Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Use a technology profiler for a fast first pass, then verify important findings against the website’s public source, headers, cookies, and browser-visible scripts. Profilers such as Wappalyzer and WhatRuns infer a site’s CMS, framework, ecommerce system, analytics, infrastructure and related components; they do not provide a guaranteed inventory of everything running behind the site.

Start by defining what you need to know

“What is this website built with?” can mean several different things. Decide which answer you need before opening a tool:

  • CMS: WordPress, a hosted publishing system, or another content platform.
  • Framework: the client- or server-side framework suggested by page scripts and markup.
  • Ecommerce: the storefront platform, checkout provider, or payment technology.
  • Marketing and measurement: analytics, advertising, tag-management and email tools.
  • Infrastructure: hosting, CDN, web server and other publicly detectable services.
  • Design components: plugins, themes and fonts exposed in the page.

A broad profile is useful for reconnaissance. A focused question—such as “Is the store using Shopify?”—makes it easier to distinguish a strong clue from an unrelated detection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Method 1: Run a technology profiler

Use a website lookup for an occasional check

Wappalyzer’s technology lookup accepts a domain and returns a profile. Its lookup workflow can show cached or live results. Cached results are described as verified within the previous 30 days; a live result is intended to be more current. Treat the date and mode as part of the result, especially when a site may have been redesigned recently.

WhatRuns also offers a one-click browser extension that reports technologies while you browse. Extensions are convenient when you are investigating many pages manually, but their categories and detection behavior differ. Compare the categories a tool covers with the question you actually have rather than assuming two tools’ lists are equivalent.

Interpret the list as evidence, not a certificate

A profiler infers technologies from public signals. Wappalyzer describes inspecting source code, HTTP headers, cookies, JavaScript variables and other observable information. A detected technology therefore means that the tool found a matching signal; it does not prove that the technology handles every part of the application or is still active on every route.

Look for context such as a version, a confidence indicator, a detected URL or a category. A very old version string may be a leftover generator value. A CDN detection may describe only the edge layer, not the application’s host. Record the page and date so you can recheck a time-sensitive conclusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Method 2: Inspect the page yourself

View the HTML source

  1. Open the page you want to examine.
  2. Use the browser’s View page source command (or its equivalent) rather than relying only on the rendered inspector.
  3. Search for distinctive terms such as generator, platform names, script paths, asset directories and embedded configuration objects.
  4. Record the exact clue, including its URL or attribute, before deciding what it proves.

Wappalyzer’s guide uses this recognizable WordPress example:

<meta name="generator" content="WordPress 4.9.8" />

This is a useful CMS clue, not a universal test. Many sites remove generator tags, proxies can rewrite markup, and a visible version can be stale. Never infer the whole backend from one meta element.

Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

Check browser-visible signals

  • HTTP headers: response headers can reveal a server, CDN, cache layer or framework-specific behavior.
  • Cookies: names and attributes can indicate a platform or analytics service, although custom names and privacy tools reduce certainty.
  • JavaScript variables: global configuration objects, data-layer entries and loaded script paths can identify analytics, storefront or frontend components.
  • Network requests: in developer tools, inspect requests made during page load and checkout. Third-party origins can reveal services that are not obvious in the initial HTML.
  • Asset paths: theme, plugin or framework directory names are useful corroboration when they are publicly exposed.

These are all public observations. They can identify what a page exposes without establishing private server code, database technology or an internal deployment pipeline.

Corroborate findings before relying on them

For a casual curiosity, one matching signal may be enough. For a migration, security review, competitive analysis or procurement decision, require at least two independent clues or a second profiler.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Write down the profiler’s detection and the page or date on which it appeared.
  2. Find a second signal in source, headers, cookies or network requests.
  3. Check another relevant page, such as a product page or checkout, because a site’s stack can vary by route.
  4. Run a second profiler if the decision has material consequences.
  5. State the result narrowly: “This page exposes WordPress generator metadata” is stronger and more accurate than “The entire site is WordPress.”

Do not turn a missing signal into proof of absence. A site can hide headers, remove metadata, bundle scripts, render content only after JavaScript executes, or place a service behind a proxy.

Choose the right workflow

Approach Best fit What to watch
Manual source and browser inspection A focused question or verification of a particular clue Requires interpreting HTML and other browser-visible signals; hidden server components remain out of reach.
Browser extension Repeated manual research while browsing Convenient, but categories and detection features vary between extensions.
Website lookup A one-off domain check or broader profile Cached and live results can differ in freshness and usage accounting.
API Automated checks or integration into another workflow Request limits and asynchronous crawling affect when a complete result appears.

For repeated lookups, Wappalyzer’s API documentation notes an important edge case: if a site is not already in its dataset, the first response may contain no technologies while a crawl is running. An empty initial response is therefore not the same as “this site uses nothing.” Retry according to the service’s documented behavior and preserve the response time.

Automate checks carefully

An API is appropriate when you need a scheduled inventory, a list of domains checked in bulk, or a feed into another system. Before building around one, check its current request limits, authentication, bulk options, response schema and handling of crawl-in-progress states. Cache your own results with timestamps, avoid treating a transient empty response as a definitive answer, and recheck domains when your use case is time-sensitive.

Automation should also respect access controls and terms. Inspect only information the site makes publicly available, do not attempt to bypass bot checks or authentication, and keep the rate of requests reasonable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Freshness, false positives and blind spots

Why results become stale

Sites change CMSs, replace analytics tags, migrate CDNs and redesign pages. A cached profile can lag behind a deployment, while a live crawl can encounter a temporary error or a route that does not expose the relevant component. Record whether a result was cached or live and its verification date.

Why a detection can be misleading

  • A generator tag or JavaScript variable may be deliberately left over after migration.
  • A hosted service may appear only on checkout, login or embedded content.
  • A reverse proxy can conceal the origin server and make infrastructure detections incomplete.
  • Minification, bundling and server-side rendering can hide familiar names.
  • Multiple technologies can coexist: a WordPress marketing site may send checkout to a separate commerce platform.

What profilers cannot establish reliably

Public detection generally cannot reveal private application code, database engines, internal queues, exact hosting topology or security controls that are not exposed in responses. Phrase your conclusion around observable evidence and identify uncertainty instead of filling gaps with assumptions.

Troubleshooting checklist

The lookup returns no technologies

  • Confirm that you entered the canonical domain and not a private or blocked URL.
  • Try a live lookup if the service distinguishes it from cached results.
  • Wait and retry when an API indicates that crawling is still in progress.
  • Inspect source and network requests manually; JavaScript-heavy pages may expose clues only after rendering.

The profiler reports an implausible version

Search the source for the exact version string and check whether it comes from a generator tag, an asset filename or a live response. If no current signal corroborates it, report the product without the version or mark the version as unverified.

Two tools disagree

Compare the signal each tool cites, the page each one scanned and the time of the scan. One may be using cached data or detecting a technology on a different route. Verify the disputed claim with source, headers, cookies or network traffic before choosing a winner.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

The page will not load for inspection

Do not bypass authentication or anti-bot controls. Try a publicly accessible page on the same domain, inspect an allowed response, or document that the technology could not be verified from public evidence.

Or skip the browser setup

If your goal is to capture the page while investigating it—or to automate visual evidence—ScreenshotNeo provides a website screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each cleanup step can be disabled. Only clean shots are billed: bot checks and CAPTCHAs, blank pages, timeouts, failed loads and cache hits cost nothing, and response headers identify the page verdict and billing status.

One request returns a PNG, JPEG, WebP or PDF. The same service supports full-page screenshots with lazy images loaded, CSS-selector element capture, dark mode, 12 device presets or a custom viewport, retina scale, PDF paper and page settings, custom CSS and JavaScript, clicks, selector or network-idle waits, request and resource blocking, headers, cookies, user agents, authorization, timezone, geolocation, transparent backgrounds, resizing, chosen cache TTLs, signed image links, asynchronous jobs with signed webhooks, up to 100 URLs per bulk call, a usage API and an OpenAPI specification. Its parameter names are compatible with those used by other screenshot APIs.

For AI-assisted investigation, its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Using the documented endpoint:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

See the ScreenshotNeo documentation for options and authentication. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

FAQ

Can I identify a site’s database from its homepage?

Usually not. A database is commonly behind server-side code and is not exposed in the public signals profilers inspect. Treat any claim about it as unverified unless the site itself publishes that information.

Is a technology profile suitable for a security audit?

It can provide reconnaissance, but it is not a complete audit. Validate every material finding and use authorized, purpose-built assessment methods for security conclusions.

Should I check the homepage or every page?

Start with the homepage, then inspect routes relevant to your question—especially login, product, checkout and embedded-app pages. Different parts of one domain can use different services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Can I identify a site’s database from its homepage?

Usually not. Databases are generally behind server-side code and are not exposed by public profiler signals.

Is a technology profile suitable for a security audit?

It is reconnaissance, not a complete audit. Material findings require authorized validation and security-specific methods.

Should I check the homepage or every page?

Start with the homepage, then inspect routes relevant to your question, particularly login, product, checkout and embedded-app pages.

The Bottom Line

Use a profiler to form a hypothesis, verify it with multiple public signals, and attach a date and freshness note to every conclusion. That workflow is faster than guessing and more reliable than treating a detector’s list as the site’s complete architecture.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.