GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa374c2942e74c2942e74c2942e74c2942e74c2942e
GraphQL introspection enabled at /graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2df9b2641df9b2641df9b2641df9b2641df9b2641
GraphQL introspection enabled at /graphql/api Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2
GraphQL introspection enabled at /graphql/api
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2fe4154c1d4813cc3cb843ae0fcd4cf328a3ccaa2
GraphQL introspection enabled at /graphql/api Types: 522 (by kind: ENUM: 41, INPUT_OBJECT: 118, INTERFACE: 26, OBJECT: 332, SCALAR: 5) Operations: - Query: Query | fields: amMegaMenuAll, amMegaMenuTree, amMegaMenuWidget, authnetcimHostedPaymentFormParams, authnetcimHostedProfileFormParams - Mutation: Mutation | fields: addBundleProductsToCart, addCommentToPost, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3f80a7c900dd36b54010663bfd9d64789705cf0b9
GraphQL introspection enabled at /graphql Types: 522 (by kind: ENUM: 41, INPUT_OBJECT: 118, INTERFACE: 26, OBJECT: 332, SCALAR: 5) Operations: - Query: Query | fields: amMegaMenuAll, amMegaMenuTree, amMegaMenuWidget, authnetcimHostedPaymentFormParams, authnetcimHostedProfileFormParams - Mutation: Mutation | fields: addBundleProductsToCart, addCommentToPost, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants Directives: deprecated, include, skip (total: 3)
Open service 151.101.129.91:443 · www.baseballmonkey.com
2026-01-09 11:54
HTTP/1.1 200 OK Connection: close Content-Length: 733237 access-control-allow-headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token x-frame-options: SAMEORIGIN x-frame-options: SAMEORIGIN content-type: text/html; charset=UTF-8 expires: Sat, 10 Jan 2026 15:54:41 GMT access-control-allow-methods: GET, POST, PATCH, PUT, DELETE, OPTIONS x-content-type-options: nosniff x-xss-protection: 1; mode=block Page title: Baseball Equipment | Baseball Gloves & Bats | Baseball Gear s.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.kaptcha.com *.authorize.net www.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; pragma: cache Accept-Ranges: bytes Date: Fri, 09 Jan 2026 11:54:13 GMT Age: 71971 X-Timer: S1767959653.101336,VS0,VE74 Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Vary: Accept-Encoding,Cookie x-origin-server: gpc116-lb1 x-san: 4.74 [0:168:1] [NC][0:0=0] Access-Control-Allow-Origin: * Strict-Transport-Security: max-age=31557600 <!doctype html><html lang="en"><head > <meta charset="utf-8"/><meta name="title" content="Baseball Equipment | Baseball Gloves & Bats | Baseball Gear"/><meta name="description" content="Get the baseball bat that gives you the edge. Make one of our baseball bats yours today and dominate the ball park tomorrow! Se Habla Espanol"/><meta name="keywords" content="Easton baseball bats, Easton baseball bat, Easton SV12 90 BSV3 (-3) Adult Baseball Bat, Adult Baseball Bats"/><meta name="robots" content="INDEX,FOLLOW"/><meta name="viewport" content="width=device-width, initial-scale=1"/><meta name="format-detection" content="telephone=no"/><title>Baseball Equipment | Baseball Gloves & Bats | Baseball Gear</title><link rel="preconnect" href="//www.googletagmanager.com" crossorigin><link rel="preconnect" href="//connect.bolt.com" crossorigin><link rel="preconnect" href="//account.bolt.com" crossorigin><link rel="preconnect" href="//app.termly.io" crossorigin><link rel="preconnect" href="//www.paypal.com" crossorigin><link rel="stylesheet" type="text/css" media="all" href="https://www.baseballmonkey.com/static/version1761116846/_cache/merged/6014dd5a6fe43264ce1bab10dc61273d.min.css" /><link rel="stylesheet" type="text/css" media="screen and (min-width: 768px)" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/styles-l.min.css" /><link rel="stylesheet" type="text/css" media="print" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/print.min.css" /><link rel="stylesheet" type="text/css" rel="preload" as="style" type="text/css" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/ms-icons.min.css" /> <link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/ms-icons.ttf" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/ms-icons.woff" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/oswald-variablefont_wght-webfont.woff" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/Luma-Icons.woff2" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/oswald-variablefont_wght-webfont.woff2" /><link rel="canonical" href="https://www.baseballmonkey.com/" /><link rel="icon" type="image/x-icon" href="https://www.baseballmonkey.com/media/favicon/stores/5/favicon.png" /><link rel="shortcut icon" type="image/x-icon" href="https://www.baseballmonkey.com/media/favicon/stores/5/favicon.png" /><meta http-equiv="X-UA-Compatible"
Open service 151.101.129.91:443 · www.baseballmonkey.com
2026-01-02 20:51
HTTP/1.1 200 OK Connection: close Content-Length: 727919 x-xss-protection: 1; mode=block Page title: Baseball Equipment | Baseball Gloves & Bats | Baseball Gear s.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.kaptcha.com *.authorize.net www.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; content-type: text/html; charset=UTF-8 expires: Sun, 04 Jan 2026 18:45:19 GMT access-control-allow-methods: GET, POST, PATCH, PUT, DELETE, OPTIONS pragma: cache access-control-allow-headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token x-content-type-options: nosniff x-frame-options: SAMEORIGIN x-frame-options: SAMEORIGIN Accept-Ranges: bytes Date: Fri, 02 Jan 2026 20:51:40 GMT Age: 7581 X-Timer: S1767387100.223578,VS0,VE4 Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Vary: Accept-Encoding,Cookie x-origin-server: gpc116-lb1 x-san: 4.74 [0:21:1] [NC][0:0=0] Access-Control-Allow-Origin: * Strict-Transport-Security: max-age=31557600 <!doctype html><html lang="en"><head > <meta charset="utf-8"/><meta name="title" content="Baseball Equipment | Baseball Gloves & Bats | Baseball Gear"/><meta name="description" content="Get the baseball bat that gives you the edge. Make one of our baseball bats yours today and dominate the ball park tomorrow! Se Habla Espanol"/><meta name="keywords" content="Easton baseball bats, Easton baseball bat, Easton SV12 90 BSV3 (-3) Adult Baseball Bat, Adult Baseball Bats"/><meta name="robots" content="INDEX,FOLLOW"/><meta name="viewport" content="width=device-width, initial-scale=1"/><meta name="format-detection" content="telephone=no"/><title>Baseball Equipment | Baseball Gloves & Bats | Baseball Gear</title><link rel="preconnect" href="//www.googletagmanager.com" crossorigin><link rel="preconnect" href="//connect.bolt.com" crossorigin><link rel="preconnect" href="//account.bolt.com" crossorigin><link rel="preconnect" href="//app.termly.io" crossorigin><link rel="preconnect" href="//www.paypal.com" crossorigin><link rel="stylesheet" type="text/css" media="all" href="https://www.baseballmonkey.com/static/version1761116846/_cache/merged/6014dd5a6fe43264ce1bab10dc61273d.min.css" /><link rel="stylesheet" type="text/css" media="screen and (min-width: 768px)" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/styles-l.min.css" /><link rel="stylesheet" type="text/css" media="print" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/print.min.css" /><link rel="stylesheet" type="text/css" rel="preload" as="style" type="text/css" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/ms-icons.min.css" /> <link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/ms-icons.ttf" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/ms-icons.woff" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/oswald-variablefont_wght-webfont.woff" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/Luma-Icons.woff2" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/oswald-variablefont
Open service 151.101.129.91:443 · www.baseballmonkey.com
2025-12-22 23:57
HTTP/1.1 200 OK Connection: close Content-Length: 729003 Page title: Baseball Equipment | Baseball Gloves & Bats | Baseball Gear s.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.kaptcha.com *.authorize.net www.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; x-frame-options: SAMEORIGIN x-frame-options: SAMEORIGIN pragma: cache access-control-allow-headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token x-xss-protection: 1; mode=block access-control-allow-methods: GET, POST, PATCH, PUT, DELETE, OPTIONS content-type: text/html; charset=UTF-8 x-content-type-options: nosniff expires: Tue, 23 Dec 2025 06:00:45 GMT Accept-Ranges: bytes Date: Mon, 22 Dec 2025 23:57:41 GMT Age: 151015 X-Timer: S1766447861.274509,VS0,VE4 Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Vary: Accept-Encoding,Cookie x-origin-server: gpc116-lb1 x-san: 4.74 [0:124:1] [NC][0:0=0] Access-Control-Allow-Origin: * Strict-Transport-Security: max-age=31557600 <!doctype html><html lang="en"><head > <meta charset="utf-8"/><meta name="title" content="Baseball Equipment | Baseball Gloves & Bats | Baseball Gear"/><meta name="description" content="Get the baseball bat that gives you the edge. Make one of our baseball bats yours today and dominate the ball park tomorrow! Se Habla Espanol"/><meta name="keywords" content="Easton baseball bats, Easton baseball bat, Easton SV12 90 BSV3 (-3) Adult Baseball Bat, Adult Baseball Bats"/><meta name="robots" content="INDEX,FOLLOW"/><meta name="viewport" content="width=device-width, initial-scale=1"/><meta name="format-detection" content="telephone=no"/><title>Baseball Equipment | Baseball Gloves & Bats | Baseball Gear</title><link rel="preconnect" href="//www.googletagmanager.com" crossorigin><link rel="preconnect" href="//connect.bolt.com" crossorigin><link rel="preconnect" href="//account.bolt.com" crossorigin><link rel="preconnect" href="//app.termly.io" crossorigin><link rel="preconnect" href="//www.paypal.com" crossorigin><link rel="stylesheet" type="text/css" media="all" href="https://www.baseballmonkey.com/static/version1761116846/_cache/merged/6014dd5a6fe43264ce1bab10dc61273d.min.css" /><link rel="stylesheet" type="text/css" media="screen and (min-width: 768px)" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/styles-l.min.css" /><link rel="stylesheet" type="text/css" media="print" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/print.min.css" /><link rel="stylesheet" type="text/css" rel="preload" as="style" type="text/css" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/ms-icons.min.css" /> <link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/ms-icons.ttf" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/ms-icons.woff" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/oswald-variablefont_wght-webfont.woff" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/Luma-Icons.woff2" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySp
Open service 151.101.129.91:443 · www.baseballmonkey.com
2025-12-21 03:33
HTTP/1.1 200 OK Connection: close Content-Length: 729003 x-xss-protection: 1; mode=block Page title: Baseball Equipment | Baseball Gloves & Bats | Baseball Gear s.google.com www.googletagmanager.com vimeo.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com connect.bolt.com connect-sandbox.bolt.com account.bolt.com account-sandbox.bolt.com sessions.bugsnag.com *.kaptcha.com *.authorize.net www.googleapis.com *.google-analytics.com *.analytics.google.com *.facebook.net *.redditstatic.com *.reddit.com *.tiktok.com *.twitter.com *.ads-twitter.com *.bing.com *.bing.net *.klaviyo.com *.clarity.ms *.doubleclick.net *.run.app 'self' 'unsafe-inline'; child-src http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; content-type: text/html; charset=UTF-8 expires: Tue, 23 Dec 2025 00:51:09 GMT access-control-allow-methods: GET, POST, PATCH, PUT, DELETE, OPTIONS pragma: cache access-control-allow-headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token x-content-type-options: nosniff x-frame-options: SAMEORIGIN x-frame-options: SAMEORIGIN Accept-Ranges: bytes Date: Sun, 21 Dec 2025 03:33:03 GMT Age: 9714 X-Timer: S1766287983.326480,VS0,VE2 Cache-Control: no-store, no-cache, must-revalidate, max-age=0 Vary: Accept-Encoding,Cookie x-origin-server: gpc116-lb1 x-san: 4.74 [0:72:1] [NC][0:0=0] Access-Control-Allow-Origin: * Strict-Transport-Security: max-age=31557600 <!doctype html><html lang="en"><head > <meta charset="utf-8"/><meta name="title" content="Baseball Equipment | Baseball Gloves & Bats | Baseball Gear"/><meta name="description" content="Get the baseball bat that gives you the edge. Make one of our baseball bats yours today and dominate the ball park tomorrow! Se Habla Espanol"/><meta name="keywords" content="Easton baseball bats, Easton baseball bat, Easton SV12 90 BSV3 (-3) Adult Baseball Bat, Adult Baseball Bats"/><meta name="robots" content="INDEX,FOLLOW"/><meta name="viewport" content="width=device-width, initial-scale=1"/><meta name="format-detection" content="telephone=no"/><title>Baseball Equipment | Baseball Gloves & Bats | Baseball Gear</title><link rel="preconnect" href="//www.googletagmanager.com" crossorigin><link rel="preconnect" href="//connect.bolt.com" crossorigin><link rel="preconnect" href="//account.bolt.com" crossorigin><link rel="preconnect" href="//app.termly.io" crossorigin><link rel="preconnect" href="//www.paypal.com" crossorigin><link rel="stylesheet" type="text/css" media="all" href="https://www.baseballmonkey.com/static/version1761116846/_cache/merged/6014dd5a6fe43264ce1bab10dc61273d.min.css" /><link rel="stylesheet" type="text/css" media="screen and (min-width: 768px)" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/styles-l.min.css" /><link rel="stylesheet" type="text/css" media="print" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/print.min.css" /><link rel="stylesheet" type="text/css" rel="preload" as="style" type="text/css" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/css/ms-icons.min.css" /> <link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/ms-icons.ttf" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/ms-icons.woff" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/oswald-variablefont_wght-webfont.woff" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/Luma-Icons.woff2" /><link rel="preload" as="font" crossorigin="anonymous" href="https://www.baseballmonkey.com/static/version1761116846/frontend/Perficient/MonkeySports/en_US/fonts/oswald-variablefont