How Pentrawl works
Everything you scan is a domain you own. Here's exactly how our scans work, what we look at, and why each check matters.
Yes. Pentrawl only performs passive, read-only checks — the same requests a normal browser or search engine would make. We never attempt to exploit, alter or overload your site. A scan puts no meaningful load on your server.
Every scan is fully automated — no human ever visits your site. When you enter a domain, Pentrawl looks up its public DNS records and makes a handful of standard web requests to the addresses it already publishes, exactly like a browser loading your homepage or a search engine indexing it. It reads the responses (headers, certificate, page source) and checks a few well-known public paths such as /robots.txt or /wp-login.php. Everything it looks at is information your server already hands out to any visitor on the open internet — we simply collect it, interpret it, and explain what it means.
We store the scan results so you can revisit and share the report. Results are automatically deleted after 30 days. We only store technical data about the public domain — never personal data, and never anything behind a login.
You should only scan domains you own or have explicit permission to test. Pentrawl checks publicly available information — the same data anyone can see — but running a security scan against a site you do not control may still be against the law in your country. Always scan responsibly.
We only check. Pentrawl inspects your public configuration — DNS records, response headers, certificates and publicly reachable paths. It never launches attacks, brute-forces logins, or tries to break into anything.
Scanning is free and requires no account. Enter a domain you own and you get the full report in seconds, including the downloadable PDF.
Pentrawl checks six layers of your website. Each check links to a full explanation of what it is, why it matters, and how to fix it.