Caddy
tcp/80
nginx
tcp/443
nginx 1.28.0
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522054bcf13
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = http://git.lsj001.com/qingxiang/NewoaksAI.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 5.78.108.142:443 · trimlightsandiego.com
2026-01-23 15:13
HTTP/1.1 200 OK Server: nginx Date: Fri, 23 Jan 2026 15:13:10 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Link: <https://trimlightsandiego.com/wp-json/>; rel="https://api.w.org/" Link: <https://trimlightsandiego.com/wp-json/wp/v2/pages/2>; rel="alternate"; title="JSON"; type="application/json" Link: <https://trimlightsandiego.com/>; rel=shortlink X-Powered-By: WordOps X-Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin-when-cross-origin X-protocol: HTTP/1.1 always Alt-Svc: h3=":443"; ma=86400
Open service 138.91.187.181:443 · chat.trimlightsandiego.com
2026-01-23 10:31
HTTP/1.1 200 OK
server: nginx/1.28.0
date: Fri, 23 Jan 2026 10:31:53 GMT
content-type: text/html
transfer-encoding: chunked
vary: Accept-Encoding
cache-control: no-store
connection: close
Page title: {{HtmlHeadTitle}}
<!doctype html>
<html lang="en" class="scroll-smooth">
<head>
<meta charset="UTF-8" />
<link rel="icon" href="{{HtmlHeadFavicon}}" />
<link rel="canonical" href="https://www.newoaks.ai" />
<link rel="dns-prefetch" href="https://cdn.newoaks.ai">
<link rel="preconnect" href="https://cdn.newoaks.ai" crossorigin>
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link rel="preload"
href="https://fonts.googleapis.com/css2?family=Inter&family=Lora&family=Merriweather&family=Noto+Sans&family=Noto+Sans+JP&family=Noto+Sans+KR&family=Noto+Sans+SC&family=Noto+Serif+SC&family=Open+Sans&family=Oswald&family=PT+Sans&family=Playfair+Display&family=Raleway&family=Roboto&family=Roboto+Condensed&family=Roboto+Slab&family=Rubik&family=Courier+Prime&family=Lato&family=Ubuntu&display=swap"
as="style" onload="this.onload=null;this.rel='stylesheet'">
<noscript>
<link
href="https://fonts.googleapis.com/css2?family=Inter&family=Lora&family=Merriweather&family=Noto+Sans&family=Noto+Sans+JP&family=Noto+Sans+KR&family=Noto+Sans+SC&family=Noto+Serif+SC&family=Open+Sans&family=Oswald&family=PT+Sans&family=Playfair+Display&family=Raleway&family=Roboto&family=Roboto+Condensed&family=Roboto+Slab&family=Rubik&family=Ubuntu&display=swap"
rel="stylesheet">
</noscript>
<meta name="viewport"
content="viewport-fit=cover, width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no" />
<meta http-equiv="Cache-Control" content="no-cache, no-store, must-revalidate" />
<meta http-equiv="Pragma" content="no-cache" />
<meta http-equiv="Expires" content="0" />
<title>{{HtmlHeadTitle}}</title>
<meta name="description" content="{{HtmlMetaDescription}}" />
<!-- Open Graph meta tags -->
<meta property="og:title" content="{{HtmlHeadTitle}}" />
<meta property="og:description" content="{{HtmlMetaDescription}}" />
<meta property="og:image" content="{{HtmlHeadFavicon}}" />
<meta property="og:type" content="website" />
<!-- Optional: Twitter Card meta tags for Twitter sharing -->
<meta name="twitter:card" content="summary_large_image" />
<meta name="twitter:title" content="{{HtmlHeadTitle}}" />
<meta name="twitter:description" content="{{HtmlMetaDescription}}" />
<meta name="twitter:image" content="{{HtmlHeadFavicon}}" />
<script async src="https://cdn.tolt.io/tolt.js" data-tolt="29b39511-096a-4580-9abd-28a52d423a04"></script>
<!-- Google Tag Manager -->
<script>
(function (w, d, s, l) {
var domain = w.location.hostname;
const gtmIds = {
'appointify.ai': 'GTM-5GNL23WQ',
'newoaks.ai': 'GTM-TVZFC978'
};
const reg = Object.keys(gtmIds).find(d => domain.endsWith(d)) || "";
var gtmId = gtmIds[reg];
if (!gtmId) return;
w[l] = w[l] || []; w[l].push({
'gtm.start':
new Date().getTime(), event: 'gtm.js'
}); var f = d.getElementsByTagName(s)[0],
j = d.createElement(s), dl = l != 'dataLayer' ? '&l=' + l : ''; j.async = true; j.src =
'https://www.googletagmanager.com/gtm.js?id=' + gtmId + dl; f.parentNode.insertBefore(j, f);
})(window, document, 'script', 'dataLayer');
</script>
<!-- End Google Tag Manager -->
<!-- Meta Pixel Code -->
<script>
console.log("========================= Meta Pixel Code ===========================");
if (window.location.hostname.includes("newoaks.ai") && !window.location.pathname.startsWith("/chatbot-iframe/") && !window.location.pathname.startsWith("/share/")) {
console.log("Loading Meta Pixel Code for newoaks.ai domain and valid pathname.");
!function (f, b, e, v, n, t, s) {
if (f.fbq) return; n = f.fbq = function () {
n.callMethod ?
n.callMethod.ap
Open service 34.76.180.229:80 · sale.trimlightsandiego.com
2026-01-10 05:32
HTTP/1.1 308 Permanent Redirect Connection: close Location: https://sale.trimlightsandiego.com/ Server: Caddy Date: Sat, 10 Jan 2026 05:33:54 GMT Content-Length: 0
Open service 34.76.180.229:443 · sale.trimlightsandiego.com
2026-01-10 05:32
HTTP/1.1 302 Found Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept Access-Control-Allow-Origin: * Alt-Svc: h3=":443"; ma=2592000 Content-Length: 40 Content-Type: text/plain; charset=utf-8 Date: Sat, 10 Jan 2026 05:32:56 GMT Location: https://switchy.io Server: Caddy Server: Google Frontend Vary: Accept X-Cloud-Trace-Context: 509e0e06bfd602f2aa390b21f9c83f4d Connection: close Found. Redirecting to https://switchy.io