Link & source crawl
Pentrawl reads your page source the way an attacker would, looking for exposed API endpoints and leaked keys hiding in plain sight.
What it is
A website's HTML and JavaScript are fully visible to anyone who views the source. Developers sometimes leave things there that shouldn't be public — internal API endpoints, access tokens, or keys hardcoded into scripts.
The link and source crawl scans that visible source for links, scripts and references to external services, surfacing anything that looks like it exposes data or credentials.
Why it matters
A single API key committed into a front-end script can be extracted by anyone in seconds and used to run up costs or access data on your behalf. Internal endpoints revealed in the source give attackers a map of your application. Because it's all in plain sight, this kind of leak is trivially easy to exploit.
How Pentrawl checks it
Pentrawl fetches your homepage and scans its HTML and JavaScript for links, script sources and calls to external APIs. Anything that appears to expose an endpoint or key is surfaced for review.
How to fix it
Never put secrets in front-end code — anything in the browser is public. Keep API keys on your server, proxy sensitive calls through your backend, and rotate any key that has been exposed.