Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd110a331ec7eeb9daecc0f65434b609dcfefaf94648dc48e89
Public Swagger UI/API detected at path: /v2/api-docs - sample paths:
DELETE /integration/user/users/remove
GET /integration/usage/meter-information/{subscriberId}/meters
GET /integration/usage/usages
GET /integration/user/{id}
POST /integration/contract/
POST /integration/contract/vbo/
POST /integration/contract/{contractId}/cancel
POST /integration/usage/adjustment/{subscriberId}
POST /integration/user/
POST /integration/user/disassociate
PUT /integration/user/user/disable
PUT /integration/user/user/enable
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd18553ecf748afe318e3bc47f920a5ea0f18388b8418388b84
Public Swagger UI/API detected at path: /swagger-ui.html - sample paths:
GET /api/webhook
GET /api/webhook/{name}
POST /api/reprocess/{file-name-prefix}
POST /api/token
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c8c9af8b78c9af8b73f6399249010e4b411c7d93a56e4aae1
Found 128 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/js/vendor/polyfills/bind.js /assets/scss /assets/scss/admin.scss /assets/scss/breakpoints /assets/scss/config.rb /assets/scss/editor-style.scss /assets/scss/govuk /assets/scss/govuk/_colours.scss /assets/scss/govuk/_conditionals.scss /assets/scss/govuk/_css3.scss /assets/scss/govuk/_device-pixels.scss /assets/scss/govuk/_font_stack.scss /assets/scss/govuk/_grid_layout.scss /assets/scss/govuk/_measurements.scss /assets/scss/govuk/_shims.scss /assets/scss/govuk/_typography.scss /assets/scss/govuk/_url-helpers.scss /assets/scss/govuk/design-patterns /assets/scss/govuk/design-patterns/_alpha-beta.scss /assets/scss/govuk/design-patterns/_buttons.scss /assets/scss/govuk/design-patterns/_media-player.scss /assets/scss/ie.scss /assets/scss/login.scss /assets/scss/modules /assets/scss/modules/_alerts.scss /assets/scss/modules/_buttons.scss /assets/scss/modules/_forms.scss /assets/scss/partials /assets/scss/partials/_functions.scss /assets/scss/partials/_grid.scss /assets/scss/partials/_ie_grid.scss /assets/scss/partials/_mixins.scss /assets/scss/partials/_normalize.scss /assets/scss/partials/_print.scss /assets/scss/partials/_typography.scss /assets/scss/partials/_variables.scss /assets/scss/style.scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /classes/formkey.php /classes/functions.php /classes/nocsrf.php /conf /conf/config.php /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /includes/beta-banner.php /includes/footer-history.php /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css
Severity: medium
Fingerprint: 5f32cf5d6962f09c8c9af8b78c9af8b73f6399249010e4b411c7d93ab5215a58
Found 128 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/js/vendor/polyfills/bind.js /assets/scss /assets/scss/admin.scss /assets/scss/breakpoints /assets/scss/config.rb /assets/scss/editor-style.scss /assets/scss/govuk /assets/scss/govuk/_colours.scss /assets/scss/govuk/_conditionals.scss /assets/scss/govuk/_css3.scss /assets/scss/govuk/_device-pixels.scss /assets/scss/govuk/_font_stack.scss /assets/scss/govuk/_grid_layout.scss /assets/scss/govuk/_measurements.scss /assets/scss/govuk/_shims.scss /assets/scss/govuk/_typography.scss /assets/scss/govuk/_url-helpers.scss /assets/scss/govuk/design-patterns /assets/scss/govuk/design-patterns/_alpha-beta.scss /assets/scss/govuk/design-patterns/_buttons.scss /assets/scss/govuk/design-patterns/_media-player.scss /assets/scss/ie.scss /assets/scss/login.scss /assets/scss/modules /assets/scss/modules/_alerts.scss /assets/scss/modules/_buttons.scss /assets/scss/modules/_forms.scss /assets/scss/partials /assets/scss/partials/_functions.scss /assets/scss/partials/_grid.scss /assets/scss/partials/_ie_grid.scss /assets/scss/partials/_mixins.scss /assets/scss/partials/_normalize.scss /assets/scss/partials/_print.scss /assets/scss/partials/_typography.scss /assets/scss/partials/_variables.scss /assets/scss/style.scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /classes/formkey.php /classes/functions.php /classes/nocsrf.php /conf /conf/config.php /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php
Severity: medium
Fingerprint: 5f32cf5d6962f09cca8154c9ca8154c95664fc6619362362e7b68e9c3ed26eb1
Found 126 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/js/vendor/polyfills/bind.js /assets/scss /assets/scss/admin.scss /assets/scss/breakpoints /assets/scss/config.rb /assets/scss/editor-style.scss /assets/scss/govuk /assets/scss/govuk/_colours.scss /assets/scss/govuk/_conditionals.scss /assets/scss/govuk/_css3.scss /assets/scss/govuk/_device-pixels.scss /assets/scss/govuk/_font_stack.scss /assets/scss/govuk/_grid_layout.scss /assets/scss/govuk/_measurements.scss /assets/scss/govuk/_shims.scss /assets/scss/govuk/_typography.scss /assets/scss/govuk/_url-helpers.scss /assets/scss/govuk/design-patterns /assets/scss/govuk/design-patterns/_alpha-beta.scss /assets/scss/govuk/design-patterns/_buttons.scss /assets/scss/govuk/design-patterns/_media-player.scss /assets/scss/ie.scss /assets/scss/login.scss /assets/scss/modules /assets/scss/modules/_alerts.scss /assets/scss/modules/_buttons.scss /assets/scss/modules/_forms.scss /assets/scss/partials /assets/scss/partials/_functions.scss /assets/scss/partials/_grid.scss /assets/scss/partials/_ie_grid.scss /assets/scss/partials/_mixins.scss /assets/scss/partials/_normalize.scss /assets/scss/partials/_print.scss /assets/scss/partials/_typography.scss /assets/scss/partials/_variables.scss /assets/scss/style.scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
Severity: medium
Fingerprint: 5f32cf5d6962f09cc8c90e6cc8c90e6c0e2cf3ffbf766141687f453501b3a4c1
Found 112 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/js/vendor/polyfills/bind.js /assets/scss /assets/scss/admin.scss /assets/scss/breakpoints /assets/scss/config.rb /assets/scss/editor-style.scss /assets/scss/govuk /assets/scss/govuk/_colours.scss /assets/scss/govuk/_conditionals.scss /assets/scss/govuk/_css3.scss /assets/scss/govuk/_device-pixels.scss /assets/scss/govuk/_font_stack.scss /assets/scss/govuk/_grid_layout.scss /assets/scss/govuk/_measurements.scss /assets/scss/govuk/_shims.scss /assets/scss/govuk/_typography.scss /assets/scss/govuk/_url-helpers.scss /assets/scss/govuk/design-patterns /assets/scss/ie.scss /assets/scss/login.scss /assets/scss/modules /assets/scss/partials /assets/scss/style.scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
Severity: medium
Fingerprint: 5f32cf5d6962f09cacbf01a6acbf01a6d4ad92d9d10c18c7f7ae6717619ff55c
Found 118 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/js/vendor/polyfills/bind.js /assets/scss /assets/scss/admin.scss /assets/scss/breakpoints /assets/scss/config.rb /assets/scss/editor-style.scss /assets/scss/govuk /assets/scss/govuk/_colours.scss /assets/scss/govuk/_conditionals.scss /assets/scss/govuk/_css3.scss /assets/scss/govuk/_device-pixels.scss /assets/scss/govuk/_font_stack.scss /assets/scss/govuk/_grid_layout.scss /assets/scss/govuk/_measurements.scss /assets/scss/govuk/_shims.scss /assets/scss/govuk/_typography.scss /assets/scss/govuk/_url-helpers.scss /assets/scss/govuk/design-patterns /assets/scss/govuk/design-patterns/_alpha-beta.scss /assets/scss/govuk/design-patterns/_buttons.scss /assets/scss/govuk/design-patterns/_media-player.scss /assets/scss/ie.scss /assets/scss/login.scss /assets/scss/modules /assets/scss/modules/_alerts.scss /assets/scss/modules/_buttons.scss /assets/scss/modules/_forms.scss /assets/scss/partials /assets/scss/style.scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
Severity: medium
Fingerprint: 5f32cf5d6962f09cf118c228f118c2282da4078ba2fea65d32113db9d04c587c
Found 101 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/js/vendor/polyfills/bind.js /assets/scss /assets/scss/admin.scss /assets/scss/breakpoints /assets/scss/config.rb /assets/scss/editor-style.scss /assets/scss/govuk /assets/scss/ie.scss /assets/scss/login.scss /assets/scss/modules /assets/scss/partials /assets/scss/style.scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
Severity: medium
Fingerprint: 5f32cf5d6962f09c48b4adea48b4adea80226a4d693fecbb05ea9123eac19b39
Found 91 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/js/vendor/polyfills/bind.js /assets/scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
Severity: medium
Fingerprint: 5f32cf5d6962f09c5d6424645d642464783059e7bc3e6f8972cc6d0d6875a781
Found 79 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/min /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
Severity: medium
Fingerprint: 5f32cf5d6962f09cecc85b04ecc85b043ae26c0739ebc0291f5e052d8756ff66
Found 53 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /conf/config.php /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
Severity: medium
Fingerprint: 5f32cf5d6962f09cef4a0ce8ef4a0ce8ce3deccbe2647d1dda25f0f9334c195d
Found 80 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
Severity: medium
Fingerprint: 5f32cf5d6962f09c8c9af8b78c9af8b73f6399249010e4b411c7d93a9da23081
Found 128 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/js/vendor/polyfills/bind.js /assets/scss /assets/scss/admin.scss /assets/scss/breakpoints /assets/scss/config.rb /assets/scss/editor-style.scss /assets/scss/govuk /assets/scss/govuk/_colours.scss /assets/scss/govuk/_conditionals.scss /assets/scss/govuk/_css3.scss /assets/scss/govuk/_device-pixels.scss /assets/scss/govuk/_font_stack.scss /assets/scss/govuk/_grid_layout.scss /assets/scss/govuk/_measurements.scss /assets/scss/govuk/_shims.scss /assets/scss/govuk/_typography.scss /assets/scss/govuk/_url-helpers.scss /assets/scss/govuk/design-patterns /assets/scss/govuk/design-patterns/_alpha-beta.scss /assets/scss/govuk/design-patterns/_buttons.scss /assets/scss/govuk/design-patterns/_media-player.scss /assets/scss/ie.scss /assets/scss/login.scss /assets/scss/modules /assets/scss/modules/_alerts.scss /assets/scss/modules/_buttons.scss /assets/scss/modules/_forms.scss /assets/scss/partials /assets/scss/partials/_functions.scss /assets/scss/partials/_grid.scss /assets/scss/partials/_ie_grid.scss /assets/scss/partials/_mixins.scss /assets/scss/partials/_normalize.scss /assets/scss/partials/_print.scss /assets/scss/partials/_typography.scss /assets/scss/partials/_variables.scss /assets/scss/style.scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /classes/formkey.php /classes/functions.php /classes/nocsrf.php /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt
Severity: medium
Fingerprint: 5f32cf5d6962f09c68a1b33768a1b33745f723a404ffb034cdbdd3ba0ef87513
Found 90 files trough .DS_Store spidering: /404.php /assets /assets/bones.php /assets/css /assets/css/admin.css /assets/css/editor-style.css /assets/css/font-awesome.css /assets/css/font-awesome.min.css /assets/css/ie.css /assets/css/login.css /assets/css/style.css /assets/css/video-embed.css /assets/fonts /assets/fonts/font-awesome.min.css /assets/fonts/fontawesome-webfont.eot /assets/fonts/fontawesome-webfont.svg /assets/fonts/fontawesome-webfont.ttf /assets/fonts/fontawesome-webfont.woff /assets/fonts/fontawesome-webfont.woff2 /assets/fonts/FontAwesome.otf /assets/images /assets/images/custom-post-icon.png /assets/images/dwp_logo copy 2.png /assets/images/dwp_logo.png /assets/images/dwp_logo_mobile.png /assets/images/dwp_logo_x2.png /assets/images/govuk /assets/images/govuk/gov.uk_logotype_crown.png /assets/images/govuk/govuk-crest-2x.png /assets/images/govuk/govuk-crest.png /assets/images/govuk/open-government-licence_2x.png /assets/images/login-logo.png /assets/images/nothing.gif /assets/images/nothumb.gif /assets/js /assets/js/govuk /assets/js/govuk/analytics /assets/js/govuk/min /assets/js/govuk/min/multivariate-test.min.js /assets/js/govuk/min/primary-links.min.js /assets/js/govuk/min/selection-buttons.min.js /assets/js/govuk/min/stick-at-top-when-scrolling.min.js /assets/js/govuk/min/stop-scrolling-at-footer.min.js /assets/js/govuk/multivariate-test.js /assets/js/govuk/primary-links.js /assets/js/govuk/selection-buttons.js /assets/js/govuk/stick-at-top-when-scrolling.js /assets/js/govuk/stop-scrolling-at-footer.js /assets/js/govuk_toolkit.js /assets/js/libs /assets/js/libs/modernizr.custom.min.js /assets/js/min /assets/js/min/govuk_toolkit.min.js /assets/js/min/jquery.html5form.min.js /assets/js/min/scripts.min.js /assets/js/min/stageprompt.min.js /assets/js/scripts.js /assets/js/stageprompt.js /assets/js/vendor /assets/js/vendor/jquery /assets/js/vendor/jquery/additional-methods.min.js /assets/js/vendor/jquery/jquery.player.min.js /assets/js/vendor/jquery/jquery.validate.min.js /assets/js/vendor/jquery/modernizr /assets/js/vendor/polyfills /assets/scss /calculation-outcome.php /canlyniad-y-cyfrifiad.php /CHANGELOG.md /classes /conf /cookies.php /cy-print.php /cyfrifiannell-credyd-pensiwn.php /favicon.ico /footer.php /header.php /includes /index.php /Live backup 4 December 2017 /pension-credit-calculator.php /print.php /readme.md /robots.txt /ssl /style.css /TEST backup 5 december 2017 /test.php /todo.txt /weekly-calculator.php
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c31c2f0b631c2f0b6785a1e2b8448cfef0476115e814280df
Found 28 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/css/patterns /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/images/govuk /wp-content/themes/dwp/library/images/govuk/gov.uk_logotype_crown.png /wp-content/themes/dwp/library/images/govuk/govuk-crest-2x.png /wp-content/themes/dwp/library/images/govuk/govuk-crest.png /wp-content/themes/dwp/library/images/govuk/open-government-licence_2x.png /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/js/libs /wp-content/themes/dwp/library/js/vendor /wp-content/themes/dwp/library/js/vendor/google /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/original bones scss/scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/library/scss/colours /wp-content/themes/dwp/library/scss/design-patterns /wp-content/themes/dwp/library/scss/elements /wp-content/themes/dwp/library/scss/elements/forms /wp-content/themes/dwp/library/scss/patterns /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Severity: low
Fingerprint: 5f32cf5d6962f09cccdd54a0ccdd54a0e4995159ed24e4a1247324ec655f5b17
Found 13 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Severity: low
Fingerprint: 5f32cf5d6962f09cae99eea9ae99eea9f50d36baa2a3d4d473d1c96ba65927c9
Found 23 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/css/patterns /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/images/govuk /wp-content/themes/dwp/library/images/govuk/gov.uk_logotype_crown.png /wp-content/themes/dwp/library/images/govuk/govuk-crest-2x.png /wp-content/themes/dwp/library/images/govuk/govuk-crest.png /wp-content/themes/dwp/library/images/govuk/open-government-licence_2x.png /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/js/libs /wp-content/themes/dwp/library/js/vendor /wp-content/themes/dwp/library/js/vendor/google /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/original bones scss/scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Severity: low
Fingerprint: 5f32cf5d6962f09c39aac35b39aac35babd199a8be6ff95e62ed4bc9133b18f7
Found 14 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/css/patterns /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Severity: low
Fingerprint: 5f32cf5d6962f09cc169dbbec169dbbebd9f86333a8bc2f7d2fec086cd4d5e47
Found 15 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/css/patterns /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/images/govuk /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Severity: low
Fingerprint: 5f32cf5d6962f09cdc57c57adc57c57a5a95add7a45a32db4b62e2b217289265
Found 19 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/css/patterns /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/images/govuk /wp-content/themes/dwp/library/images/govuk/gov.uk_logotype_crown.png /wp-content/themes/dwp/library/images/govuk/govuk-crest-2x.png /wp-content/themes/dwp/library/images/govuk/govuk-crest.png /wp-content/themes/dwp/library/images/govuk/open-government-licence_2x.png /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Severity: low
Fingerprint: 5f32cf5d6962f09cab28146bab28146b3ef725d8f16d086e6ce392d99de4ac9c
Found 21 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/css/patterns /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/images/govuk /wp-content/themes/dwp/library/images/govuk/gov.uk_logotype_crown.png /wp-content/themes/dwp/library/images/govuk/govuk-crest-2x.png /wp-content/themes/dwp/library/images/govuk/govuk-crest.png /wp-content/themes/dwp/library/images/govuk/open-government-licence_2x.png /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/js/libs /wp-content/themes/dwp/library/js/vendor /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Severity: low
Fingerprint: 5f32cf5d6962f09c9e04c3bc9e04c3bc30ebabdd0db01f956072c6381c67bf29
Found 22 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/css/patterns /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/images/govuk /wp-content/themes/dwp/library/images/govuk/gov.uk_logotype_crown.png /wp-content/themes/dwp/library/images/govuk/govuk-crest-2x.png /wp-content/themes/dwp/library/images/govuk/govuk-crest.png /wp-content/themes/dwp/library/images/govuk/open-government-licence_2x.png /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/js/libs /wp-content/themes/dwp/library/js/vendor /wp-content/themes/dwp/library/js/vendor/google /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Severity: low
Fingerprint: 5f32cf5d6962f09c684e525d684e525d21ca29166e5d63f09ef3dbaf15b81e58
Found 27 files trough .DS_Store spidering: /db /wp-content /wp-content/plugins /wp-content/themes /wp-content/themes/dwp /wp-content/themes/dwp/library /wp-content/themes/dwp/library/css /wp-content/themes/dwp/library/css/patterns /wp-content/themes/dwp/library/images /wp-content/themes/dwp/library/images/govuk /wp-content/themes/dwp/library/images/govuk/gov.uk_logotype_crown.png /wp-content/themes/dwp/library/images/govuk/govuk-crest-2x.png /wp-content/themes/dwp/library/images/govuk/govuk-crest.png /wp-content/themes/dwp/library/images/govuk/open-government-licence_2x.png /wp-content/themes/dwp/library/js /wp-content/themes/dwp/library/js/libs /wp-content/themes/dwp/library/js/vendor /wp-content/themes/dwp/library/js/vendor/google /wp-content/themes/dwp/library/original bones scss /wp-content/themes/dwp/library/original bones scss/scss /wp-content/themes/dwp/library/scss /wp-content/themes/dwp/library/scss/colours /wp-content/themes/dwp/library/scss/design-patterns /wp-content/themes/dwp/library/scss/elements /wp-content/themes/dwp/library/scss/patterns /wp-content/themes/dwp/partials /wp-content/themes/twentyseventeen
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549d43ca19da4da14d5a4da14d5a4da14d5a4da14d5
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Jobs/fullSearch/{customerId}/{criteria}
GET /api/Jobs/{mdmId}
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3dec863f59258a9f72eacd4d9eb5bbc5a957af4f2
GraphQL introspection enabled at /graphql Types: 134 (by kind: ENUM: 10, INPUT_OBJECT: 12, OBJECT: 107, SCALAR: 5) Operations: - Query: Query | fields: analytics, assets, authentication, comments, contribute - Mutation: Mutation | fields: analytics, assets, authentication, comments, groups - Subscription: Subscription | fields: loggingLiveTrail Directives: auth, cacheControl, deprecated, include, rateLimit, skip, specifiedBy (total: 7)
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549e8d97bb70493dbcbed0d93ebed0d93ebed0d93eb
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /.well-known/keys
GET /.well-known/openid-configuration
POST /api/Signing/{clientId}
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cae99eea9ae99eea912213001b994462f712c38df85ea9500
Found 23 files trough .DS_Store spidering: /applications /applications/controllers /applications/exports /applications/helpers /applications/models /applications/modules /applications/settings /applications/templates /applications/views /data /libraries /libraries/phpexcel /libraries/phpmailer /libraries/tcpdf /public /public/css /public/fonts /public/images /public/js /public/scripts /public/themes /resources /utilities
Severity: low
Fingerprint: 5f32cf5d6962f09c39aac35b39aac35b1869af2becc68e21900957e99352c2b7
Found 14 files trough .DS_Store spidering: /applications /applications/controllers /applications/exports /applications/helpers /applications/models /applications/modules /applications/settings /applications/templates /applications/views /data /libraries /public /resources /utilities
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4b3468c8e41b772ca168c60e1717391fef68e129cf
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /api/admin/cache
DELETE /api/v1/customers/{customerId}/accounts/{accountTokenId}
DELETE /api/v1/customers/{customerId}/policies/{policyNumber}/payments/{publicId}
DELETE /api/v1/customers/{customerId}/profile/mfa/{factorId}
DELETE /api/v2/preferences/{preferencesId}/bill-alerts
DELETE /api/v2/preferences/{preferencesId}/paperless
GET /api/admin/cache/keys
GET /api/v1/brand-data
GET /api/v1/components
GET /api/v1/customers/{customerId}
GET /api/v1/customers/{customerId}/accounts
GET /api/v1/customers/{customerId}/billing-details
GET /api/v1/customers/{customerId}/claims
GET /api/v1/customers/{customerId}/claims/faqs
GET /api/v1/customers/{customerId}/claims/getValidMimes
GET /api/v1/customers/{customerId}/claims/process-steps
GET /api/v1/customers/{customerId}/claims/{claimNumber}/upload-history
GET /api/v1/customers/{customerId}/claims/{policyNumber}
GET /api/v1/customers/{customerId}/id-cards
GET /api/v1/customers/{customerId}/payment-instrument-restrictions
GET /api/v1/customers/{customerId}/payments
GET /api/v1/customers/{customerId}/policies
GET /api/v1/customers/{customerId}/policies/{policyNumber}
GET /api/v1/customers/{customerId}/policies/{policyNumber}/document/{docid}/{category}
GET /api/v1/customers/{customerId}/policies/{policyNumber}/id-card
GET /api/v1/customers/{customerId}/policies/{policyNumber}/payment
GET /api/v1/customers/{customerId}/policies/{policyNumber}/payment/restart
GET /api/v1/customers/{customerId}/policies/{policyNumber}/payments
GET /api/v1/customers/{customerId}/policies/{policyNumber}/rewrite/{rewriteNumber}
GET /api/v1/customers/{customerId}/policies/{policyNumber}/{paymentChannel}/iframe
GET /api/v1/customers/{customerId}/profile/email/{email}/availability
GET /api/v1/customers/{customerId}/profile/mfa
GET /api/v1/customers/{customerId}/profile/mfa/enrollment
GET /api/v1/customers/{customerId}/profile/phone/{phone}/availability
GET /api/v1/customers/{customerId}/workflows/fnol
GET /api/v1/demomode/{version}
GET /api/v1/document/{docId}
GET /api/v1/esignature/{envId}
GET /api/v1/experiment/{experimentName}
GET /api/v1/feature-flags
GET /api/v1/legal-agreements/{type}/versions/most-current
GET /api/v1/link/preferences/{linkCode}
GET /api/v1/preferences/{customerNumber}
GET /api/v1/quickpay/policies/{policyNumber}/accounts
GET /api/v1/quickpay/policies/{policyNumber}/payment/iframe
GET /api/v1/quickpay/policy
GET /api/v1/tokens/claims
GET /api/v1/tokens/sso
GET /api/v1/tokens/user
GET /api/v1/user
GET /api/v1/users/{email}/preferences/bill-alerts
GET /api/v1/users/{email}/preferences/paperless
GET /api/v1/users/{email}/profile/reset-password
GET /api/v1/version/{version}
POST /api/v1/activity
POST /api/v1/client-logging/error
POST /api/v1/client-logging/info
POST /api/v1/contact/contact-us
POST /api/v1/contact/customer-feedback
POST /api/v1/contact/supporting-docs
POST /api/v1/customers/{customerId}/claims/uploadClaimOverviewDocuments
POST /api/v1/customers/{customerId}/policies/{policyNumber}/automatic-payments
POST /api/v1/quickpay/policies/{policyNumber}/payment
POST /api/v1/tokens/validate-token
POST /api/v1/users/{email}/profile
POST /api/v2/users/{identityId}/profile/reset-password
PUT /api/v1/customers/{customerId}/language/{language}
PUT /api/v1/customers/{customerId}/last-login-date
PUT /api/v1/customers/{customerId}/preferences/bill-alerts
PUT /api/v1/customers/{customerId}/preferences/document-notifications
PUT /api/v1/customers/{customerId}/preferences/paperless
PUT /api/v1/customers/{customerId}/profile/email
PUT /api/v1/customers/{customerId}/profile/mfa/email/{email}
PUT /api/v1/customers/{customerId}/profile/name-contact-info
PUT /api/v1/customers/{customerId}/profile/site-terms-agreement
PUT /api/v1/preferences/{preferenceId}
PUT /api/v1/users/{email}/quote/{quoteNumber}/opt-out
Severity: info
Fingerprint: 5733ddf49ff49cd110a331ec973dfce54b9694ce17c4b4ea690a700e27d3f259
Public Swagger UI/API detected at path: /v2/api-docs - sample paths:
DELETE /api/admin/cache
DELETE /api/v1/customers/{customerId}/accounts/{accountTokenId}
DELETE /api/v1/customers/{customerId}/policies/{policyNumber}/payments/{publicId}
DELETE /api/v1/customers/{customerId}/profile/mfa/{factorId}
DELETE /api/v2/preferences/{preferencesId}/bill-alerts
DELETE /api/v2/preferences/{preferencesId}/paperless
GET /actuator
GET /api/admin/cache/keys
GET /api/v1/brand-data
GET /api/v1/components
GET /api/v1/customers/{customerId}
GET /api/v1/customers/{customerId}/accounts
GET /api/v1/customers/{customerId}/billing-details
GET /api/v1/customers/{customerId}/claims
GET /api/v1/customers/{customerId}/claims/faqs
GET /api/v1/customers/{customerId}/claims/getValidMimes
GET /api/v1/customers/{customerId}/claims/process-steps
GET /api/v1/customers/{customerId}/claims/{claimNumber}/upload-history
GET /api/v1/customers/{customerId}/claims/{policyNumber}
GET /api/v1/customers/{customerId}/id-cards
GET /api/v1/customers/{customerId}/payment-instrument-restrictions
GET /api/v1/customers/{customerId}/payments
GET /api/v1/customers/{customerId}/policies
GET /api/v1/customers/{customerId}/policies/{policyNumber}
GET /api/v1/customers/{customerId}/policies/{policyNumber}/document/{docid}/{category}
GET /api/v1/customers/{customerId}/policies/{policyNumber}/id-card
GET /api/v1/customers/{customerId}/policies/{policyNumber}/payment
GET /api/v1/customers/{customerId}/policies/{policyNumber}/payment/restart
GET /api/v1/customers/{customerId}/policies/{policyNumber}/payments
GET /api/v1/customers/{customerId}/policies/{policyNumber}/rewrite/{rewriteNumber}
GET /api/v1/customers/{customerId}/policies/{policyNumber}/{paymentChannel}/iframe
GET /api/v1/customers/{customerId}/profile/email/{email}/availability
GET /api/v1/customers/{customerId}/profile/mfa
GET /api/v1/customers/{customerId}/profile/mfa/enrollment
GET /api/v1/customers/{customerId}/profile/phone/{phone}/availability
GET /api/v1/customers/{customerId}/workflows/fnol
GET /api/v1/demomode/{version}
GET /api/v1/document/{docId}
GET /api/v1/esignature/{envId}
GET /api/v1/experiment/{experimentName}
GET /api/v1/feature-flags
GET /api/v1/legal-agreements/{type}/versions/most-current
GET /api/v1/link/preferences/{linkCode}
GET /api/v1/preferences/{customerNumber}
GET /api/v1/quickpay/policies/{policyNumber}/accounts
GET /api/v1/quickpay/policies/{policyNumber}/payment/iframe
GET /api/v1/quickpay/policy
GET /api/v1/tokens/claims
GET /api/v1/tokens/sso
GET /api/v1/tokens/user
GET /api/v1/user
GET /api/v1/users/{email}/preferences/bill-alerts
GET /api/v1/users/{email}/preferences/paperless
GET /api/v1/users/{email}/profile/reset-password
GET /api/v1/version/{version}
GET /error
GET /favicon.ico
POST /api/v1/activity
POST /api/v1/client-logging/error
POST /api/v1/client-logging/info
POST /api/v1/contact/contact-us
POST /api/v1/contact/customer-feedback
POST /api/v1/contact/supporting-docs
POST /api/v1/customers/{customerId}/claims/uploadClaimOverviewDocuments
POST /api/v1/customers/{customerId}/policies/{policyNumber}/automatic-payments
POST /api/v1/quickpay/policies/{policyNumber}/payment
POST /api/v1/tokens/validate-token
POST /api/v1/users/{email}/profile
POST /api/v2/users/{identityId}/profile/reset-password
PUT /api/v1/customers/{customerId}/language/{language}
PUT /api/v1/customers/{customerId}/last-login-date
PUT /api/v1/customers/{customerId}/preferences/bill-alerts
PUT /api/v1/customers/{customerId}/preferences/document-notifications
PUT /api/v1/customers/{customerId}/preferences/paperless
PUT /api/v1/customers/{customerId}/profile/email
PUT /api/v1/customers/{customerId}/profile/mfa/email/{email}
PUT /api/v1/customers/{customerId}/profile/name-contact-info
PUT /api/v1/customers/{customerId}/profile/site-terms-agreement
PUT /api/v1/preferences/{preferenceId}
PUT /api/v1/users/{email}/quote/{quoteNumber}/opt-out
pcctest.dwp.gov.uk 12 careersdev.dwp.gov.uk 9 cloudmds.dnb.com 2 retailnet.swatch.com 2 self-service-api.dairylandinsurance.com 2 viper-prd.credit-dnb.com 1 dev3-am-racpad.rentacenter.com 1 dev-am-racpad.rentacenter.com 1 prd-yosemite.csp-digital.com 1 wiki.csp-digital.com 1 prd-cachingapiissuer.csp-digital.com 1