Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035493f08b3a2b7916cf561883c7304c1b3d9a1d7d747
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/admin/invoice/{requestMoneyId}
DELETE /api/bank/{id}
DELETE /api/money-container/{containerId}
GET /api/CloudPayments/request/v2/getRequestMoneyActivity
GET /api/EmailTemplate
GET /api/EmailTemplate/{id}
GET /api/Invoice/history
GET /api/Invoice/pending
GET /api/Role
GET /api/Role/permission
GET /api/Role/{id}
GET /api/Transaction/recent
GET /api/User
GET /api/User/getUserBasicInfo
GET /api/User/kycStatus
GET /api/User/me
GET /api/User/{id}
GET /api/User/{id}/kycStatus
GET /api/Wallet/balance
GET /api/Wallet/funding-methods
GET /api/WatchlistScreening
GET /api/WatchlistScreening/me
GET /api/WatchlistScreening/{id}
GET /api/admin/merchant/search
GET /api/bank/linked
GET /api/money-container
PATCH /api/Auth/login/verify
PATCH /api/Auth/refresh/mobile
PATCH /api/Auth/register/resend
PATCH /api/Auth/register/verify
PATCH /api/Auth/register/verify/mobile
PATCH /api/Profile/password
POST /api/Auth/create-password
POST /api/Auth/forgot-password
POST /api/Auth/forgot-password/validate-code
POST /api/Auth/login
POST /api/Auth/login/mobile
POST /api/Auth/logout
POST /api/Auth/refresh
POST /api/Auth/register
POST /api/CloudPayments/auth/login
POST /api/CloudPayments/kyc/register
POST /api/CloudPayments/request/updateStatus
POST /api/CloudPayments/request/v2/requestMoney
POST /api/CloudPayments/transaction/cancel
POST /api/CloudPayments/transaction/refund
POST /api/CloudPayments/transaction/update-status
POST /api/CloudPayments/user/update-profile
POST /api/CloudPayments/user/update-status
POST /api/EmailTemplate/{id}/send
POST /api/Invoice/{id}/pay
POST /api/PlaidLayer/createSessionToken
POST /api/PlaidLayer/getUserAccountSession
POST /api/User/updateUserStatus
POST /api/Wallet/add-funds
POST /api/WatchlistScreening/{watchlistScreeningId}/refresh
POST /api/admin/invoice/create
POST /api/admin/merchant
POST /webhook/plaid
PUT /api/Role/{id}/permissions
PUT /api/WatchlistScreening/hit/{hitId}/review
PUT /api/admin/merchant/{companyCode}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035492b50afb0d69113f853d2e834458caefe6429f6b3
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/bank/{id}
DELETE /api/money-container/{containerId}
GET /api/CloudPayments/request/v2/getRequestMoneyActivity
GET /api/EmailTemplate
GET /api/EmailTemplate/{id}
GET /api/Invoice/history
GET /api/Invoice/pending
GET /api/Role
GET /api/Role/permission
GET /api/Role/{id}
GET /api/Transaction/recent
GET /api/User
GET /api/User/getUserBasicInfo
GET /api/User/kycStatus
GET /api/User/me
GET /api/User/{id}
GET /api/Wallet/balance
GET /api/Wallet/funding-methods
GET /api/WatchlistScreening
GET /api/WatchlistScreening/me
GET /api/WatchlistScreening/{id}
GET /api/bank/linked
GET /api/money-container
PATCH /api/Auth/login/verify
PATCH /api/Auth/refresh/mobile
PATCH /api/Auth/register/resend
PATCH /api/Auth/register/verify
PATCH /api/Auth/register/verify/mobile
PATCH /api/Profile/password
PATCH /api/User/{id}/kycStatus
POST /api/Auth/create-password
POST /api/Auth/forgot-password
POST /api/Auth/forgot-password/validate-code
POST /api/Auth/login
POST /api/Auth/login/mobile
POST /api/Auth/logout
POST /api/Auth/refresh
POST /api/Auth/register
POST /api/CloudPayments/auth/login
POST /api/CloudPayments/kyc/register
POST /api/CloudPayments/request/updateStatus
POST /api/CloudPayments/request/v2/requestMoney
POST /api/CloudPayments/transaction/cancel
POST /api/CloudPayments/transaction/refund
POST /api/CloudPayments/transaction/update-status
POST /api/CloudPayments/user/update-profile
POST /api/CloudPayments/user/update-status
POST /api/EmailTemplate/{id}/send
POST /api/Invoice/{id}/pay
POST /api/PlaidLayer/createSessionToken
POST /api/PlaidLayer/getUserAccountSession
POST /api/User/updateUserStatus
POST /api/Wallet/add-funds
POST /api/WatchlistScreening/{watchlistScreeningId}/refresh
POST /webhook/plaid
PUT /api/Role/{id}/permissions
PUT /api/WatchlistScreening/hit/{hitId}/review
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035492b50afb0d69113f853d2e834458caefe3b97e403
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/bank/{id}
DELETE /api/money-container/{containerId}
GET /api/CloudPayments/request/v2/getRequestMoneyActivity
GET /api/EmailTemplate
GET /api/EmailTemplate/{id}
GET /api/Invoice/history
GET /api/Invoice/pending
GET /api/Role/permission
GET /api/Role/{id}
GET /api/Transaction/recent
GET /api/User
GET /api/User/getUserBasicInfo
GET /api/User/kycStatus
GET /api/User/me
GET /api/User/{id}
GET /api/Wallet/balance
GET /api/Wallet/funding-methods
GET /api/bank/linked
GET /api/money-container
PATCH /api/Auth/login/verify
PATCH /api/Auth/refresh/mobile
PATCH /api/Auth/register/resend
PATCH /api/Auth/register/verify
PATCH /api/Auth/register/verify/mobile
PATCH /api/Profile/password
PATCH /api/User/{id}/kycStatus
POST /api/Auth/create-password
POST /api/Auth/forgot-password
POST /api/Auth/forgot-password/validate-code
POST /api/Auth/login
POST /api/Auth/login/mobile
POST /api/Auth/logout
POST /api/Auth/refresh
POST /api/Auth/register
POST /api/CloudPayments/auth/login
POST /api/CloudPayments/kyc/register
POST /api/CloudPayments/request/updateStatus
POST /api/CloudPayments/request/v2/requestMoney
POST /api/CloudPayments/transaction/cancel
POST /api/CloudPayments/transaction/refund
POST /api/CloudPayments/transaction/update-status
POST /api/CloudPayments/user/update-profile
POST /api/CloudPayments/user/update-status
POST /api/EmailTemplate/{id}/send
POST /api/Invoice/{id}/pay
POST /api/PlaidLayer/createSessionToken
POST /api/PlaidLayer/getUserAccountSession
POST /api/Role
POST /api/User/updateUserStatus
POST /api/Wallet/add-funds
POST /webhook/plaid
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035492b50afb01c6ab45cca86b646bb91548610941e5f
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/bank/{id}
GET /api/CloudPayments/request/v2/getRequestMoneyActivity
GET /api/EmailTemplate
GET /api/EmailTemplate/{id}
GET /api/Invoice/history
GET /api/Invoice/pending
GET /api/User
GET /api/User/getUserBasicInfo
GET /api/User/kycStatus
GET /api/User/me
GET /api/User/{id}
GET /api/Wallet/balance
GET /api/Wallet/funding-methods
GET /api/bank/linked
PATCH /api/Auth/login/verify
PATCH /api/Auth/refresh/mobile
PATCH /api/Auth/register/resend
PATCH /api/Auth/register/verify
PATCH /api/Auth/register/verify/mobile
PATCH /api/Profile/password
PATCH /api/User/{id}/kycStatus
POST /api/Auth/create-password
POST /api/Auth/forgot-password
POST /api/Auth/forgot-password/validate-code
POST /api/Auth/login
POST /api/Auth/login/mobile
POST /api/Auth/logout
POST /api/Auth/refresh
POST /api/Auth/register
POST /api/CloudPayments/auth/login
POST /api/CloudPayments/kyc/register
POST /api/CloudPayments/request/updateStatus
POST /api/CloudPayments/request/v2/requestMoney
POST /api/CloudPayments/transaction/cancel
POST /api/CloudPayments/transaction/refund
POST /api/CloudPayments/transaction/update-status
POST /api/CloudPayments/user/update-profile
POST /api/CloudPayments/user/update-status
POST /api/EmailTemplate/{id}/send
POST /api/Invoice/{id}/pay
POST /api/PlaidLayer/createSessionToken
POST /api/PlaidLayer/getUserAccountSession
POST /api/User/updateUserStatus
POST /api/Wallet/add-funds
POST /webhook/plaid
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354906ca315f1b9fe969b88f9ea7d71073ff559d97ea
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/CloudPayments/request/v2/getRequestMoneyActivity
GET /api/EmailTemplate
GET /api/EmailTemplate/{id}
GET /api/Invoice/history
GET /api/Invoice/pending
GET /api/User
GET /api/User/getUserBasicInfo
GET /api/User/kycStatus
GET /api/User/me
GET /api/User/{id}
PATCH /api/Auth/login/verify
PATCH /api/Auth/refresh/mobile
PATCH /api/Auth/register/resend
PATCH /api/Auth/register/verify
PATCH /api/Auth/register/verify/mobile
PATCH /api/Profile/password
PATCH /api/User/{id}/kycStatus
POST /api/Auth/create-password
POST /api/Auth/forgot-password
POST /api/Auth/forgot-password/validate-code
POST /api/Auth/login
POST /api/Auth/login/mobile
POST /api/Auth/logout
POST /api/Auth/refresh
POST /api/Auth/register
POST /api/CloudPayments/auth/login
POST /api/CloudPayments/kyc/register
POST /api/CloudPayments/request/updateStatus
POST /api/CloudPayments/request/v2/requestMoney
POST /api/CloudPayments/transaction/cancel
POST /api/CloudPayments/transaction/refund
POST /api/CloudPayments/transaction/update-status
POST /api/CloudPayments/user/update-profile
POST /api/CloudPayments/user/update-status
POST /api/EmailTemplate/{id}/send
POST /api/Invoice/{id}/pay
POST /api/PlaidLayer/createSessionToken
POST /api/PlaidLayer/getUserAccountSession
POST /api/User/updateUserStatus
POST /webhook/plaid
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549b51e258fd348e05d9d51eac911e7afc4a29988eb
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/EmailTemplate
GET /api/EmailTemplate/{id}
GET /api/Invoice/history
GET /api/Invoice/pending
GET /api/User
GET /api/User/getUserBasicInfo
GET /api/User/kycStatus
GET /api/User/me
GET /api/User/{id}
PATCH /api/Auth/login/verify
PATCH /api/Auth/refresh/mobile
PATCH /api/Auth/register/resend
PATCH /api/Auth/register/verify
PATCH /api/Auth/register/verify/mobile
PATCH /api/User/{id}/kycStatus
POST /api/Auth/forgot-password
POST /api/Auth/forgot-password/validate-code
POST /api/Auth/login
POST /api/Auth/login/mobile
POST /api/Auth/logout
POST /api/Auth/refresh
POST /api/Auth/register
POST /api/CloudPayments/auth/login
POST /api/CloudPayments/kyc/register
POST /api/CloudPayments/transaction/cancel
POST /api/CloudPayments/transaction/refund
POST /api/CloudPayments/transaction/update-status
POST /api/CloudPayments/user/update-profile
POST /api/CloudPayments/user/update-status
POST /api/EmailTemplate/{id}/send
POST /api/Invoice/{id}/pay
POST /api/PlaidLayer/createSessionToken
POST /api/PlaidLayer/getUserAccountSession
POST /api/User/updateUserStatus
POST /webhook/plaid
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549b51e258fd348e05d38f6dcac921c5c8d87b28b90
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/EmailTemplate
GET /api/EmailTemplate/{id}
GET /api/User/getUserBasicInfo
GET /api/User/kycStatus
PATCH /api/Auth/login/verify
PATCH /api/Auth/refresh
PATCH /api/Auth/refresh/mobile
PATCH /api/Auth/register/resend
PATCH /api/Auth/register/verify
PATCH /api/Auth/register/verify/mobile
PATCH /api/User/{id}/kycStatus
POST /api/Auth/forgot-password
POST /api/Auth/forgot-password/validate-code
POST /api/Auth/login
POST /api/Auth/login/mobile
POST /api/Auth/logout
POST /api/Auth/register
POST /api/EmailTemplate/{id}/send
POST /api/PlaidLayer/createSessionToken
POST /api/PlaidLayer/getUserAccountSession
POST /api/User/updateUserStatus
POST /webhook/plaid
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549b51e258fd348e05d38f6dcac921c5c8d08409ef0
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/EmailTemplate
GET /api/EmailTemplate/{id}
GET /api/User/getUserBasicInfo
GET /api/User/kycStatus
PATCH /api/Auth/login/verify
PATCH /api/Auth/refresh
PATCH /api/Auth/refresh/mobile
PATCH /api/Auth/register/resend
PATCH /api/Auth/register/verify
PATCH /api/Auth/register/verify/mobile
PATCH /api/User/{id}/kycStatus
POST /api/Auth/forgot-password
POST /api/Auth/forgot-password/validate-code
POST /api/Auth/login
POST /api/Auth/login/mobile
POST /api/Auth/logout
POST /api/Auth/register
POST /api/EmailTemplate/{id}/send
POST /api/PlaidLayer/createSessionToken
POST /api/PlaidLayer/getUserAccountSession
POST /webhook/plaid
Open service 194.1.147.46:443 · www.vyreli.com
2026-02-02 05:44
HTTP/1.1 301 Moved Permanently Date: Mon, 02 Feb 2026 05:44:44 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.1.34 X-Redirect-By: WordPress Location: https://vyreli.com/ Vary: Accept-Encoding,Origin WPX: 1 X-turbo-charged-by: LiteSpeed X-Edge-Location: WPX CLOUD/NY01 alt-svc: h3=":443"; ma=86400 x-quic: h3 Server: WPX CLOUD/NY01 X-Cache-Status: MISS
Open service 194.1.147.92:443 · vyreli.com
2026-01-23 10:24
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 10:24:46 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding X-Powered-By: PHP/8.1.34 Link: <https://vyreli.com/wp-json/>; rel="https://api.w.org/" Link: <https://vyreli.com/wp-json/wp/v2/pages/11>; rel="alternate"; title="JSON"; type="application/json" Link: <https://vyreli.com/>; rel=shortlink Vary: Accept-Encoding,Origin WPX: 1 X-turbo-charged-by: LiteSpeed X-Edge-Location: WPX CLOUD/FF02 cache-control: public,max-age=3600,stale-while-revalidate=21600 alt-svc: h3=":443"; ma=86400 x-quic: h3 Server: WPX CLOUD/FF02 X-Cache-Status: MISS
Open service 20.118.138.143:443 · api.dev.vyreli.com
2026-01-23 05:10
HTTP/1.1 404 Site Not Found
Content-Length: 2667
Connection: close
Content-Type: text/html
Date: Fri, 23 Jan 2026 05:11:28 GMT
Page title: Microsoft Azure Web App - Error 404
<!DOCTYPE html>
<html>
<head>
<title>Microsoft Azure Web App - Error 404</title>
<style type="text/css">
html {
height: 100%;
width: 100%;
}
#feature {
width: 960px;
margin: 75px auto 0 auto;
overflow: auto;
}
#content {
font-family: "Segoe UI";
font-weight: normal;
font-size: 22px;
color: #ffffff;
float: left;
margin-top: 68px;
margin-left: 0px;
vertical-align: middle;
}
#content h1 {
font-family: "Segoe UI Light";
color: #ffffff;
font-weight: normal;
font-size: 60px;
line-height: 48pt;
width: 800px;
}
a, a:visited, a:active, a:hover {
color: #ffffff;
}
#content a.button {
background: #0DBCF2;
border: 1px solid #FFFFFF;
color: #FFFFFF;
display: inline-block;
font-family: Segoe UI;
font-size: 24px;
line-height: 46px;
margin-top: 10px;
padding: 0 15px 3px;
text-decoration: none;
}
#content a.button img {
float: right;
padding: 10px 0 0 15px;
}
#content a.button:hover {
background: #1C75BC;
}
</style>
<script type="text/javascript">
function toggle_visibility(id) {
var e = document.getElementById(id);
if (e.style.display == 'block')
e.style.display = 'none';
else
e.style.display = 'block';
}
</script>
</head>
<body bgcolor="#00abec">
<div id="feature">
<div id="content">
<h1>404 Web Site not found.</h1>
<p>You may be seeing this error due to one of the reasons listed below :</p>
<ul>
<li>Custom domain has not been configured inside Azure. See <a href="https://go.microsoft.com/fwlink/?linkid=2194614">how to map an existing domain</a> to resolve this.</li>
<li>Client cache is still pointing the domain to old IP address. Clear the cache by running the command <i>ipconfig/flushdns.</i></li>
</ul>
<p>Checkout <a href="https://go.microsoft.com/fwlink/?linkid=2194451">App Service Domain FAQ</a> for more questions.</p>
</div>
</div>
</body>
</html>
Open service 194.1.147.46:443 · www.vyreli.com
2026-01-23 00:35
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 00:35:39 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.1.34 X-Redirect-By: WordPress Location: https://vyreli.com/ Vary: Accept-Encoding,Origin WPX: 1 X-turbo-charged-by: LiteSpeed X-Edge-Location: WPX CLOUD/NY01 alt-svc: h3=":443"; ma=86400 x-quic: h3 Server: WPX CLOUD/NY01 X-Cache-Status: MISS
Open service 194.1.147.46:443 · www.vyreli.com
2026-01-10 02:14
HTTP/1.1 301 Moved Permanently Date: Sat, 10 Jan 2026 02:14:23 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.1.34 X-Redirect-By: WordPress Location: https://vyreli.com/ Vary: Accept-Encoding,Origin WPX: 1 X-turbo-charged-by: LiteSpeed X-Edge-Location: WPX CLOUD/FF02 alt-svc: h3=":443"; ma=86400 x-quic: h3 Server: WPX CLOUD/FF02 X-Cache-Status: MISS