Website Tech Stack Detector - CMS, Framework & Analytics avatar

Website Tech Stack Detector - CMS, Framework & Analytics

Pricing

from $50.00 / 1,000 analysed domains

Go to Apify Store
Website Tech Stack Detector - CMS, Framework & Analytics

Website Tech Stack Detector - CMS, Framework & Analytics

Detect the technology behind any website: CMS, ecommerce platform, JS framework, hosting, CDN, analytics, payment and cookie-consent tools, plus a security-header scorecard.

Pricing

from $50.00 / 1,000 analysed domains

Rating

0.0

(0)

Developer

Apisight

Apisight

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

2 days ago

Last modified

Share

Website Tech Stack Scanner — CMS, Framework & Analytics Detector

Find out what any website is built with. Give it a list of domains and it returns the CMS, ecommerce platform, JavaScript framework, hosting, CDN, analytics, payment providers and cookie-consent tool behind each one — plus a security-header scorecard.

Built for competitive research, lead qualification by technology, migration audits and agency prospecting. Works on a single domain or thousands.

What it detects

Over 150 technologies across 30 categories:

CategoryExamples
CMSWordPress, Drupal, Webflow, Squarespace, Wix, Ghost, TYPO3, Sitecore, AEM, Contentful, Sanity, Framer
EcommerceShopify, WooCommerce, Magento, PrestaShop, BigCommerce, Shopware, Salesforce Commerce, Lightspeed
JS frameworkReact, Next.js, Vue, Nuxt, Angular, Svelte, SvelteKit, Astro, Remix, Gatsby, Alpine.js, htmx
Hosting / CDNVercel, Netlify, Cloudflare, Fastly, Akamai, CloudFront, WP Engine, Kinsta, Heroku, Render, Fly.io
AnalyticsGA4, Google Tag Manager, Plausible, Fathom, Matomo, PostHog, Mixpanel, Amplitude, Segment, Hotjar, Clarity
AdvertisingMeta Pixel, Google Ads, TikTok, LinkedIn Insight, Pinterest, Reddit
PaymentStripe, PayPal, Mollie, Adyen, Klarna, Afterpay, Apple Pay
Consent (CMP)Cookiebot, OneTrust, Usercentrics, CookieYes, Iubenda, Complianz, Osano, Termly
Alsoweb servers, runtimes, live chat, error monitoring, A/B testing, reviews, page builders, SEO plugins

Version numbers are extracted where the site discloses them (for example nginx 1.27.3, WordPress 6.8.1, Ghost 5.118).

Input

{
"startUrls": ["apify.com", "shopify.com", "wordpress.org"],
"includeSecurityHeaders": true,
"maxConcurrency": 10,
"requestTimeoutSecs": 20
}
FieldTypeDefaultNotes
startUrlsarray—Domains or full URLs. example.com and https://example.com/ both work. Duplicates are removed.
includeSecurityHeadersbooleantrueAdds the security-header scorecard. No extra cost.
maxConcurrencyinteger101–25.
requestTimeoutSecsinteger205–60.

Output

One record per domain:

{
"domain": "allbirds.com",
"status": "ok",
"httpStatus": 200,
"responseTimeMs": 412,
"pageTitle": "Allbirds | Everyday Shoes",
"https": true,
"technologyCount": 9,
"summary": {
"cms": [],
"ecommerce": ["Shopify"],
"jsFramework": ["React"],
"hosting": ["Cloudflare"],
"analytics": ["Google Tag Manager", "Google Analytics 4"],
"payment": ["Stripe", "Apple Pay"],
"consentPlatform": ["OneTrust"]
},
"technologies": [
{
"name": "Shopify",
"category": "Ecommerce",
"version": null,
"confidence": "high",
"matchedOn": ["header", "html"],
"evidence": "x-shopify-stage: production | markup: cdn.shopify.com"
}
],
"security": {
"headerScore": 67,
"headersPresent": {
"strictTransportSecurity": true,
"contentSecurityPolicy": false,
"xFrameOptions": true,
"xContentTypeOptions": true,
"referrerPolicy": true,
"permissionsPolicy": false
},
"versionDisclosure": { "server": "nginx/1.27.3" }
},
"scannedAt": "2026-09-30T09:14:02Z"
}

Every technology carries its own evidence and confidence, so you can verify any detection rather than trusting a bare label.

  • confidence: "high" — matched a response header, cookie or <meta generator> tag, or matched two independent signals.
  • confidence: "medium" — matched a single markup or asset-URL signal.

Pricing and what you are charged for

EventPriceWhen
domain-analysed$0.05Once per domain successfully analysed
apify-actor-start$0.00005Once per run (a twentieth of a cent)

You are not charged for results you cannot use. A target that returns status: "blocked" or status: "error" costs you nothing. Those records still appear in your dataset, with a blockReason explaining exactly what happened — we would rather hand you an honest failure you can see than a half-empty guess you would have to catch yourself.

There is no per-record dataset charge, so a run full of blocked sites costs you essentially nothing beyond the fraction-of-a-cent start fee.

Honest limitations

  • Sites behind bot protection cannot be fingerprinted. Some sites (Cloudflare challenges, DataDome, PerimeterX, Incapsula) serve an interstitial instead of the real page. These are reported as status: "blocked" and are not billed. This is a hard limit of any HTTP-based scanner, and we would rather tell you than return a half-empty guess.
  • Detection is based on the homepage. Technologies that only load on checkout, login or deep pages may be missed. Pass those specific URLs directly if you need them.
  • Client-side-only technologies may be under-reported, since no JavaScript is executed. This keeps the scanner fast and cheap; for full rendering you would need a browser-based tool.
  • No personal data. This Actor reads only public technical metadata — HTTP headers, markup and asset URLs. It does not collect emails, names, contact details or any personal data, and is not intended for building contact lists.

Common uses

  • Agency prospecting — find every prospect still on an outdated CMS.
  • Competitive research — see which analytics, payment and CMP vendors a market uses.
  • Lead qualification — filter a domain list down to Shopify or WooCommerce stores.
  • Migration and due diligence — inventory a portfolio of sites before a replatform.
  • Compliance review — check which consent platform and security headers a site uses.

FAQ

Can I scan thousands of domains? Yes. Pass them all in startUrls and raise maxConcurrency. Cost scales linearly with successfully analysed domains only.

Why does a site show fewer technologies than I expect? Either it is behind bot protection (check status and blockReason), or the technology only appears on pages other than the homepage, or it is injected by JavaScript at runtime.

Is the version number always present? No. Most sites deliberately hide version numbers. We report a version only when the site discloses it, and never guess.