CMS & Tech Detector
Free, no signup. Inspect a public page for visible CMS, framework, CDN, ecommerce, analytics, JavaScript, and font fingerprints — with the exact evidence that fired.
The HAR is parsed locally and is not uploaded. Request bodies, cookies, headers, and query values are not retained by tag inventory.
Checks run from our server; we fetch the URL you enter and don't keep the results. We fetch the URL you enter; the detector runs in your browser. Optional HAR parsing stays in this browser tab. Anonymous run-level outcome counters may be used for aggregate research; URLs, domains, IPs, and identifiers are never included, and no statistic is released below 100 runs.
Sample report
Illustrative example — deterministic supported signatures
For HTML containing <meta name="generator" content="WordPress"> and asset paths under /wp-content/, the detector reports:
A single supported fingerprint would be medium confidence. No match would produce an explicit “no signatures matched” message, not a claim that the page uses no technology.
How to use it
- Enter a public page URL, ideally a representative page rather than a login screen.
- Choose Detect stack and review each technology, category, confidence, and evidence string.
- Confirm important detections in source, response headers, or the platform itself before acting on them.
- Check more than one template when a site may use different technology by section.
Site passport Local context for this saved site
Local data
Saved targets, named lists, and recent check summaries remain only in this browser.
Visible fingerprints
Tag inventory evidence
Rate this tool
How to read the result
- High confidence means more than one signature for that technology matched.
- Medium confidence means one supported signature matched.
- Evidence names the signature rules that fired; it should be reviewed before treating a detection as fact.
- No signatures matched means only that the current raw HTML and selected headers lacked a known signal.
Data sources & freshness
The server fetches public HTML and a selected response-header map. In the browser, the detector lowercases those values and compares them to a curated JSON signature list covering HTML substrings, generator metadata, headers, and supported cookie names. Matches are grouped by technology and sorted by category and name.
Features
- CMSA content management system (CMS) is software that lets users create, manage, and publish digital content — like blog posts and pages — without writing raw code. WordPress, Drupal, and Joomla are the most common open-source CMS platforms., framework, CDN, ecommerce, analytics, JavaScript, and font categories.
- Exact evidence for every detection.
- Two transparent confidence levels based on match count.
- Browser-side matching after the public fetch.
Limitations
The checker does not render JavaScript, scan a whole site, identify private infrastructure, verify versions, or test vulnerabilities. Proxies, tag managers, cached markup, and removed or spoofed fingerprints can cause false negatives or false positives.
Frequently asked questions
How does a technology detector identify a CMS or framework?
It matches public fingerprints in raw HTML and selected response headers against a maintained signature list. The report shows the exact signal that matched so you can judge it.
Why did the detector miss a technology I know the site uses?
A site can remove generator tags, proxy assets, rename paths, render signals with JavaScript, or hide origin headers behind a CDN. No match means no supported public signature was observed, not that the technology is absent.
Can a tech-stack detection be wrong?
Yes. Public strings can be shared, stale, or spoofed. One matching signal is medium confidence; multiple supported signals raise confidence, but neither is proof of the complete production stack.
Is this a vulnerability scanner?
No. It does not test versions, vulnerabilities, ports, authentication, or application behavior. It only reports supported public fingerprints.
Feature requests for Tech Stack Checker
Upvote what you want most. New ideas can be submitted from the floating Feedback menu; requests appear here once approved, and the most-wanted rise to the top.
You won't be emailed about that request anymore.
Loading…
➕ Request a feature
New requests are reviewed before they appear here.
Tentang alat
Batasan pemeriksa tidak render JavaScript, scan seluruh situs, identifikasi privat infrastructure, verifikasi versions, atau uji vulnerabilities. Proxies, tag managers, disimpan di cache markup, dan dihapus atau spoofed fingerprints dapat penyebab false negatives atau false positives.
Bagaimana untuk gunakan ini Masukkan publik halaman URL, ideally perwakilan halaman daripada daripada login screen. Pilih Detect stack dan tinjau setiap technology, kategori, confidence, dan bukti string. Konfirmasi penting detections di sumber, header respons, atau platform dirinya sendiri sebelum acting pada mereka. Periksa lebih banyak daripada satu template ketika situs mungkin gunakan berbeda technology oleh section.
Gratis, tanpa pendaftaran. Periksa publik halaman untuk terlihat CMS, framework, CDN, ecommerce, analytics, JavaScript, dan font fingerprints — dengan tepat bukti yang fired. Halaman URL Detect stack Opsional lokal HAR bukti HAR adalah parsed secara lokal dan tidak diunggah. Permintaan bodies, cookies, header, dan kueri nilai tidak dipertahankan oleh tag inventaris.
Fitur
- detection berarti publik sinyal cocok, tidak yang technology adalah definitively present atau digunakan everywhere. Situs dapat hapus, proxy, spoof, atau perubahan ini sinyal; ini tidak keamanan scan.
- Adalah ini vulnerability scanner?
- Bagaimana melakukan technology detector identifikasi CMS atau framework?
- Ini cocok publik fingerprints di mentah HTML dan dipilih header respons terhadap maintained signature daftar. laporan menunjukkan tepat sinyal yang cocok so Anda dapat judge ini.
- situs dapat hapus generator tag, proxy aset, rename jalur, render sinyal dengan JavaScript, atau menyembunyikan asal header di balik CDN. Tidak ada cocok berarti tidak ada supported publik signature adalah teramati, tidak yang technology tidak ada.
Cara kerja
Mengapa detector miss technology I know situs menggunakan? Dapat tech-stack detection menjadi salah? Data sumber & kebaruan server mengambil publik HTML dan dipilih respons-header peta. Di browser, detector lowercases itu nilai dan membandingkan mereka untuk curated JSON signature daftar covering HTML substrings, generator metadata, header, dan supported cookie menyebut. Cocok adalah grouped oleh technology dan sorted oleh kategori dan nama. Terlihat fingerprints Tag inventaris bukti
Batasan
- Bagaimana untuk baca hasil Tinggi confidence berarti lebih banyak daripada satu signature untuk yang technology cocok. Sedang confidence berarti satu supported signature cocok. Bukti menyebut signature aturan yang fired; ini seharusnya menjadi ditinjau sebelum treating detection sebagai fakta. Tidak ada signatures cocok berarti hanya yang saat ini mentah HTML dan dipilih header lacked diketahui sinyal.
- Identifikasi terlihat CMS, framework, CDN, dan analytics fingerprints dari publik HTML dan dipilih header respons.
- Tidak. Ini tidak uji versions, vulnerabilities, ports, authentication, atau aplikasi perilaku. Ini hanya laporan supported publik fingerprints.
- Ya. Publik strings dapat menjadi bersama, usang, atau spoofed. Satu mencocokkan sinyal adalah sedang confidence; multiple supported sinyal raise confidence, tetapi neither adalah proof dari lengkap produksi stack.
Pertanyaan umum
Identifikasi terlihat CMS, framework, CDN, dan analytics fingerprints dari publik HTML dan dipilih header respons.
Tidak. Ini tidak uji versions, vulnerabilities, ports, authentication, atau aplikasi perilaku. Ini hanya laporan supported publik fingerprints.
Ya. Publik strings dapat menjadi bersama, usang, atau spoofed. Satu mencocokkan sinyal adalah sedang confidence; multiple supported sinyal raise confidence, tetapi neither adalah proof dari lengkap produksi stack.
Mengapa detector miss technology I know situs menggunakan?
Dapat tech-stack detection menjadi salah?
Data sumber & kebaruan server mengambil publik HTML dan dipilih respons-header peta. Di browser, detector lowercases itu nilai dan membandingkan mereka untuk curated JSON signature daftar covering HTML substrings, generator metadata, header, dan supported cookie menyebut. Cocok adalah grouped oleh technology dan sorted oleh kategori dan nama.
Terlihat fingerprints Tag inventaris bukti
Fitur, framework, CDN, ecommerce, analytics, JavaScript, dan font kategori. Tepat bukti untuk setiap detection. Dua transparan confidence levels berdasarkan pada cocok count. Browser-side mencocokkan setelah publik ambil.