Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Best overall: Wappalyzer is the most balanced choice when you need both a browser workflow and an API. BuiltWith is stronger for broad coverage, historical data and bulk intelligence; WhatCMS is a lightweight detector with batch and API options; W3Techs Site Info is built for structured benchmarking; and CMS Detect is the quickest one-click browser check.

All five infer a site’s stack from public fingerprints. They do not reveal private server configuration, and a customized, server-rendered or deliberately obscured site may expose too little evidence for a confident result.

What a CMS detector can (and cannot) tell you

A detector fetches one or more public pages and searches the response for clues associated with known platforms. WhatCMS describes these clues as generator tags, image paths, HTTP headers, session names and thousands of other artifacts. A result is therefore an inference about what was visible on the fetched page, not proof of every component running on the server.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Usually visible: a CMS name, version (when exposed), plugins or themes, JavaScript frameworks, analytics tags, web servers, hosting signals and CDN markers.
  • Often hidden: private plugins, server-side services, staging infrastructure, features loaded only after login, and systems whose identifying headers or paths have been removed.
  • Common causes of a partial result: a single-page application, aggressive caching, bot protection, a headless CMS, custom templates, regional content differences or a site that blocks automated requests.

Use a detector as reconnaissance. Confirm important findings by checking several pages, viewing the source and response headers, and treating an unreported technology as “not observed,” not “absent.” The vendors reviewed here do not publish a controlled, independent accuracy benchmark across all five tools, so this guide does not claim an accuracy ranking.

At-a-glance comparison

Tool Manual browser workflow API and automation Coverage and batch work Historical or statistical depth Pricing or limits stated by the vendor Evidence and confidence
Wappalyzer Website lookup and browser extension URL lookups, live results and recursive options through its API Broad CMS and wider technology enrichment; suited to scripted workflows Not its primary differentiator Free account includes 50 technology lookups per month; paid plans add larger limits and API credits Results identify detected technologies; inspect API fields for the evidence returned
BuiltWith Detailed domain lookup Domain API returns XML, JSON, CSV or XLSX More than 127,670 internet technologies displayed on its current lookup page; lists and trends support bulk research Strong historical changes, related-domain lists and market intelligence Plan limits vary; consult the current vendor pricing Domain API includes confidence scores and metadata
WhatCMS One-off detector and reports Technology endpoint, batch detections and API access Checks thousands of artifacts; also reports hosting and WordPress-theme information Focused on detection rather than long-term market statistics Free checks and paid/API options are offered; current limits vary Explains the artifacts used, which makes a result easier to audit
W3Techs Site Info Structured site-information view Site Info API Technology categories, names, versions and detection locations Newer-version percentages and benchmarking-oriented fields Published bundles range from 1,000 requests for 100 Euro to 100,000 for 2,000 Euro; requests are generally valid for one year Shows where on the site a technology was found and supplies version fields when available
CMS Detect Chrome extension and one-click browser check Automation is not its main emphasis CMS, frameworks and other technologies for quick checks Limited compared with BuiltWith or W3Techs Check the current extension and service terms for limits Fast result, but less evidence and confidence detail is exposed than in the API-focused tools

1. Wappalyzer: best overall for browser and API workflows

Choose Wappalyzer when your work alternates between inspecting a page yourself and feeding detections into a script, CRM or enrichment pipeline. Its website lookup handles a one-off question; the browser extension keeps detection beside the page you are reviewing; and the API supports URL lookups, live results and recursive options.

Why developers choose it

  • A single workflow covers manual research and automation.
  • The free account allowance is 50 technology lookups per month, useful for prototyping before purchasing more capacity.
  • Its output is broader than a CMS-only label, helping you identify frameworks, analytics and infrastructure that explain how a site is built.

Best workflow

  1. Run the site through the web lookup for an initial inventory.
  2. Open the same URL in the extension and inspect several internal pages, not only the home page.
  3. Move repeated checks to the API, recording the URL, timestamp and returned technologies so changes are auditable.

Wappalyzer is the best default when you do not yet know whether the job will remain manual or become an automated data flow.

2. BuiltWith: best for breadth, history and bulk intelligence

BuiltWith is the stronger choice when “Which CMS?” is only the first question. Its lookup page currently displays coverage of more than 127,670 internet technologies, a vendor figure that can change. Coverage spans CMSs, ecommerce systems, frameworks, analytics, hosting and other infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Useful capabilities

  • Domain API: request XML, JSON, CSV or XLSX, depending on how your pipeline consumes data.
  • Confidence and metadata: useful when you need to distinguish a strong signal from a weak match.
  • Lists and trends: support lead discovery, related-domain research and historical technology changes.

Pick BuiltWith for prospecting or market mapping where you need to find many domains, compare their stacks over time or export results for analysis. For a single developer checking one site, its breadth can be more than you need.

3. WhatCMS: best lightweight detector with batch and API options

WhatCMS is practical when you want a focused detector that still scales beyond one URL. Its service offers one-off checks, reports, batch detections, hosting and WordPress-theme detection, plus API access. The technology endpoint can return a CMS, programming language, database, web server and other technology data.

How its detection works

WhatCMS says: “Our detection algorithm checks for thousands of artifacts to determine if the requested page was generated by a CMS.” In practice, those artifacts include generator tags, image paths, headers and session names. This explanation is valuable because it tells you what a positive result represents and why a heavily customized site may produce little evidence.

Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

When it fits

  • Use the free one-off checker for a quick answer during debugging or competitive research.
  • Use batch detection when you have a list of domains and need a consistent report.
  • Use the API when CMS, hosting and WordPress-theme fields belong in the same enrichment record.

4. W3Techs Site Info: best for structured benchmarking

W3Techs Site Info is designed for people who need a defensible, structured record rather than a simple yes/no label. Its Site Info API returns technology categories such as Content Management System, technology names, versions when available, newer-version percentages and where on the site a technology was found.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the fields matter

  • Category and name: keep CMS results separate from servers, JavaScript libraries and analytics.
  • Version: allows upgrade or lifecycle analysis when the site exposes a version.
  • Detection location: shows whether the signal came from a page, header or another part of the site.
  • Newer-version percentage: supports benchmarking questions that a basic detector cannot answer.

Published request bundles range from 1,000 requests for 100 Euro to 100,000 for 2,000 Euro, and requests are generally valid for one year. Confirm current terms before budgeting, because bundles and prices can change.

5. CMS Detect: best for a simple one-click browser check

CMS Detect is the lowest-friction option when you want an answer while browsing. Its Chrome extension reports CMSs, frameworks and other technologies from the browser toolbar.

Choose it when speed matters most

  • You are checking a handful of sites manually.
  • You want an extension rather than an API account or export workflow.
  • You do not need historical changes, lead lists or detailed confidence metadata.

For recurring audits or data pipelines, move up to Wappalyzer, BuiltWith, WhatCMS or W3Techs, whose automation and structured output better match those jobs.

How to detect a CMS yourself from the browser

A detector is convenient, but you can validate its result with ordinary browser tools. This method is useful when an extension reports an unexpected platform or when you need to understand the evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open page source. Use your browser’s “View page source” command and search for generator, CMS-specific paths such as /wp-content/, theme names, script URLs and recognizable asset directories.
  2. Inspect response headers. In Developer Tools, open Network, reload the page and inspect the document request. Look for server, cache and platform headers, while remembering that headers can be removed or spoofed.
  3. Check cookies and storage. Session-cookie names can reveal a framework or CMS family, but do not treat a cookie alone as proof.
  4. Compare internal pages. Check an article, search page and contact page. A home page may be cached or built separately from the rest of the site.
  5. Record evidence. Save the URL, date, exact artifact and page where it appeared. Mark the conclusion as confirmed, probable or unknown.
  6. Cross-check with two detectors. Agreement increases confidence; disagreement is a reason to inspect source and headers rather than pick the more convenient answer.

Small browser-console helper

For a quick inventory of loaded scripts, run this in the page’s Developer Tools Console:

console.table([...document.scripts].map(s => s.src).filter(Boolean));

This only lists scripts visible to the current page. It does not identify server-side code and may miss resources loaded later or behind a login.

Or skip the browser setup

If you need a clean visual record of a page while investigating its stack, ScreenshotNeo can capture the URL with one request. It is a screenshot service, not a CMS detector: use it to preserve what a detector or browser actually saw, document a UI state, or attach visual evidence to an issue.

Before the capture, ScreenshotNeo accepts the cookie or consent banner like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status in X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

See the ScreenshotNeo API documentation for all options. Basic cURL example:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The service supports full-page captures with lazy images loaded, CSS-selector element shots, dark mode, 12 device presets or custom viewports, retina scale, PDF output, custom CSS and JavaScript, clicks, waits, blocked requests, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, selectable cache TTLs, signed image links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage data and an OpenAPI specification. Parameter names used by other screenshot APIs also work, which eases migration.

There is a free allowance of 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is included on every plan. Create a free ScreenshotNeo account to start.

Choosing the right detector

Your requirement Best fit Reason
Manual checks that may become scripted Wappalyzer Extension, lookup and API in one workflow
Large prospect lists or historical stack changes BuiltWith Broad coverage, confidence metadata, lists and trends
Quick checks plus batch, hosting or theme data WhatCMS Focused detector with batch and API options
Benchmarking, versions and detection locations W3Techs Site Info Structured fields and published request bundles
Fast one-off browser result CMS Detect Chrome toolbar workflow with minimal setup
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting unreliable or conflicting results

No CMS is detected

Check an internal page, source and headers. The site may be headless, fully custom, server-rendered without public markers or blocking the fetcher. Record “not observed” rather than naming a platform from a vague visual similarity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

Two tools report different CMSs

Compare the exact URLs and timestamps. One tool may have seen a cached page, a regional variant or a subdomain. Look for the underlying artifact and prefer the conclusion supported by a reproducible source or header.

The reported version is missing or implausible

Version fields are available only when a site exposes a recognizable version signal. Plugins, CDNs and custom builds can also make a component appear newer or older than the core CMS. Treat the version as an observed value, not a security guarantee.

API requests fail or consume credits unexpectedly

Verify authentication, URL encoding, redirects and rate limits; log the HTTP status and response body. Start with a small sample, cache results under your own retention policy and confirm whether the vendor bills submitted requests, successful detections or another unit.

The browser extension sees more than the API

Extensions run in a live browser and can observe post-load scripts, while an API may fetch a different rendering path. Compare user agent, cookies, geography and timing before treating the outputs as contradictory.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FAQ

Can a CMS detector identify a headless CMS?

Sometimes, if the front end exposes API paths, asset conventions or headers; often it cannot. A headless back end may leave no public fingerprint on the rendered site.

Is a detector’s result suitable as a vulnerability finding?

No. Detection is reconnaissance. Confirm the platform and version through authorized administration or asset inventory before making a security decision.

Should I test every page on a domain?

Test representative templates—home, article, search, login and a static page—because different sub-systems and caches can expose different signals.

Do these tools detect technologies other than CMSs?

Yes. Wappalyzer, BuiltWith, WhatCMS, W3Techs and CMS Detect can report broader technologies such as frameworks, analytics, hosting or web servers, although the exact fields differ by product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can a CMS detector identify a headless CMS?

Sometimes, if the front end exposes API paths, asset conventions or headers; often it cannot. A headless back end may leave no public fingerprint on the rendered site.

Is a detector’s result suitable as a vulnerability finding?

No. Detection is reconnaissance. Confirm the platform and version through authorized administration or asset inventory before making a security decision.

Should I test every page on a domain?

Test representative templates—home, article, search, login and a static page—because different sub-systems and caches can expose different signals.

Do these tools detect technologies other than CMSs?

Yes. Wappalyzer, BuiltWith, WhatCMS, W3Techs and CMS Detect can report broader technologies such as frameworks, analytics, hosting or web servers, although the exact fields differ by product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.