Documentation
Technology stack and risk signals
Use Crawle's passive technology intelligence to understand visible frameworks, client libraries, CMS markers, security headers, and exposed-version risks.
Workspace technology intelligence
Technology
Visible stack, evidence categories, and risk signals across the workspace
Common components
Most frequent visible technologies across the workspace.
- React4 sites
- Next.js2 sites
- Cloudflare2 sites
- Stripe1 site
- Tailwind CSS1 site
- Vercel1 site
- Plausible Analytics1 site
- Docusaurus1 site
- Algolia1 site
- nginx1 site
Evidence categories
Where Crawle is finding stack evidence.
- JavaScript libraries43
- Security headers17
- Analytics & tags16
- Frameworks15
- CDN / edge12
- Web servers9
Sites
Open a site to inspect evidence, run an on-demand scan, or acknowledge a finding.
| Top signals | |||||
|---|---|---|---|---|---|
Storefront shop.crawle-demo.io | Scanned | 38 | 92 high risk | Jun 9, 6:30 AM | Next.jsReactCloudflareStripe |
Marketing site www.crawle-demo.io | Scanned | 27 | 4 | Jun 9, 5:10 AM | Next.jsReactVercelPlausible Analytics |
Documentation docs.crawle-demo.io | Scanned | 19 | 2 | Jun 8, 10:48 PM | DocusaurusReactAlgoliaCloudflare |
Customer app app.crawle-demo.io | Scanned | 33 | 61 high risk | Jun 9, 4:02 AM | ReactnginxSentryDatadog |
Blog blog.crawle-demo.io | Not scanned | 0 | 0 | Never | No signals yet |
Legacy portal legacy.crawle-demo.io Host unreachable on the last scan (connection timed out). | Unavailable | 14 | 3 | May 31, 1:25 PM | WordPressPHPApache |
What Crawle checks
Technology scans reuse normal crawl evidence instead of running intrusive security probes.
- Response headers, public HTML markers, meta generator tags, and script/style URLs.
- Framework and platform hints such as Next.js, Shopify, WordPress, Cloudflare, Vercel, nginx, Apache, and PHP.
- Exposed client-library versions where public assets reveal them.
- Security-header posture such as HSTS and Content-Security-Policy on sampled HTTPS responses.
- Optional cached enrichment from OSV.dev, CISA KEV, FIRST EPSS, and endoflife.date when enabled.
Risk language
Findings are presented as technology risk signals, not as a replacement for a dedicated security scanner.
- High-severity exposed-version findings require deterministic public evidence.
- Unknown versions are shown as context, not as version-specific vulnerability claims.
- AI-assisted review, when enabled later, must not be the sole source for critical findings.
- Evidence is bounded and sensitive headers such as cookies and authorization values are redacted.
Scan cadence
Automatic scans run monthly by default and can be adjusted per site.
- Run an on-demand scan from the Technology tab when a team has changed frameworks or frontend bundles.
- Keep automatic scans enabled for client sites where stack drift or exposed old assets matter.
- Disable scans per site if the customer does not want technology posture checks.
- Crawle stores the current profile and finding history so agents and reports can reference it later.
Alerts and reports
Technology risk signals and stack changes use the same routing controls as the rest of Crawle.
- Critical and high deterministic findings follow the critical incident window and can notify in real time.
- Warnings follow the warning incident window and can roll into daily digests.
- Use workspace recipient routing or the site alert settings to choose who gets technology risk and technology stack-change emails, Slack, Teams, or webhooks.
- The first technology scan becomes the baseline; later scans can alert when components are added, removed, or change version.
- SSL certificate incidents remain in Crawle's dedicated SSL alert path so teams do not get duplicate risk notifications.
- Weekly reports include stack context and top open technology findings.
- CSV and JSON exports are available with finding state, severity, evidence, and advisory IDs.
Using agents
OAuth MCP tools expose the same stack and risk context to Claude, ChatGPT, Codex, Gemini, and internal agents.
- Grant technology:read so agents can summarize stack context and open findings.
- Grant technology:write only when agents should run scans, acknowledge findings, or update scan settings.
- Ask agents to separate deterministic findings from general hardening recommendations.
- Keep workspace context explicit when an account has multiple client workspaces.
Continuous monitoring
Put these docs to work on a real client site.
Set up continuous monitoring across your client portfolio.