7aeJ0VbBf8HfGqqVIEk%2FpGljHNtJZCFqWZKlPI%2B7eUZKSvfHvDn%2Bl%2Fatfx5AZBZXUQ5Wo0Ez%2Br8NsZz6TY0392jcJQru3wrrOK"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 34.32.211.156:443 · provider.ticnine.com
2026-01-02 03:03
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 03:03:50 GMT
Content-Type: application/json
Content-Length: 71
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"OP-PROVIDER-SERVICE-API v8.10.1 Running..","success":true}
Open service 34.32.211.156:443 · app-api.ticnine.com
2025-12-30 12:00
HTTP/1.1 200 OK
Date: Tue, 30 Dec 2025 12:00:47 GMT
Content-Type: application/json
Content-Length: 66
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"PROCYS-SERVICE-API v8.10.5 Running..","success":true}
Open service 104.26.2.241:443 · www.ticnine.com
2025-12-22 23:40
HTTP/1.1 301 Moved Permanently
Date: Mon, 22 Dec 2025 23:40:36 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b237713df339833-LHR
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
expires: Tue, 23 Dec 2025 00:25:10 GMT
Cache-Control: max-age=3600
x-redirect-by: WordPress
location: https://ticnine.com/
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=n2kFUqFsAtKexVOmBgEnBKndEIkueudL4lzlJIOPGFq7%2Fqwh4pUGVahGPJPxVsP243oolGFfmI63y%2FR3FJR6YCE7syYqr%2B8B9RmVOBOSdkRyKPyItJBFhkms%2BmHzli7DYw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 34.32.211.156:443 · auth.ticnine.com
2025-12-22 23:39
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 23:39:51 GMT
Content-Type: application/json
Content-Length: 65
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"LOGIN-SERVICE-API v8.10.1 Running..","success":true}
Open service 34.32.211.156:443 · provider.ticnine.com
2025-12-22 18:35
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 18:35:45 GMT
Content-Type: application/json
Content-Length: 71
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"OP-PROVIDER-SERVICE-API v8.10.0 Running..","success":true}
Open service 34.32.211.156:443 · app-api.ticnine.com
2025-12-22 13:27
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 13:27:13 GMT
Content-Type: application/json
Content-Length: 66
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"PROCYS-SERVICE-API v8.10.0 Running..","success":true}
Open service 104.26.2.241:443 · ticnine.com
2025-12-22 12:44
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 12:44:59 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1fb6b56fbd11f3-AMS
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
cf-cache-status: DYNAMIC
vary: accept-encoding
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=k4U%2B9gYazqOThRNAt15nqvumgcPAqdalAGlwri9VsZOa6sc8yDs6QpPsdU8c4JM4cbMk%2FAK9aUv9xc74gyKgCu%2BOhEw1e1UQqeXxlAhD%2FsAsDT1leUd5PU%2BCPxfW"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 104.26.1.129:443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 22:29:54 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1aa68429c80-SIN
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
vary: accept-encoding
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=J80WbEDHNzIlYz7PJe5c8%2Bn8oRWfrzrzL8MAI3LRgJ2EsYxSnQ1qBsxI6qB1GNfbZTDCI9tjF3jg7%2F2OhNLmwioAj6m5nMJr7sXXTKtXkm1z2HQRb%2Byzci%2Bk42Nm"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 2606:4700:20::ac43:4a90:8443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 303 See Other
Date: Sun, 21 Dec 2025 22:29:53 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a70c8cc1c8-SIN
location: https://ticnine.com/login.php
expires: Fri, 28 May 1999 00:00:00 GMT
last-modified: Sun, 21 Dec 2025 22:14:30 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
pragma: no-cache
p3p: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA"
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=j%2BDGm0VgCzroRtwSOPmAP1eIIX%2BnltGMcYSbZ1w7WpzwOOxpNINNK6c9R71dINfqyZqSnWmNoUuYVGb9WMvmvB%2F3qcWqzueQuil2bf5TB4yJXFpGqzsvVr%2B24M9otWOen1xQAI5F18PN"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 2606:4700:20::681a:81:443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 22:29:54 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a70c230a9d-SIN
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
vary: accept-encoding
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=U4KJEOs2YsXA92RhRwELuZt64tbiG4LnvrQ43f8KPrQkGIomjkDarnLvjKR%2Fnj6k2kgi8S0pwIQpyTJGyE2mNhrIdaOOUxYdLwOBow%2BzbcKYcATSDEBaublr9NYG02v%2B0LBJmQXCRIzF"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 2606:4700:20::ac43:4a90:80 · ticnine.com
2025-12-21 22:29
HTTP/1.1 301 Moved Permanently
Date: Sun, 21 Dec 2025 22:29:32 GMT
Content-Type: text/html
Content-Length: 167
Connection: close
Cache-Control: max-age=3600
Expires: Sun, 21 Dec 2025 23:29:32 GMT
Location: https://ticnine.com/
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=p3D9byVvLo%2F%2FNWGCk%2FigMGot1g6CE8HMfFSzb0sm9aKaiEj0mSnwN6by4NIcgQ5lh%2FHS0sNlGVDrsuCKdN1GiYwZRO4UW8WcLrCqEgeEGAQQB4%2FEnw57NjrYVr22LN4iWFvXYEfANl0z"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 9b1ad1a03cd39e08-EWR
Page title: 301 Moved Permanently
<html>
<head><title>301 Moved Permanently</title></head>
<body>
<center><h1>301 Moved Permanently</h1></center>
<hr><center>cloudflare</center>
</body>
</html>
Open service 104.26.1.129:80 · ticnine.com
2025-12-21 22:29
HTTP/1.1 301 Moved Permanently
Date: Sun, 21 Dec 2025 22:29:32 GMT
Content-Type: text/html
Content-Length: 167
Connection: close
Cache-Control: max-age=3600
Expires: Sun, 21 Dec 2025 23:29:32 GMT
Location: https://ticnine.com/
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=qnRYfhE2YkN33y1gDWx8sOTyydWV2Tx1VZeh4CPuO2udDTSRL5VQtGL2T9BjCM96qdTCWhw%2BrDp3qP3viYr8aBMZacOCJB9LkWZJHCMZUAkdO2Jmf0aUCF1N24Vc"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 9b1ad1a04d34ab69-YYZ
Page title: 301 Moved Permanently
<html>
<head><title>301 Moved Permanently</title></head>
<body>
<center><h1>301 Moved Permanently</h1></center>
<hr><center>cloudflare</center>
</body>
</html>
Open service 172.67.74.144:80 · ticnine.com
2025-12-21 22:29
HTTP/1.1 301 Moved Permanently
Date: Sun, 21 Dec 2025 22:29:32 GMT
Content-Type: text/html
Content-Length: 167
Connection: close
Cache-Control: max-age=3600
Expires: Sun, 21 Dec 2025 23:29:32 GMT
Location: https://ticnine.com/
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=X7CT8JrFghU8st6ErE%2F6wp3IQQMe9cNuusD%2FL77J7LaDoKMaJFaSSZ1bODpAYzg%2BC%2BmG71z7d7KqlZWoRSahg2QqzMBjCSANg4vrEh5WlTcQoAYgO51Qt1%2B2fd18"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 9b1ad19fdcf7c1bd-BLR
Page title: 301 Moved Permanently
<html>
<head><title>301 Moved Permanently</title></head>
<body>
<center><h1>301 Moved Permanently</h1></center>
<hr><center>cloudflare</center>
</body>
</html>
Open service 104.26.1.129:8443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 303 See Other
Date: Sun, 21 Dec 2025 22:29:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a2ca84ac7c-YYZ
location: https://ticnine.com/login.php
expires: Fri, 28 May 1999 00:00:00 GMT
last-modified: Sun, 21 Dec 2025 22:14:10 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
pragma: no-cache
p3p: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA"
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=eumPiST6pIEYpwQNiL6LWUbtYSW7TiR8QgTk007ayBzMI7xmzI%2BOL3IIEgwyHq3Y5xuSIb%2FHAt0FrdsD48ibCPmZsFtQdwlfrSGgoePYZLLM5TnbeOD%2BQ5CFAxtX"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 104.26.0.129:443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 22:29:34 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a78d1f0ae3-AMS
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
cf-cache-status: DYNAMIC
vary: accept-encoding
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XnaQNB5w2W95%2BBpjQp5%2FsXLXP6YHifL9JIB5ya36lr5sXqLqRhTRyT2SdS8dusaWhjoojzERgcZvpV9DI%2FkWOFBnH%2F7tBhz3pt1BGBmYtZwfRG3ERWqQQv%2B1An6F"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 2606:4700:20::681a:181:8443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 303 See Other
Date: Sun, 21 Dec 2025 22:29:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a0ef0db6a8-AMS
location: https://ticnine.com/login.php
expires: Fri, 28 May 1999 00:00:00 GMT
last-modified: Sun, 21 Dec 2025 22:14:10 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
pragma: no-cache
p3p: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA"
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=VjMU3vM%2Bcm7sVIT28YNlM%2F%2B4ZJRegS62p3AhKvWfpZ4oD08nFxxv6%2BA%2BpjQISlta6I7JXyB%2Fc7qbibsvksgsNCCNVBE6QbdbESMpgTQZQNS0RRuGnDDel%2BPWDEAW7X2xRlQlS7hpm%2BfD"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 2606:4700:20::681a:181:443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 22:29:34 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a3ebdedc72-FRA
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
cf-cache-status: DYNAMIC
vary: accept-encoding
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=gYfvuTjfvTc3TYiTnDDistgnFXOd6V2mmo2dO%2B0PkC0P5LAIrJTDxyM78bP34dxnsjMag9fPViYu1tWSgrQ0fcljPnlZ9BB7n0DOTVrrvhbNF6fmRz0OIOT8v5BJTMGaAR6XCGtQd7m3"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 172.67.74.144:8443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 303 See Other
Date: Sun, 21 Dec 2025 22:29:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a07e796562-AMS
location: https://ticnine.com/login.php
expires: Fri, 28 May 1999 00:00:00 GMT
last-modified: Sun, 21 Dec 2025 22:14:09 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
pragma: no-cache
p3p: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA"
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2FUPEdkQQSAhluB%2BVcdKj796pYwnhxt%2Fb8uqNKrdPyN0BfqQCIkgFs%2FXFJfcetXoVxag%2Bzu1IHVtMh96AFMCjBzCuni6xjtJiN%2F%2Fdpfa5q2biW8n5TyTM1GBaHgzW"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 2606:4700:20::681a:81:8443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 303 See Other
Date: Sun, 21 Dec 2025 22:29:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a1dffac3ff-EWR
location: https://ticnine.com/login.php
expires: Fri, 28 May 1999 00:00:00 GMT
last-modified: Sun, 21 Dec 2025 22:14:10 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
pragma: no-cache
p3p: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA"
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=aNaM9gA44af%2BPMECn6NhLrfLJXM%2FgUhxym%2FPvgR3w1kFGXbSPWRlpljmEbKtAk8ZoNSpDrj1EDEygssdr1DOnTClUBeVrv%2FkcrQ8q7Eb2GOWUEstaU3Ann85%2Fc4rpAt0UrWS5%2F7EDdZX"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 2606:4700:20::ac43:4a90:443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 22:29:34 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a599f9ac51-YYZ
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
cf-cache-status: DYNAMIC
vary: accept-encoding
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=fhvOTliAdNBlCz4RMwLXKz%2BhXtRBeJ8nzOowQqu6lArqWHR%2FFNf6rz6Yb0LH9VDNObetjjo9LCn%2FZgGG8U73TA5D76zdgqi%2BN69Fm8uEqijqxPrVVsQUMXuAEuB5%2BFQXrk49tfiHbad%2F"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 104.26.0.129:80 · ticnine.com
2025-12-21 22:29
HTTP/1.1 301 Moved Permanently
Date: Sun, 21 Dec 2025 22:29:32 GMT
Content-Type: text/html
Content-Length: 167
Connection: close
Cache-Control: max-age=3600
Expires: Sun, 21 Dec 2025 23:29:32 GMT
Location: https://ticnine.com/
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=kbSo%2FI0m%2BMerp1djumGAm5TtySo81UjIxb%2Bor4WwUZYwyzhOKZJWNph4GR6NQwt8r3H%2BKHR5be34wD3y5PfrrFq3eXGOMVY03jf5CTe%2FPgHC%2BQURWzKkRplRKE8d"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 9b1ad19f78075fd7-FRA
Page title: 301 Moved Permanently
<html>
<head><title>301 Moved Permanently</title></head>
<body>
<center><h1>301 Moved Permanently</h1></center>
<hr><center>cloudflare</center>
</body>
</html>
Open service 104.26.0.129:8443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 303 See Other
Date: Sun, 21 Dec 2025 22:29:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a1ca7b785b-EWR
location: https://ticnine.com/login.php
expires: Fri, 28 May 1999 00:00:00 GMT
last-modified: Sun, 21 Dec 2025 22:14:10 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
pragma: no-cache
p3p: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA"
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=1NCLo47dn6YmnMonQXoe%2BcdJJCa5J7l%2BOQXGDD8IcPGOf4XKlBFZmBf3LjNrFt4rAS9ndwDYHdHC7KEjBuFAhkEcXlrsI3vD0xLRPO4T0B%2B%2FSLFCGcgnrk9q6wnk"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 2606:4700:20::681a:181:80 · ticnine.com
2025-12-21 22:29
HTTP/1.1 301 Moved Permanently
Date: Sun, 21 Dec 2025 22:29:32 GMT
Content-Type: text/html
Content-Length: 167
Connection: close
Cache-Control: max-age=3600
Expires: Sun, 21 Dec 2025 23:29:32 GMT
Location: https://ticnine.com/
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=PkUBabGSN9cVTPOOup2JsnV4PVTiBn%2FJioxyMDyOQeN8o1XD2YNT0M6r8NHkJeApkJnUuIQwflx9Rn1L0IpZx9y920I%2FH6UQcW1dL4f0Vl%2F8AhhhY%2Bhoz0XiBmGiW28i4FuaJyLWja7v"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 9b1ad19f794c3d90-LHR
Page title: 301 Moved Permanently
<html>
<head><title>301 Moved Permanently</title></head>
<body>
<center><h1>301 Moved Permanently</h1></center>
<hr><center>cloudflare</center>
</body>
</html>
Open service 2606:4700:20::681a:81:80 · ticnine.com
2025-12-21 22:29
HTTP/1.1 301 Moved Permanently
Date: Sun, 21 Dec 2025 22:29:32 GMT
Content-Type: text/html
Content-Length: 167
Connection: close
Cache-Control: max-age=3600
Expires: Sun, 21 Dec 2025 23:29:32 GMT
Location: https://ticnine.com/
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ZeoQbO%2FYu6esmgGvYmtyk80g6V4DHb7EpyyxBk1SpsGiIvQ%2B452sXeKB7ubPCP%2FsmN2KB9xDtTVknb2AXT1LExvANXZYCno%2BQlAwvJBxF8KGa5UlkCcWFVGFGpy8T7fL1o4FuWlg%2FLUY"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 9b1ad19f08f4d382-FRA
Page title: 301 Moved Permanently
<html>
<head><title>301 Moved Permanently</title></head>
<body>
<center><h1>301 Moved Permanently</h1></center>
<hr><center>cloudflare</center>
</body>
</html>
Open service 172.67.74.144:443 · ticnine.com
2025-12-21 22:29
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 22:29:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b1ad1a16b926e1d-FRA
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
cf-cache-status: DYNAMIC
vary: accept-encoding
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=2pSugnJ1ZhxCN9s493YEbLdYVXtgJeyIwhULjQuxA%2BDSY7RDd8v2u4K19wfiqissMzwVCI892WpWY4gkWjha3WUNZ4oif2Zr%2FDc0Zfsat8xSK4Vf089Jbl%2FHYhoZ"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 104.26.2.241:443 · www.ticnine.com
2025-12-21 04:01
HTTP/1.1 301 Moved Permanently
Date: Sun, 21 Dec 2025 04:01:41 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b147a518bfc4073-SIN
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
expires: Sun, 21 Dec 2025 04:46:20 GMT
Cache-Control: max-age=3600
x-redirect-by: WordPress
location: https://ticnine.com/
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OAm92VUYzDbyIGkmiU7LbnYxB%2FvDzOcOkCP4iPILtA5dBL6QuaQFxBIDIqFnF1E2c6t217YoSxHlC%2FUcRGASZeW8gmXi33FJ9MMdUkupxeCWj1c5XOfiSmccDhUu9YPchg%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 34.32.211.156:443 · provider.ticnine.com
2025-12-20 21:16
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 21:16:14 GMT
Content-Type: application/json
Content-Length: 70
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"OP-PROVIDER-SERVICE-API v8.9.0 Running..","success":true}
Open service 34.32.211.156:443 · app-api.ticnine.com
2025-12-20 14:05
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 14:05:43 GMT
Content-Type: application/json
Content-Length: 65
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"PROCYS-SERVICE-API v8.9.6 Running..","success":true}
Open service 104.26.2.241:443 · ticnine.com
2025-12-20 10:16
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 10:16:28 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9b0e6265fcc99110-FRA
x-powered-by: PHP/8.3.28
x-powered-by: PleskLin
link: <https://ticnine.com/wp-json/>; rel="https://api.w.org/", <https://ticnine.com/wp-json/wp/v2/pages/255>; rel="alternate"; title="JSON"; type="application/json", <https://ticnine.com/>; rel=shortlink
cf-cache-status: DYNAMIC
vary: accept-encoding
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=xFF%2FLJd%2FVxbKvFxuW02gQcR85fLJC%2B4NgT3NoqFrjqt7gDwNun8Jggo355OuSNlXf9t0TNDTbtikVGx8m74O1zzIlaEIspY8%2BPbQz93YIGNWoqt0r3oWwWh%2FV9x9"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 34.32.211.156:443 · auth.ticnine.com
2025-12-20 05:41
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 05:41:09 GMT
Content-Type: application/json
Content-Length: 64
Connection: close
Vary: Origin
Strict-Transport-Security: max-age=15724800; includeSubDomains
{"message":"LOGIN-SERVICE-API v8.9.1 Running..","success":true}