GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37d96f14f55243bdde5a2735607dbce6459d15ab5
GraphQL introspection enabled at /graphql Types: 385 (by kind: ENUM: 28, INPUT_OBJECT: 91, INTERFACE: 20, OBJECT: 241, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, oneOf, skip (total: 4) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2d562a70c2fd428505555046b706aa7db43f29cce
GraphQL introspection enabled at /graphql/api Types: 385 (by kind: ENUM: 28, INPUT_OBJECT: 91, INTERFACE: 20, OBJECT: 241, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, oneOf, skip (total: 4) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2d562a70c2fd428505555046b706aa7dbea0f54c3
GraphQL introspection enabled at /graphql/api Types: 385 (by kind: ENUM: 28, INPUT_OBJECT: 91, INTERFACE: 20, OBJECT: 241, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37d96f14f55243bdde5a2735607dbce64a8cf2186
GraphQL introspection enabled at /graphql Types: 385 (by kind: ENUM: 28, INPUT_OBJECT: 91, INTERFACE: 20, OBJECT: 241, SCALAR: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToCompareList Directives: deprecated, include, oneOf, skip (total: 4)
Open service 23.50.131.148:443 · www.bwxtstore.com
2026-01-08 21:01
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Content-Length: 0
Report-To: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/ad1de0bf-a6f7-41e7-94d6-3152bd3ba570.sansec.watch\/"}]}
.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.akstat.io *.go-mpulse.net *.helpscout.net d3hb14vkzrxvla.cloudfront.net trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.cloudflare.com *.googleapis.com *.addthis.com *.graph.instagram.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ad1de0bf-a6f7-41e7-94d6-3152bd3ba570.sansec.watch/; report-to report-endpoint;, upgrade-insecure-requests;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Location: https://bwxtstore.com/
X-UA-Compatible: IE=edge
X-Frame-Options: SAMEORIGIN
X-Magento-Cache-Debug: MISS
Expires: Thu, 08 Jan 2026 21:01:03 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 08 Jan 2026 21:01:03 GMT
Connection: close
Set-Cookie: PHPSESSID=p9dc6bh1m5fs6ht9f6m786395d; expires=Fri, 09 Jan 2026 01:01:03 GMT; Max-Age=14400; path=/; domain=bwxtstore.com; secure; HttpOnly; SameSite=Lax
Server-Timing: edge; dur=14
Server-Timing: origin; dur=666
Server-Timing: cdn-cache; desc=MISS
Alt-Svc: h3=":443"; ma=93600
Server-Timing: ak_p; desc="1767906063056_389224216_4199927538_67826_10486_99_115_-";dur=1
Open service 23.50.131.148:443 · www.bwxtstore.com
2026-01-02 14:41
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Content-Length: 0
Report-To: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/ad1de0bf-a6f7-41e7-94d6-3152bd3ba570.sansec.watch\/"}]}
.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.akstat.io *.go-mpulse.net *.helpscout.net d3hb14vkzrxvla.cloudfront.net trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.cloudflare.com *.googleapis.com *.addthis.com *.graph.instagram.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ad1de0bf-a6f7-41e7-94d6-3152bd3ba570.sansec.watch/; report-to report-endpoint;, upgrade-insecure-requests;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Location: https://bwxtstore.com/
X-UA-Compatible: IE=edge
X-Frame-Options: SAMEORIGIN
X-Magento-Cache-Debug: MISS
Expires: Fri, 02 Jan 2026 14:41:12 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 02 Jan 2026 14:41:12 GMT
Connection: close
Set-Cookie: PHPSESSID=uptg5lj4g2r1p8fj6gsb5q7m12; expires=Fri, 02 Jan 2026 18:41:12 GMT; Max-Age=14400; path=/; domain=bwxtstore.com; secure; HttpOnly; SameSite=Lax
Server-Timing: edge; dur=1
Server-Timing: origin; dur=221
Server-Timing: cdn-cache; desc=MISS
Alt-Svc: h3=":443"; ma=93600
Server-Timing: ak_p; desc="1767364871846_389224212_2803278938_22053_3481_149_151_-";dur=1
Open service 2.16.204.80:443 · www.bwxtstore.com
2026-01-01 08:43
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 371 Expires: Thu, 01 Jan 2026 08:43:07 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 01 Jan 2026 08:43:07 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Alt-Svc: h3=":443"; ma=93600 Server-Timing: ak_p; desc="1767256987790_34610512_2985996896_22_129654_11_14_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.bwxtstore.com/" on this server.<P> Reference #18.501d1002.1767256987.b1fab260 <P>https://errors.edgesuite.net/18.501d1002.1767256987.b1fab260</P> </BODY> </HTML>
Open service 2.16.204.80:80 · www.bwxtstore.com
2026-01-01 08:43
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 371 Expires: Thu, 01 Jan 2026 08:43:10 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 01 Jan 2026 08:43:10 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767256990717_34610512_2986009311_13_7427_8_0_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.bwxtstore.com/" on this server.<P> Reference #18.501d1002.1767256990.b1fae2df <P>https://errors.edgesuite.net/18.501d1002.1767256990.b1fae2df</P> </BODY> </HTML>
Open service 2a02:26f0:7100::210:12a:80 · www.bwxtstore.com
2026-01-01 08:43
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 371 Expires: Thu, 01 Jan 2026 08:43:10 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 01 Jan 2026 08:43:10 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767256990647_34603302_491694096_17_7766_0_0_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.bwxtstore.com/" on this server.<P> Reference #18.26011002.1767256990.1d4ea810 <P>https://errors.edgesuite.net/18.26011002.1767256990.1d4ea810</P> </BODY> </HTML>
Open service 2.16.204.91:80 · www.bwxtstore.com
2026-01-01 08:43
HTTP/1.1 301 Moved Permanently Content-Type: text/html Content-Length: 162 Location: https://www.bwxtstore.com/ Expires: Thu, 01 Jan 2026 08:43:11 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 01 Jan 2026 08:43:11 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=103 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767256991250_34610523_3536405708_10437_7265_97_0_-";dur=1 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.204.91:443 · www.bwxtstore.com
2026-01-01 08:43
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Content-Length: 0
Report-To: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/ad1de0bf-a6f7-41e7-94d6-3152bd3ba570.sansec.watch\/"}]}
.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.akstat.io *.go-mpulse.net *.helpscout.net d3hb14vkzrxvla.cloudfront.net trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.cloudflare.com *.googleapis.com *.addthis.com *.graph.instagram.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ad1de0bf-a6f7-41e7-94d6-3152bd3ba570.sansec.watch/; report-to report-endpoint;, upgrade-insecure-requests;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Location: https://bwxtstore.com/
X-UA-Compatible: IE=edge
X-Frame-Options: SAMEORIGIN
X-Magento-Cache-Debug: MISS
Expires: Thu, 01 Jan 2026 08:43:09 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 01 Jan 2026 08:43:09 GMT
Connection: close
Set-Cookie: PHPSESSID=6r77frbn2h6pjqhs2e6pr5lrv2; expires=Thu, 01 Jan 2026 12:43:09 GMT; Max-Age=14400; path=/; domain=bwxtstore.com; secure; HttpOnly; SameSite=Lax
Server-Timing: edge; dur=28
Server-Timing: origin; dur=485
Server-Timing: cdn-cache; desc=MISS
Alt-Svc: h3=":443"; ma=93600
Server-Timing: ak_p; desc="1767256988625_34610523_3536392377_51276_8053_83_87_-";dur=1
Open service 2a02:26f0:7100::210:123:443 · www.bwxtstore.com
2026-01-01 08:43
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Content-Length: 0
Report-To: {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"https:\/\/ad1de0bf-a6f7-41e7-94d6-3152bd3ba570.sansec.watch\/"}]}
.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.certcapture.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com *.akstat.io *.go-mpulse.net *.helpscout.net d3hb14vkzrxvla.cloudfront.net trial-eum-clientnsv4-s.akamaihd.net trial-eum-clienttons-s.akamaihd.net *.cloudflare.com *.googleapis.com *.addthis.com *.graph.instagram.com *.google-analytics.com *.stripe.com klarna.com *.klarna.com *.klarnacdn.net *.klarnaevt.com *.link.com *.amazon.com 'self' 'unsafe-inline'; child-src *.certcapture.com assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline'; report-uri https://ad1de0bf-a6f7-41e7-94d6-3152bd3ba570.sansec.watch/; report-to report-endpoint;, upgrade-insecure-requests;
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Location: https://bwxtstore.com/
X-UA-Compatible: IE=edge
X-Frame-Options: SAMEORIGIN
X-Magento-Cache-Debug: MISS
Expires: Thu, 01 Jan 2026 08:43:09 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 01 Jan 2026 08:43:09 GMT
Connection: close
Set-Cookie: PHPSESSID=kkhnopgl8kp4ds67mjmcboi0l4; expires=Thu, 01 Jan 2026 12:43:09 GMT; Max-Age=14400; path=/; domain=bwxtstore.com; secure; HttpOnly; SameSite=Lax
Server-Timing: edge; dur=289
Server-Timing: origin; dur=490
Server-Timing: cdn-cache; desc=MISS
Alt-Svc: h3=":443"; ma=93600
Server-Timing: ak_p; desc="1767256988474_34603295_569575333_77968_6556_79_86_-";dur=1
Open service 2a02:26f0:7100::210:123:80 · www.bwxtstore.com
2026-01-01 08:43
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 371 Expires: Thu, 01 Jan 2026 08:43:10 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 01 Jan 2026 08:43:10 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767256990581_34603295_569576128_16_6295_0_0_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.bwxtstore.com/" on this server.<P> Reference #18.1f011002.1767256990.21f30ac0 <P>https://errors.edgesuite.net/18.1f011002.1767256990.21f30ac0</P> </BODY> </HTML>
Open service 2a02:26f0:7100::210:12a:443 · www.bwxtstore.com
2026-01-01 08:43
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 371 Expires: Thu, 01 Jan 2026 08:43:07 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 01 Jan 2026 08:43:07 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Alt-Svc: h3=":443"; ma=93600 Server-Timing: ak_p; desc="1767256987649_34603295_569574957_17_5883_18_20_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.bwxtstore.com/" on this server.<P> Reference #18.1f011002.1767256987.21f3062d <P>https://errors.edgesuite.net/18.1f011002.1767256987.21f3062d</P> </BODY> </HTML>
Open service 23.50.131.148:443 · www.bwxtstore.com
2025-12-22 07:35
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 371 Expires: Mon, 22 Dec 2025 07:35:58 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 22 Dec 2025 07:35:58 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Alt-Svc: h3=":443"; ma=93600 Server-Timing: ak_p; desc="1766388958697_389224212_880207597_9_5824_0_34_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.bwxtstore.com/" on this server.<P> Reference #18.14173317.1766388958.3476e6ed <P>https://errors.edgesuite.net/18.14173317.1766388958.3476e6ed</P> </BODY> </HTML>