Free tool · Developer
Website technology detector
Find out what a website is built with: CMS or eCommerce platform, frameworks, web server, CDN, analytics, tag manager, cookie consent tool, structured data, HTTP protocol and security headers.
Technology Checker
What it detects
More than 130 technologies from public fingerprints
Every platform leaves traces in what a server sends: response headers such as Server or X-Powered-By, cookie names, the generator meta tag, asset paths like /wp-content/ or /static/frontend/, and script addresses of third-party services. The detector reads one response and matches these fingerprints, showing the evidence for each result.
CMS and eCommerce
WordPress, WooCommerce, Magento 2 / Adobe Commerce, Magento 1, Shopify, PrestaShop, Shopware, BigCommerce, OpenCart, Drupal, Joomla, TYPO3, Webflow, Wix, Squarespace, Ghost, HubSpot CMS and more, with versions where the site exposes them.
Frameworks and libraries
Next.js, Nuxt, Gatsby, Remix, Astro, SvelteKit, React, Vue, Angular, Laravel, Livewire, Symfony, Django, Ruby on Rails, ASP.NET, jQuery with its version, Bootstrap, Tailwind CSS and others.
Server, CDN and hosting
nginx, Apache, LiteSpeed, IIS, Caddy and Varnish; Cloudflare, Fastly, Akamai, Amazon CloudFront, Bunny CDN and Azure Front Door; Vercel, Netlify, WP Engine, Kinsta and similar hosts.
Analytics, tags and marketing
Google Tag Manager, Google Analytics 4, retired Universal Analytics tags, Matomo, Plausible, Hotjar, Microsoft Clarity, Meta Pixel, LinkedIn Insight, HubSpot, Klaviyo and more.
Consent and security
Cookiebot, OneTrust, CookieYes, Complianz, Usercentrics, Didomi, iubenda and Google Consent Mode; reCAPTCHA, hCaptcha, Cloudflare Turnstile, Sucuri and Imperva.
Protocol, schema and headers
The negotiated HTTP version and whether HTTP/3 is advertised, compression, structured data types, and how many of the six key security headers are set well.
Why it matters
Know the stack before you quote, audit or migrate
Agencies and developers look up a site’s technology before a sales call, an estimate or a takeover of maintenance. Knowing that a store runs Magento 1, or that a site still loads an old jQuery version and a retired analytics tag, changes the scope and the risks of the work.
Site owners use it too: to confirm what a previous agency installed, to find tracking scripts nobody remembers adding, or to check that a CDN and HTTP/2 are actually active after a hosting change.
The technical recommendations only follow from what was detected: end-of-life platforms and PHP versions, jQuery releases with published vulnerabilities, missing compression or HTTP/2, exposed version numbers, weak security headers, several overlapping analytics tools, and tracking scripts without a detectable consent tool.
Limits of detection
No JavaScript runs, so services loaded later by a tag manager may not appear, and a platform that hides its fingerprints can go undetected. A service can occasionally be listed because the page references it without using it. Versions appear only when the site publishes them.
Questions
About the technology
detector
For the full list of response headers and recommended security header values, use the HTTP Headers Checker.
How is this different from browser extensions like Wappalyzer?
The idea is similar: matching known fingerprints. Extensions also see what JavaScript loads after the page opens; this tool reads what the server sends, which is what many crawlers see, and needs no installation.
Why is my WordPress version shown?
WordPress adds a generator meta tag with its version unless a theme or plugin removes it. Keeping WordPress updated matters far more than hiding the tag, but removing it stops casual version scans.
The site uses Google Analytics but it was not detected. Why?
It is probably loaded through Google Tag Manager or a consent tool after the page loads. The detector lists Google Tag Manager when it finds the container script.
Is it legal to check someone else’s website?
The tool makes one normal request to a public page, as any visitor’s browser does, and reads only what is publicly sent.
Is anything stored?
The result is cached for 20 minutes, then deleted. Usage is counted anonymously with the host name only.
Need help with what
the tools found?
HUB engineers implement technical SEO, performance, security and AI-readiness fixes on WordPress, Magento, custom PHP and modern JavaScript stacks.