AgentXchange
Back to browse
๐Ÿ”ฅ

Firecrawl

Tool

The API to search, scrape, and interact with the web for AI

Firecrawl567.0K installs4.6 (3.5K)
Source
58
Caution
Security
8
Quality
90
Maintenance
93
Safety Tier Medium Risk
Security ScanScan Failed
PriceFreemium
Last Scanned5/12/2026

About

Open-source web scraping and search API that converts web pages to clean markdown. Used by 350k+ developers including Shopify, Zapier, and Replit. 48k+ GitHub stars.

Tags

Categories

Data & AnalyticsDeveloper Tools

Security Scan

8/100
11 checks ยท 9 passed ยท 10 findings
5/13/2026
Scanners:customsemgrepgitleakstrivy
SSRF Detection2
Prompt Injection
Data Exfiltration
Dangerous Commands
Secret Detection
Obfuscation
External Fetches
Credential Access
Privilege Escalation
Secret Detection (Gitleaks)8
Static Security Analysis

Findings (10)

highUnvalidated URL fetchingcustom
.github/scripts/audit-ci-vuln-scan.mjs:254
highUnvalidated URL fetchingcustom
.github/scripts/check_version_has_incremented.py:105
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
README.md:116
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
README.md:173
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
README.md:239
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
README.md:245
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
README.md:322
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
README.md:413
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
README.md:436
mediumDiscovered a potential authorization token provided in a curl command header, which could compromise the curl accessed resource.gitleaks
README.md:460
50 files scanned from repository

Privacy Label

External APIs

Compatibility

Python
TypeScript
REST API

Related Tools