Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Use a technology profiler for a fast first pass, then verify important findings against the website’s public source, headers, cookies, and browser-visible scripts. Profilers such as Wappalyzer and WhatRuns infer a site’s CMS, framework, ecommerce system, analytics, infrastructure and related components; they do not provide a guaranteed inventory of everything running behind the site.
Start by defining what you need to know
“What is this website built with?” can mean several different things. Decide which answer you need before opening a tool:
- CMS: WordPress, a hosted publishing system, or another content platform.
- Framework: the client- or server-side framework suggested by page scripts and markup.
- Ecommerce: the storefront platform, checkout provider, or payment technology.
- Marketing and measurement: analytics, advertising, tag-management and email tools.
- Infrastructure: hosting, CDN, web server and other publicly detectable services.
- Design components: plugins, themes and fonts exposed in the page.
A broad profile is useful for reconnaissance. A focused question—such as “Is the store using Shopify?”—makes it easier to distinguish a strong clue from an unrelated detection.
Method 1: Run a technology profiler
Use a website lookup for an occasional check
Wappalyzer’s technology lookup accepts a domain and returns a profile. Its lookup workflow can show cached or live results. Cached results are described as verified within the previous 30 days; a live result is intended to be more current. Treat the date and mode as part of the result, especially when a site may have been redesigned recently.
#1 Best Overall
WhatRuns also offers a one-click browser extension that reports technologies while you browse. Extensions are convenient when you are investigating many pages manually, but their categories and detection behavior differ. Compare the categories a tool covers with the question you actually have rather than assuming two tools’ lists are equivalent.
Interpret the list as evidence, not a certificate
A profiler infers technologies from public signals. Wappalyzer describes inspecting source code, HTTP headers, cookies, JavaScript variables and other observable information. A detected technology therefore means that the tool found a matching signal; it does not prove that the technology handles every part of the application or is still active on every route.
Look for context such as a version, a confidence indicator, a detected URL or a category. A very old version string may be a leftover generator value. A CDN detection may describe only the edge layer, not the application’s host. Record the page and date so you can recheck a time-sensitive conclusion.
Method 2: Inspect the page yourself
View the HTML source
- Open the page you want to examine.
- Use the browser’s View page source command (or its equivalent) rather than relying only on the rendered inspector.
- Search for distinctive terms such as
generator, platform names, script paths, asset directories and embedded configuration objects. - Record the exact clue, including its URL or attribute, before deciding what it proves.
Wappalyzer’s guide uses this recognizable WordPress example:
<meta name="generator" content="WordPress 4.9.8" />
This is a useful CMS clue, not a universal test. Many sites remove generator tags, proxies can rewrite markup, and a visible version can be stale. Never infer the whole backend from one meta element.
Rank #2
- HTML CSS Design and Build Web Sites
- Comes with secure packaging
- It can be a gift option
Check browser-visible signals
- HTTP headers: response headers can reveal a server, CDN, cache layer or framework-specific behavior.
- Cookies: names and attributes can indicate a platform or analytics service, although custom names and privacy tools reduce certainty.
- JavaScript variables: global configuration objects, data-layer entries and loaded script paths can identify analytics, storefront or frontend components.
- Network requests: in developer tools, inspect requests made during page load and checkout. Third-party origins can reveal services that are not obvious in the initial HTML.
- Asset paths: theme, plugin or framework directory names are useful corroboration when they are publicly exposed.
These are all public observations. They can identify what a page exposes without establishing private server code, database technology or an internal deployment pipeline.
Corroborate findings before relying on them
For a casual curiosity, one matching signal may be enough. For a migration, security review, competitive analysis or procurement decision, require at least two independent clues or a second profiler.
- Write down the profiler’s detection and the page or date on which it appeared.
- Find a second signal in source, headers, cookies or network requests.
- Check another relevant page, such as a product page or checkout, because a site’s stack can vary by route.
- Run a second profiler if the decision has material consequences.
- State the result narrowly: “This page exposes WordPress generator metadata” is stronger and more accurate than “The entire site is WordPress.”
Do not turn a missing signal into proof of absence. A site can hide headers, remove metadata, bundle scripts, render content only after JavaScript executes, or place a service behind a proxy.
Choose the right workflow
| Approach | Best fit | What to watch |
|---|---|---|
| Manual source and browser inspection | A focused question or verification of a particular clue | Requires interpreting HTML and other browser-visible signals; hidden server components remain out of reach. |
| Browser extension | Repeated manual research while browsing | Convenient, but categories and detection features vary between extensions. |
| Website lookup | A one-off domain check or broader profile | Cached and live results can differ in freshness and usage accounting. |
| API | Automated checks or integration into another workflow | Request limits and asynchronous crawling affect when a complete result appears. |
For repeated lookups, Wappalyzer’s API documentation notes an important edge case: if a site is not already in its dataset, the first response may contain no technologies while a crawl is running. An empty initial response is therefore not the same as “this site uses nothing.” Retry according to the service’s documented behavior and preserve the response time.
Automate checks carefully
An API is appropriate when you need a scheduled inventory, a list of domains checked in bulk, or a feed into another system. Before building around one, check its current request limits, authentication, bulk options, response schema and handling of crawl-in-progress states. Cache your own results with timestamps, avoid treating a transient empty response as a definitive answer, and recheck domains when your use case is time-sensitive.
Rank #3
Automation should also respect access controls and terms. Inspect only information the site makes publicly available, do not attempt to bypass bot checks or authentication, and keep the rate of requests reasonable.
Recommended Free Tools
Freshness, false positives and blind spots
Why results become stale
Sites change CMSs, replace analytics tags, migrate CDNs and redesign pages. A cached profile can lag behind a deployment, while a live crawl can encounter a temporary error or a route that does not expose the relevant component. Record whether a result was cached or live and its verification date.
Why a detection can be misleading
- A generator tag or JavaScript variable may be deliberately left over after migration.
- A hosted service may appear only on checkout, login or embedded content.
- A reverse proxy can conceal the origin server and make infrastructure detections incomplete.
- Minification, bundling and server-side rendering can hide familiar names.
- Multiple technologies can coexist: a WordPress marketing site may send checkout to a separate commerce platform.
What profilers cannot establish reliably
Public detection generally cannot reveal private application code, database engines, internal queues, exact hosting topology or security controls that are not exposed in responses. Phrase your conclusion around observable evidence and identify uncertainty instead of filling gaps with assumptions.
Troubleshooting checklist
The lookup returns no technologies
- Confirm that you entered the canonical domain and not a private or blocked URL.
- Try a live lookup if the service distinguishes it from cached results.
- Wait and retry when an API indicates that crawling is still in progress.
- Inspect source and network requests manually; JavaScript-heavy pages may expose clues only after rendering.
The profiler reports an implausible version
Search the source for the exact version string and check whether it comes from a generator tag, an asset filename or a live response. If no current signal corroborates it, report the product without the version or mark the version as unverified.
Two tools disagree
Compare the signal each tool cites, the page each one scanned and the time of the scan. One may be using cached data or detecting a technology on a different route. Verify the disputed claim with source, headers, cookies or network traffic before choosing a winner.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #4
- Brand: Wiley
- Set of 2 Volumes
- A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers
The page will not load for inspection
Do not bypass authentication or anti-bot controls. Try a publicly accessible page on the same domain, inspect an allowed response, or document that the technology could not be verified from public evidence.
Or skip the browser setup
If your goal is to capture the page while investigating it—or to automate visual evidence—ScreenshotNeo provides a website screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Only clean shots are billed: bot checks and CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and response headers identify the page verdict and billing status.
One request returns a PNG, JPEG, WebP or PDF. The same service supports full-page screenshots with lazy images loaded, CSS-selector element capture, dark mode, 12 device presets or a custom viewport, retina scale, PDF paper and page settings, custom CSS and JavaScript, clicks, selector or network-idle waits, request and resource blocking, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed image links, asynchronous jobs with signed webhooks, up to 100 URLs per bulk call, a usage API and an OpenAPI specification. Its parameter names are compatible with those used by other screenshot APIs.
For AI-assisted investigation, its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.
Using the documented endpoint:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo documentation for options and authentication. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.FAQ
Can I identify a site’s database from its homepage?
Usually not. A database is commonly behind server-side code and is not exposed in the public signals profilers inspect. Treat any claim about it as unverified unless the site itself publishes that information.
Best Value
Is a technology profile suitable for a security audit?
It can provide reconnaissance, but it is not a complete audit. Validate every material finding and use authorized, purpose-built assessment methods for security conclusions.
Should I check the homepage or every page?
Start with the homepage, then inspect routes relevant to your question—especially login, product, checkout and embedded-app pages. Different parts of one domain can use different services.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Frequently Asked Questions
Can I identify a site’s database from its homepage?
Usually not. Databases are generally behind server-side code and are not exposed by public profiler signals.
Is a technology profile suitable for a security audit?
It is reconnaissance, not a complete audit. Material findings require authorized validation and security-specific methods.
Should I check the homepage or every page?
Start with the homepage, then inspect routes relevant to your question, particularly login, product, checkout and embedded-app pages.
The Bottom Line
Use a profiler to form a hypothesis, verify it with multiple public signals, and attach a date and freshness note to every conclusion. That workflow is faster than guessing and more reliable than treating a detector’s list as the site’s complete architecture.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

