GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa382d2d8c831c7956c0539e841ac951c35fbbf2b30
GraphQL introspection enabled at /graphql Types: 400 (by kind: ENUM: 31, INPUT_OBJECT: 92, INTERFACE: 20, OBJECT: 252, SCALAR: 5) Operations: - Query: Query | fields: authnetcimHostedPaymentFormParams, authnetcimHostedProfileFormParams, availableStores, awScIsStoreCreditApplied, awScStoreCreditDetails - Mutation: Mutation | fields: addBundleProductsToCart, addCommentToPost, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa382d2d8c831c7956c0539e841ac951c351c35f36d
GraphQL introspection enabled at /graphql Types: 400 (by kind: ENUM: 31, INPUT_OBJECT: 92, INTERFACE: 20, OBJECT: 252, SCALAR: 5) Operations: - Query: Query | fields: authnetcimHostedPaymentFormParams, authnetcimHostedProfileFormParams, availableStores, awScIsStoreCreditApplied, awScStoreCreditDetails - Mutation: Mutation | fields: addBundleProductsToCart, addCommentToPost, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa382d2d8c831c7956c0539e841ac951c35fbbf2b30
GraphQL introspection enabled at /graphql Types: 400 (by kind: ENUM: 31, INPUT_OBJECT: 92, INTERFACE: 20, OBJECT: 252, SCALAR: 5) Operations: - Query: Query | fields: authnetcimHostedPaymentFormParams, authnetcimHostedProfileFormParams, availableStores, awScIsStoreCreditApplied, awScStoreCreditDetails - Mutation: Mutation | fields: addBundleProductsToCart, addCommentToPost, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa382d2d8c831c7956c0539e841ac951c351c35f36d
GraphQL introspection enabled at /graphql Types: 400 (by kind: ENUM: 31, INPUT_OBJECT: 92, INTERFACE: 20, OBJECT: 252, SCALAR: 5) Operations: - Query: Query | fields: authnetcimHostedPaymentFormParams, authnetcimHostedProfileFormParams, availableStores, awScIsStoreCreditApplied, awScStoreCreditDetails - Mutation: Mutation | fields: addBundleProductsToCart, addCommentToPost, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e29db79fb72c5838255e4a0ed0683c4c625016174c
GraphQL introspection enabled at /graphql/api Types: 400 (by kind: ENUM: 31, INPUT_OBJECT: 92, INTERFACE: 20, OBJECT: 252, SCALAR: 5) Operations: - Query: Query | fields: authnetcimHostedPaymentFormParams, authnetcimHostedProfileFormParams, availableStores, awScIsStoreCreditApplied, awScStoreCreditDetails - Mutation: Mutation | fields: addBundleProductsToCart, addCommentToPost, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Open service 54.230.228.76:443 · www.vsevenweaponsystems.com
2026-01-10 02:17
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Accept-Ranges: bytes Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Open service 54.230.228.46:443 · vsevenweaponsystems.com
2026-01-09 06:54
HTTP/1.1 302 Found Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Cache-Control: max-age=0, must-revalidate, no-cache, no-store is.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; Date: Fri, 09 Jan 2026 06:54:45 GMT Expires: Thu, 09 Jan 2025 06:54:45 GMT Location: https://www.vsevenweaponsystems.com/ Pragma: no-cache Server: nginx Set-Cookie: PHPSESSID=9884b18d817fe3d07b327da70a62d752; expires=Fri, 09 Jan 2026 07:54:45 GMT; Max-Age=3600; path=/; domain=vsevenweaponsystems.com; secure; HttpOnly; SameSite=Lax; Secure Set-Cookie: lagrange_session=26115c8d-4359-42b8-9959-fc8c5bc868b5; Path=/; Max-Age=1800; HttpOnly; Secure; SameSite=Lax Set-Cookie: wcid=2FXVKrFCvO7zAAAB; Path=/; Domain=127.0.0.1; Max-Age=31536000; HttpOnly; Secure; SameSite=Lax Strict-Transport-Security: max-age=31557600 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Live-Attribute: true X-Xss-Protection: 1; mode=block X-Cache: Miss from cloudfront Via: 1.1 2be8016001d2c9c5362b82e28629d2d6.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P5 X-Amz-Cf-Id: Aa27QFLq_GgGhAm1FFylCR2W4AK4w1cqr2fMsohJF4y3-x8BvIQa-g== Age: 0
Open service 54.230.228.76:443 · www.vsevenweaponsystems.com
2026-01-02 23:35
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Accept-Ranges: bytes Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Open service 54.230.228.46:443 · vsevenweaponsystems.com
2026-01-02 06:53
HTTP/1.1 302 Found Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Cache-Control: max-age=0, must-revalidate, no-cache, no-store is.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; Date: Fri, 02 Jan 2026 06:53:31 GMT Expires: Thu, 02 Jan 2025 06:53:30 GMT Location: https://www.vsevenweaponsystems.com/ Pragma: no-cache Server: nginx Set-Cookie: PHPSESSID=02671f7206db24b655db7fccd3deff16; expires=Fri, 02 Jan 2026 07:53:30 GMT; Max-Age=3600; path=/; domain=vsevenweaponsystems.com; secure; HttpOnly; SameSite=Lax; Secure Set-Cookie: lagrange_session=3e7e8217-989c-433b-b2c0-cf281a1a5a55; Path=/; Max-Age=1800; HttpOnly; Secure; SameSite=Lax Set-Cookie: wcid=D2pS2wb72sFiAAAB; Path=/; Domain=127.0.0.1; Max-Age=31536000; HttpOnly; Secure; SameSite=Lax Strict-Transport-Security: max-age=31557600 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Live-Attribute: true X-Xss-Protection: 1; mode=block X-Cache: Miss from cloudfront Via: 1.1 3909cd34f904454f54cf78c975b2c198.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P5 X-Amz-Cf-Id: v7keR0tQR1fyy6YBBOxriIolt62L2_Gb-rVOOYpAtraEb40YTmNDZg== Age: 0
Open service 54.230.228.76:443 · www.vsevenweaponsystems.com
2025-12-23 09:52
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Accept-Ranges: bytes Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Open service 54.230.228.46:443 · vsevenweaponsystems.com
2025-12-23 04:54
HTTP/1.1 302 Found Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Cache-Control: max-age=0, must-revalidate, no-cache, no-store is.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; Date: Tue, 23 Dec 2025 04:54:35 GMT Expires: Mon, 23 Dec 2024 04:54:35 GMT Location: https://www.vsevenweaponsystems.com/ Pragma: no-cache Server: nginx Set-Cookie: PHPSESSID=f6da4854b4b698a5ab3cf765ab94bcf3; expires=Tue, 23 Dec 2025 05:54:35 GMT; Max-Age=3600; path=/; domain=vsevenweaponsystems.com; secure; HttpOnly; SameSite=Lax; Secure Set-Cookie: lagrange_session=535d8233-26cd-416d-a02e-40f90ec07ade; Path=/; Max-Age=1800; HttpOnly; Secure; SameSite=Lax Set-Cookie: wcid=NN/npMDKbcUWAAAB; Path=/; Domain=127.0.0.1; Max-Age=31536000; HttpOnly; Secure; SameSite=Lax Strict-Transport-Security: max-age=31557600 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Live-Attribute: true X-Xss-Protection: 1; mode=block X-Cache: Miss from cloudfront Via: 1.1 f6bc6f6279f11021614bfd42e1f4410e.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P5 X-Amz-Cf-Id: vp4XOi29z-T6KNBDUiW2QOWKLCcoYzwF_RIu101mFEIzflfBmgwBZA== Age: 0
Open service 54.230.228.76:443 · www.vsevenweaponsystems.com
2025-12-21 10:01
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Accept-Ranges: bytes Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Open service 54.230.228.46:443 · vsevenweaponsystems.com
2025-12-21 03:32
HTTP/1.1 302 Found Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Cache-Control: max-age=0, must-revalidate, no-cache, no-store is.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; Date: Sun, 21 Dec 2025 03:32:45 GMT Expires: Sat, 21 Dec 2024 03:32:45 GMT Location: https://www.vsevenweaponsystems.com/ Pragma: no-cache Server: nginx Set-Cookie: PHPSESSID=f60ec5c2703569b1ede52ea98ec79e14; expires=Sun, 21 Dec 2025 04:32:45 GMT; Max-Age=3600; path=/; domain=vsevenweaponsystems.com; secure; HttpOnly; SameSite=Lax; Secure Set-Cookie: lagrange_session=81bac8e1-1e95-409c-ba52-3368f89a5d22; Path=/; Max-Age=1800; HttpOnly; Secure; SameSite=Lax Set-Cookie: wcid=+z6QEeXMs5d8AAAB; Path=/; Domain=127.0.0.1; Max-Age=31536000; HttpOnly; Secure; SameSite=Lax Strict-Transport-Security: max-age=31557600 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Live-Attribute: true X-Xss-Protection: 1; mode=block X-Cache: Miss from cloudfront Via: 1.1 f9e9a2e2a630392daf40b42b49debe88.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P5 X-Amz-Cf-Id: Xcv5VNqAj3GwU5033PBC4iCmSX4kvKRYtdWWkwgkT2onPH68YA1IVw== Age: 0
Open service 54.230.228.76:443 · www.vsevenweaponsystems.com
2025-12-19 11:27
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Accept-Ranges: bytes Cache-Control: max-age=0, no-cache, no-store, must-revalidate
Open service 54.230.228.46:443 · vsevenweaponsystems.com
2025-12-19 04:09
HTTP/1.1 302 Found Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Cache-Control: max-age=0, must-revalidate, no-cache, no-store is.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; Date: Fri, 19 Dec 2025 04:09:53 GMT Expires: Thu, 19 Dec 2024 04:09:53 GMT Location: https://www.vsevenweaponsystems.com/ Pragma: no-cache Server: nginx Set-Cookie: PHPSESSID=b38f5930af7541ecac9eea4e4c21d646; expires=Fri, 19 Dec 2025 05:09:53 GMT; Max-Age=3600; path=/; domain=vsevenweaponsystems.com; secure; HttpOnly; SameSite=Lax; Secure Set-Cookie: lagrange_session=b8c978bc-0fe7-42c3-96d7-1897bbd0ef7d; Path=/; Max-Age=1800; HttpOnly; Secure; SameSite=Lax Set-Cookie: wcid=ZvSTW0HG28SfAAAB; Path=/; Domain=vsevenweaponsystems.com; Max-Age=31536000; HttpOnly; Secure; SameSite=Lax Strict-Transport-Security: max-age=31557600 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Live-Attribute: true X-Xss-Protection: 1; mode=block X-Cache: Miss from cloudfront Via: 1.1 c357e4a7404abfefc6d5fb1647246a74.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P5 X-Amz-Cf-Id: 58GTa-_MzV3UgCTuo8_s1h5Zx632kmojmIj_33jSXiaPSanM9QrpfQ== Age: 0