GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6d5e6ea65d5e6ea65d5e6ea65d5e6ea65d5e6ea65
GraphQL introspection enabled at /api/graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d66c8f92bec25a336ef8db87ef87c4f8cf09c497f7
GraphQL introspection enabled at /api/graphql Types: 702 (by kind: ENUM: 62, INPUT_OBJECT: 175, INTERFACE: 31, OBJECT: 429, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addPreorderItemsToCurrentPreorder Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6d50133bbfecc26394d86cb84553ba46ae7b4a54a
GraphQL introspection enabled at /api/graphql Types: 679 (by kind: ENUM: 58, INPUT_OBJECT: 169, INTERFACE: 30, OBJECT: 417, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addPreorderItemsToCurrentPreorder Directives: deprecated, include, skip (total: 3)
Open service 151.101.131.10:443 · www.securitron.com
2026-01-09 02:46
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 243 x-dispatcher: prod-dispatcher x-vhost: publish strict-transport-security: max-age=63072000; includeSubdomains content-security-policy: upgrade-insecure-requests; frame-ancestors 'self' http://localhost https://localhost https://aemstage1.assaabloyservices.com https://aemdev.hesinnovations.com https://assaconnect.azurewebsites.net https://assaconnect-qa.azurewebsites.net https://assaconnect-staging.azurewebsites.net https://connect.assaabloy.com https://edc.adamsrite.com https://egress-calculator-qa.azurewebsites.net https://egresscalc.assaabloy.com https://egress-calculator-prod.azurewebsites.net https://eac-dev.aa-bts.com https://eac-qa.aa-bts.com https://eacconfig.assaabloy.com; default-src * data: 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; worker-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: https: http:; child-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; base-uri 'self'; referrer-policy: strict-origin-when-cross-origin location: https://www.securitron.com/en/index content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Fri, 09 Jan 2026 02:46:10 GMT set-cookie: affinity="46e58acc38cf0ab0"; Path=/; HttpOnly; secure X-Served-By: cache-lga21922-LGA X-Cache: MISS X-Timer: S1767926771.678163,VS0,VS0,VE19 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://www.securitron.com/en/index">here</a>.</p> </body></html>
Open service 151.101.131.10:443 · www.securitron.com
2026-01-02 00:21
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 243 x-dispatcher: prod-dispatcher x-vhost: publish strict-transport-security: max-age=63072000; includeSubdomains content-security-policy: upgrade-insecure-requests; frame-ancestors 'self' http://localhost https://localhost https://aemstage1.assaabloyservices.com https://aemdev.hesinnovations.com https://assaconnect.azurewebsites.net https://assaconnect-qa.azurewebsites.net https://assaconnect-staging.azurewebsites.net https://connect.assaabloy.com https://edc.adamsrite.com https://egress-calculator-qa.azurewebsites.net https://egresscalc.assaabloy.com https://egress-calculator-prod.azurewebsites.net https://eac-dev.aa-bts.com https://eac-qa.aa-bts.com https://eacconfig.assaabloy.com; default-src * data: 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; worker-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: https: http:; child-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; base-uri 'self'; referrer-policy: strict-origin-when-cross-origin location: https://www.securitron.com/en/index content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Fri, 02 Jan 2026 00:21:15 GMT set-cookie: affinity="e5228bf4bf6b714e"; Path=/; HttpOnly; secure X-Served-By: cache-fra-eddf8230194-FRA X-Cache: MISS X-Timer: S1767313276.788851,VS0,VS0,VE91 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://www.securitron.com/en/index">here</a>.</p> </body></html>
Open service 151.101.131.10:443 · www.securitron.com
2025-12-22 14:35
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 243 x-dispatcher: prod-dispatcher x-vhost: publish strict-transport-security: max-age=63072000; includeSubdomains content-security-policy: upgrade-insecure-requests; frame-ancestors 'self' http://localhost https://localhost https://aemstage1.assaabloyservices.com https://aemdev.hesinnovations.com https://assaconnect.azurewebsites.net https://assaconnect-qa.azurewebsites.net https://assaconnect-staging.azurewebsites.net https://connect.assaabloy.com https://edc.adamsrite.com https://egress-calculator-qa.azurewebsites.net https://egresscalc.assaabloy.com https://egress-calculator-prod.azurewebsites.net https://eac-dev.aa-bts.com https://eac-qa.aa-bts.com https://eacconfig.assaabloy.com; default-src * data: 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; object-src 'none'; script-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; script-src-elem 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; worker-src 'self' 'unsafe-eval' 'unsafe-inline' blob: data: https: http:; child-src 'self' 'unsafe-eval' 'unsafe-inline' blob: https: http:; base-uri 'self'; referrer-policy: strict-origin-when-cross-origin location: https://www.securitron.com/en/index content-type: text/html; charset=iso-8859-1 Accept-Ranges: bytes Date: Mon, 22 Dec 2025 14:35:51 GMT set-cookie: affinity="dd3e247bddebb1f9"; Path=/; HttpOnly; secure X-Served-By: cache-fra-eddf8230060-FRA X-Cache: MISS X-Timer: S1766414151.466935,VS0,VS0,VE97 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://www.securitron.com/en/index">here</a>.</p> </body></html>