Documentation

Technology stack and risk signals

Use Crawle's passive technology intelligence to understand visible frameworks, client libraries, CMS markers, security headers, and exposed-version risks.

Workspace technology intelligence

Technology

Visible stack, evidence categories, and risk signals across the workspace

Jun 9
Sites scanned0/6in this workspace
Total components0across the stack
High-risk sites0needs review
Open findings0across scanned sites
Unavailable sites0unreachable

Common components

Most frequent visible technologies across the workspace.

  • React4 sites
  • Next.js2 sites
  • Cloudflare2 sites
  • Stripe1 site
  • Tailwind CSS1 site
  • Vercel1 site
  • Plausible Analytics1 site
  • Docusaurus1 site
  • Algolia1 site
  • nginx1 site

Evidence categories

Where Crawle is finding stack evidence.

  • JavaScript libraries43
  • Security headers17
  • Analytics & tags16
  • Frameworks15
  • CDN / edge12
  • Web servers9

Sites

Open a site to inspect evidence, run an on-demand scan, or acknowledge a finding.

Top signals
Storefront
shop.crawle-demo.io
Scanned3892 high riskJun 9, 6:30 AM
Next.jsReactCloudflareStripe
Marketing site
www.crawle-demo.io
Scanned274Jun 9, 5:10 AM
Next.jsReactVercelPlausible Analytics
Documentation
docs.crawle-demo.io
Scanned192Jun 8, 10:48 PM
DocusaurusReactAlgoliaCloudflare
Customer app
app.crawle-demo.io
Scanned3361 high riskJun 9, 4:02 AM
ReactnginxSentryDatadog
Blog
blog.crawle-demo.io
Not scanned00NeverNo signals yet
Legacy portal
legacy.crawle-demo.io
Host unreachable on the last scan (connection timed out).
Unavailable143May 31, 1:25 PM
WordPressPHPApache
Workspace-level technology intelligence shows detected components, evidence categories, findings, and site coverage across the current client filter.

What Crawle checks

Technology scans reuse normal crawl evidence instead of running intrusive security probes.

  • Response headers, public HTML markers, meta generator tags, and script/style URLs.
  • Framework and platform hints such as Next.js, Shopify, WordPress, Cloudflare, Vercel, nginx, Apache, and PHP.
  • Exposed client-library versions where public assets reveal them.
  • Security-header posture such as HSTS and Content-Security-Policy on sampled HTTPS responses.
  • Optional cached enrichment from OSV.dev, CISA KEV, FIRST EPSS, and endoflife.date when enabled.

Risk language

Findings are presented as technology risk signals, not as a replacement for a dedicated security scanner.

  • High-severity exposed-version findings require deterministic public evidence.
  • Unknown versions are shown as context, not as version-specific vulnerability claims.
  • AI-assisted review, when enabled later, must not be the sole source for critical findings.
  • Evidence is bounded and sensitive headers such as cookies and authorization values are redacted.

Scan cadence

Automatic scans run monthly by default and can be adjusted per site.

  • Run an on-demand scan from the Technology tab when a team has changed frameworks or frontend bundles.
  • Keep automatic scans enabled for client sites where stack drift or exposed old assets matter.
  • Disable scans per site if the customer does not want technology posture checks.
  • Crawle stores the current profile and finding history so agents and reports can reference it later.

Alerts and reports

Technology risk signals and stack changes use the same routing controls as the rest of Crawle.

  • Critical and high deterministic findings follow the critical incident window and can notify in real time.
  • Warnings follow the warning incident window and can roll into daily digests.
  • Use workspace recipient routing or the site alert settings to choose who gets technology risk and technology stack-change emails, Slack, Teams, or webhooks.
  • The first technology scan becomes the baseline; later scans can alert when components are added, removed, or change version.
  • SSL certificate incidents remain in Crawle's dedicated SSL alert path so teams do not get duplicate risk notifications.
  • Weekly reports include stack context and top open technology findings.
  • CSV and JSON exports are available with finding state, severity, evidence, and advisory IDs.

Using agents

OAuth MCP tools expose the same stack and risk context to Claude, ChatGPT, Codex, Gemini, and internal agents.

  • Grant technology:read so agents can summarize stack context and open findings.
  • Grant technology:write only when agents should run scans, acknowledge findings, or update scan settings.
  • Ask agents to separate deterministic findings from general hardening recommendations.
  • Keep workspace context explicit when an account has multiple client workspaces.

Continuous monitoring

Put these docs to work on a real client site.

Set up continuous monitoring across your client portfolio.