See what is actually exposed.
Fray discovers, validates and explains your attack surface — then gives your AI the evidence to reason about it.
Fray is searching the invisible paths around the target.
Enter your domain above and hit "Investigate" to see your own results here.
How this surface connects
Discovered assets converge on shared infrastructure, backed by evidence. Click any step to see why Fray connected it.
What Fray found, in order
The real sequence this investigation followed — not a mockup, the actual pipeline that just ran.
Domain resolves and is reachable
api, admin, and staging subdomains found
Next.js identified on the API surface
Certificate and transport configuration checked
Admin login surface + WAF boundary gap identified
93.184.xxx.xxx identified as shared infrastructure
6 findings confirmed against multiple evidence sources
What Matters
6 security signals · 1 critical · 3 highCRITICALWAF boundary bypass
4 assets appear reachable outside the expected security boundary.
WAF boundary bypass
4 assets appear reachable outside the expected security boundary.
HIGHPublic staging environment
staging.example.com is externally reachable and exposes the production stack.
Public staging environment
staging.example.com is externally reachable and exposes the production stack.
HIGHAdministrative surfaces exposed
3 administrative interfaces are publicly discoverable.
Administrative surfaces exposed
3 administrative interfaces are publicly discoverable.
What Fray looks at 6 categories
Why is this risky? What should I fix first? What changed?
gitlab.com
27 assets discovered · 6 security signals
3 need deeper verification — see Findings tab →
This report distinguishes Verified (independently confirmed), Likely (strong signal, confirmation pending), and Insufficient Evidence (not enough to classify either way) — Fray would rather under-claim than overstate what it found.
Some security issues were found — address the high-severity ones within the next week.
The investigation identified 6 Security Findings: 1 Critical, 3 High, 1 Medium, and 1 Low. Cloudflare WAF detected.
- 8 admin login page(s) confirmed publicly accessible (of 60 paths checked) — restrict access by IP
- Your staging/dev site is publicly accessible — it may have weaker security
What Matters
6 security signals · 1 critical · 3 highOrigin Outside Expected WAF Boundary
4 assets appear reachable outside the expected security boundary.
Admin Panels Publicly Accessible
8 admin login pages confirmed exposed, out of 60 paths checked.
GraphQL Introspection Enabled
Full schema is exposed at /api/graphql to any caller — no auth required to query it.
Public Staging / Internal Environment
admin.demo.fray.info ↗ and staging.demo.fray.info ↗ are publicly reachable. Their security posture may differ from production.
2 subdomains behind a different CDN
registry.gitlab.com (Google CDN) and status.gitlab.com (CloudFront) — not a WAF bypass, just a different provider than Cloudflare.
136 origin IP candidates found
Sourced from MX/SPF records — most trace to third-party mail (Google) and billing (Zuora) infrastructure, not gitlab's own origin. Fray will not classify these as exposed origins without independent confirmation.
Attack surface
13 subdomains · 63 high-value targetsShow admin paths
Remediation plan
5 action itemsBlock direct-to-origin access CRITICAL
Restrict exposed admin panels HIGH
Disable GraphQL introspection HIGH
Remove exposed sensitive file CRITICAL
Enable DNSSEC MEDIUM
Technical details
For engineers — full evidence belowDNS & Email DNSSEC not enabled · SPF/DMARC missing
| NS | diva.ns.cloudflare.com, jermaine.ns.cloudflare.com |
| MX | 1 aspmx.l.google.com, 10 alt3.aspmx.l.google.com |
| DNSSEC | ✗ Not enabled |
| SPF | ✗ Missing |
| DMARC | ✗ Missing |
Security Headers 78/100
| Missing | COOP (low), CORP (low) |
Technologies 0 detected this scan
No technologies detected — re-run with --deep for subdomain-level fingerprinting.
Rate Limits fixed-window · 500 req
| ratelimit-limit | 500 |
| ratelimit-remaining | 458 |
Suggested validation tests 4 categories
csp_bypass · modern_bypasses · prototype_pollution · ssti — run fray test https://gitlab.com -c <category> --smart for details on each.
🤖 Fray sees. Your AI reasons.
MCP-nativeThis investigation — the evidence, the correlations, the attack path graph above — isn't just for reading. Connect Fray to Claude, ChatGPT, or any MCP-compatible AI, and it can query this attack surface directly: ask follow-up questions, correlate findings across scans, re-investigate a specific asset on demand.
Most tools stop at "here's what we found." Fray gives your AI the evidence to reason about why it matters — because the AI is working from verified, structured findings, not summarizing a PDF.
Report abuse · Acceptable Use Policy · Privacy