security / exposed files & endpoints / link & source crawl
Exposed files & endpoints

Link & source crawl

Pentrawl reads your page source the way an attacker would, looking for exposed API endpoints and leaked keys hiding in plain sight.

Severity if missing
Medium
Category
Exposed files & endpoints
Standard
OWASP

What it is

A website's HTML and JavaScript are fully visible to anyone who views the source. Developers sometimes leave things there that shouldn't be public — internal API endpoints, access tokens, or keys hardcoded into scripts.

The link and source crawl scans that visible source for links, scripts and references to external services, surfacing anything that looks like it exposes data or credentials.

Why it matters

A single API key committed into a front-end script can be extracted by anyone in seconds and used to run up costs or access data on your behalf. Internal endpoints revealed in the source give attackers a map of your application. Because it's all in plain sight, this kind of leak is trivially easy to exploit.

The risk
API keys or internal endpoints left in your page source can be read by anyone and used to access data or services in your name.

How Pentrawl checks it

Pentrawl fetches your homepage and scans its HTML and JavaScript for links, script sources and calls to external APIs. Anything that appears to expose an endpoint or key is surfaced for review.

How to fix it

Never put secrets in front-end code — anything in the browser is public. Keep API keys on your server, proxy sensitive calls through your backend, and rotate any key that has been exposed.

Check your domain's Link & source crawl in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →