See what is actually exposed.
Fray discovers, validates and explains your attack surface — then gives your AI the evidence to reason about it.
Fray is searching the invisible paths around the target.
Enter your domain above and hit "Investigate" to see your own results here.
27 assets discovered · 6 security signals
How the surface connects
Fray connects assets, infrastructure and evidence into one investigation path.
What Matters
6 security signals · 1 critical · 3 highCRITICALWAF boundary bypass
4 assets appear reachable outside the expected security boundary.
WAF boundary bypass
4 assets appear reachable outside the expected security boundary.
HIGHPublic staging environment
staging.example.com is externally reachable and exposes the production stack.
Public staging environment
staging.example.com is externally reachable and exposes the production stack.
HIGHAdministrative surfaces exposed
3 administrative interfaces are publicly discoverable.
Administrative surfaces exposed
3 administrative interfaces are publicly discoverable.
Why is this risky? What should I fix first? What changed?
gitlab.com
Some security issues were found — address the high-severity ones within the next week.
The investigation identified 6 Security Findings: 1 Critical, 3 High, 1 Medium, and 1 Low. Cloudflare WAF detected.
- 8 admin login page(s) confirmed publicly accessible (of 60 paths checked) — restrict access by IP
- Your staging/dev site is publicly accessible — it may have weaker security
What Matters
6 security signals · 1 critical · 3 highOrigin Outside Expected WAF Boundary
4 assets appear reachable outside the expected security boundary.
Admin Panels Publicly Accessible
8 admin login pages confirmed exposed, out of 60 paths checked.
GraphQL Introspection Enabled
Full schema is exposed at /api/graphql to any caller — no auth required to query it.
Public Staging / Internal Environment
admin.demo.fray.info ↗ and staging.demo.fray.info ↗ are publicly reachable. Their security posture may differ from production.
2 subdomains behind a different CDN
registry.gitlab.com (Google CDN) and status.gitlab.com (CloudFront) — not a WAF bypass, just a different provider than Cloudflare.
136 origin IP candidates found
Sourced from MX/SPF records — most trace to third-party mail (Google) and billing (Zuora) infrastructure, not gitlab's own origin.
Attack surface
13 subdomains · 63 high-value targetsShow admin paths
Remediation plan
5 action itemsBlock direct-to-origin access CRITICAL
Restrict exposed admin panels HIGH
Disable GraphQL introspection HIGH
Remove exposed sensitive file CRITICAL
Enable DNSSEC MEDIUM
Technical details
For engineers — full evidence belowDNS & Email DNSSEC not enabled · SPF/DMARC missing
| NS | diva.ns.cloudflare.com, jermaine.ns.cloudflare.com |
| MX | 1 aspmx.l.google.com, 10 alt3.aspmx.l.google.com |
| DNSSEC | ✗ Not enabled |
| SPF | ✗ Missing |
| DMARC | ✗ Missing |
Security Headers 78/100
| Missing | COOP (low), CORP (low) |
Technologies 0 detected this scan
No technologies detected — re-run with --deep for subdomain-level fingerprinting.
Rate Limits fixed-window · 500 req
| ratelimit-limit | 500 |
| ratelimit-remaining | 458 |
Suggested validation tests 4 categories
csp_bypass · modern_bypasses · prototype_pollution · ssti — run fray test https://gitlab.com -c <category> --smart for details on each.
Report abuse · Acceptable Use Policy · Privacy