🔧 Technology Detector

Identify the technologies, frameworks, and libraries used by any website including programming languages, CMS, and analytics tools.

💡 Tip: Enter a domain and click "Detect Technologies" to see what tech stack they use.
Enter a domain and click "Detect Technologies" to view results.

How a stack gets identified

Enter a domain and our server requests the page, then matches what comes back against known fingerprints, grouping whatever it recognises into categories. Nothing is executed - this is the served HTML and the response headers, read closely. Most software leaves marks like these without being asked to:

x-powered-by: PHP/8.2          the server admits it
<meta name="generator" ...>     the CMS signs the page
/wp-content/themes/...         paths give away WordPress
/_next/static/chunks/...       and these give away Next.js
PHPSESSID, ASP.NET_SessionId   cookie names name the runtime

Treat the list as evidence, not an inventory

Worth running against your own site. A x-powered-by header advertising an exact framework version is a free hint to anyone testing published vulnerabilities against it, and switching it off is usually a single line of server configuration.

Frequently asked questions

How can I tell whether a site runs on WordPress?

Three signs, any of which is close to conclusive: asset URLs containing /wp-content/ or /wp-includes/, a generator meta tag naming WordPress and its version, and a /wp-json/ link in the head or headers from the REST API. Hiding the first is difficult, which is why it is the reliable one.

Can I stop tools like this identifying my stack?

You can make it harder, not impossible. Removing x-powered-by, the server version and the generator meta tag deletes the easy answers, and a build step that renames and bundles assets hides the paths. Cookie names, response header order and framework-specific URL patterns remain. Treat it as reducing noise, not as a security measure.

Why does the result look different from what I see in devtools?

Because your browser ran the page and this did not. Devtools shows everything that eventually loaded, including scripts pulled in by other scripts; this shows what the server sent in the first response. The difference is roughly the set of third-party tools loaded at runtime.