Website Tech Stack Detector - CMS, Framework & Analytics
Pricing
from $50.00 / 1,000 analysed domains
Website Tech Stack Detector - CMS, Framework & Analytics
Detect the technology behind any website: CMS, ecommerce platform, JS framework, hosting, CDN, analytics, payment and cookie-consent tools, plus a security-header scorecard.
Pricing
from $50.00 / 1,000 analysed domains
Rating
0.0
(0)
Developer
Apisight
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
2 days ago
Last modified
Categories
Share
Website Tech Stack Scanner — CMS, Framework & Analytics Detector
Find out what any website is built with. Give it a list of domains and it returns the CMS, ecommerce platform, JavaScript framework, hosting, CDN, analytics, payment providers and cookie-consent tool behind each one — plus a security-header scorecard.
Built for competitive research, lead qualification by technology, migration audits and agency prospecting. Works on a single domain or thousands.
What it detects
Over 150 technologies across 30 categories:
| Category | Examples |
|---|---|
| CMS | WordPress, Drupal, Webflow, Squarespace, Wix, Ghost, TYPO3, Sitecore, AEM, Contentful, Sanity, Framer |
| Ecommerce | Shopify, WooCommerce, Magento, PrestaShop, BigCommerce, Shopware, Salesforce Commerce, Lightspeed |
| JS framework | React, Next.js, Vue, Nuxt, Angular, Svelte, SvelteKit, Astro, Remix, Gatsby, Alpine.js, htmx |
| Hosting / CDN | Vercel, Netlify, Cloudflare, Fastly, Akamai, CloudFront, WP Engine, Kinsta, Heroku, Render, Fly.io |
| Analytics | GA4, Google Tag Manager, Plausible, Fathom, Matomo, PostHog, Mixpanel, Amplitude, Segment, Hotjar, Clarity |
| Advertising | Meta Pixel, Google Ads, TikTok, LinkedIn Insight, Pinterest, Reddit |
| Payment | Stripe, PayPal, Mollie, Adyen, Klarna, Afterpay, Apple Pay |
| Consent (CMP) | Cookiebot, OneTrust, Usercentrics, CookieYes, Iubenda, Complianz, Osano, Termly |
| Also | web servers, runtimes, live chat, error monitoring, A/B testing, reviews, page builders, SEO plugins |
Version numbers are extracted where the site discloses them (for example nginx 1.27.3,
WordPress 6.8.1, Ghost 5.118).
Input
{"startUrls": ["apify.com", "shopify.com", "wordpress.org"],"includeSecurityHeaders": true,"maxConcurrency": 10,"requestTimeoutSecs": 20}
| Field | Type | Default | Notes |
|---|---|---|---|
startUrls | array | — | Domains or full URLs. example.com and https://example.com/ both work. Duplicates are removed. |
includeSecurityHeaders | boolean | true | Adds the security-header scorecard. No extra cost. |
maxConcurrency | integer | 10 | 1–25. |
requestTimeoutSecs | integer | 20 | 5–60. |
Output
One record per domain:
{"domain": "allbirds.com","status": "ok","httpStatus": 200,"responseTimeMs": 412,"pageTitle": "Allbirds | Everyday Shoes","https": true,"technologyCount": 9,"summary": {"cms": [],"ecommerce": ["Shopify"],"jsFramework": ["React"],"hosting": ["Cloudflare"],"analytics": ["Google Tag Manager", "Google Analytics 4"],"payment": ["Stripe", "Apple Pay"],"consentPlatform": ["OneTrust"]},"technologies": [{"name": "Shopify","category": "Ecommerce","version": null,"confidence": "high","matchedOn": ["header", "html"],"evidence": "x-shopify-stage: production | markup: cdn.shopify.com"}],"security": {"headerScore": 67,"headersPresent": {"strictTransportSecurity": true,"contentSecurityPolicy": false,"xFrameOptions": true,"xContentTypeOptions": true,"referrerPolicy": true,"permissionsPolicy": false},"versionDisclosure": { "server": "nginx/1.27.3" }},"scannedAt": "2026-09-30T09:14:02Z"}
Every technology carries its own evidence and confidence, so you can verify any
detection rather than trusting a bare label.
confidence: "high"— matched a response header, cookie or<meta generator>tag, or matched two independent signals.confidence: "medium"— matched a single markup or asset-URL signal.
Pricing and what you are charged for
| Event | Price | When |
|---|---|---|
domain-analysed | $0.05 | Once per domain successfully analysed |
apify-actor-start | $0.00005 | Once per run (a twentieth of a cent) |
You are not charged for results you cannot use. A target that returns
status: "blocked" or status: "error" costs you nothing. Those records still appear in
your dataset, with a blockReason explaining exactly what happened — we would rather hand
you an honest failure you can see than a half-empty guess you would have to catch yourself.
There is no per-record dataset charge, so a run full of blocked sites costs you essentially nothing beyond the fraction-of-a-cent start fee.
Honest limitations
- Sites behind bot protection cannot be fingerprinted. Some sites (Cloudflare
challenges, DataDome, PerimeterX, Incapsula) serve an interstitial instead of the real
page. These are reported as
status: "blocked"and are not billed. This is a hard limit of any HTTP-based scanner, and we would rather tell you than return a half-empty guess. - Detection is based on the homepage. Technologies that only load on checkout, login or deep pages may be missed. Pass those specific URLs directly if you need them.
- Client-side-only technologies may be under-reported, since no JavaScript is executed. This keeps the scanner fast and cheap; for full rendering you would need a browser-based tool.
- No personal data. This Actor reads only public technical metadata — HTTP headers, markup and asset URLs. It does not collect emails, names, contact details or any personal data, and is not intended for building contact lists.
Common uses
- Agency prospecting — find every prospect still on an outdated CMS.
- Competitive research — see which analytics, payment and CMP vendors a market uses.
- Lead qualification — filter a domain list down to Shopify or WooCommerce stores.
- Migration and due diligence — inventory a portfolio of sites before a replatform.
- Compliance review — check which consent platform and security headers a site uses.
FAQ
Can I scan thousands of domains?
Yes. Pass them all in startUrls and raise maxConcurrency. Cost scales linearly with
successfully analysed domains only.
Why does a site show fewer technologies than I expect?
Either it is behind bot protection (check status and blockReason), or the technology
only appears on pages other than the homepage, or it is injected by JavaScript at runtime.
Is the version number always present? No. Most sites deliberately hide version numbers. We report a version only when the site discloses it, and never guess.