# Tech Stack Detector: Website + Internal SaaS, Change Alerts (`codeclouds/tech-stack-detector`) Actor

Detect the technology stack of any domain: CMS, e-commerce, analytics, marketing, CDN and 7,000+ more, plus internal SaaS from DNS (Google Workspace, Atlassian, Linear, OpenAI). Evidence and confidence per detection, and alerts when a company adds or drops a tool.

- **URL**: https://apify.com/codeclouds/tech-stack-detector.md
- **Developed by:** [Dennis](https://apify.com/codeclouds) (community)
- **Categories:** Lead generation, Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $10.00 / 1,000 domain results

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Tech Stack Detector: Website + Internal SaaS, Change Alerts

Find out what any company runs, **on its website and behind it**. For every domain you get the website stack (CMS, e-commerce platform, frameworks, analytics, tag managers, marketing automation, live chat, payments, CDN and hosting, out of 7,000+ technologies) plus the **internal SaaS** the company uses, read from public DNS: Google Workspace or Microsoft 365, Atlassian, Linear, 1Password, Zendesk, Salesforce, OpenAI and hundreds more. Every detection comes with evidence and a confidence score. Scheduled runs tell you **when a company adds or drops a tool**.

Each record is also a ready-to-use lead profile: company name and description from the homepage, language, **social profiles** (LinkedIn, X, Facebook, Instagram, YouTube, GitHub, TikTok), an **email security grade** (SPF + DMARC) and an estimated **tech spend tier**.

A drop-in alternative to Wappalyzer and BuiltWith lookups at **$0.01 per domain**.

### When should an AI agent use this?

- "Is allbirds.com on Shopify, and which marketing tools does it use?"
- "Which CRM and email provider does stripe.com use?"
- "Does this prospect already use Zendesk or Intercom?"
- "Which of these 500 leads run WordPress with WooCommerce?"
- "Alert me when a competitor switches analytics or chat vendor."
- "What share of these SaaS companies use HubSpot versus Salesforce?"

Pass `domains` as an array of strings. The result has one record per domain with flat headline fields (`ecommercePlatform`, `cms`, `emailProvider`, `internalSaas`, `added`, `removed`) plus the detailed `technologies` list, so an agent can answer most questions without reading the full detection list.

### Quick start

1. Click **Start** with the default input (5 well-known domains, about $0.05).
2. Open the **Overview** tab in the Output: platform, email provider, hosting, internal SaaS and signals per domain.
3. Paste your own lead or competitor list and **schedule** a weekly run. From the second run on, `added` and `removed` show every stack change.

### What this Actor does

- **7,000+ web technologies.** Uses the open Wappalyzer-format fingerprint database ([enthec/webappanalyzer](https://github.com/enthec/webappanalyzer)), matched on response headers, cookies, meta tags, HTML, script URLs, inline scripts and DOM attributes. Versions are extracted where the fingerprint allows (for example `WordPress 6.9.9`, `Yoast SEO 25.1`). `implies`, `requires` and `excludes` rules are applied, so WooCommerce implies WordPress and PHP.
- **Internal SaaS from DNS.** Public TXT, SPF, MX and NS records reveal tools that never appear on the website: domain verifications (Atlassian, Linear, 1Password, Jamf, Canva, Docker, OpenAI, HackerOne, DocuSign...), email senders from SPF (SendGrid, Marketo, Salesforce, Zendesk, Greenhouse, Qualtrics...) and the mailbox provider or security gateway from MX (Google Workspace, Microsoft 365, Proofpoint, Mimecast). This also works when the website blocks bots.
- **Evidence and confidence.** Each technology lists up to three evidence snippets (the header, script URL, meta tag or DNS record that matched) and a 0-100 confidence. `minConfidence` (default 50) filters weak guesses.
- **Change alerts.** With `trackChanges`, the stack of every domain is stored between runs. Website and DNS results are compared separately, so a temporarily blocked website never shows up as "removed everything". `onlyChanges` returns only domains whose stack changed.
- **Lead enrichment fields.** `siteTitle`, `siteDescription` and `language` from the homepage; `socialProfiles` with the company pages linked from the site (personal LinkedIn profiles are ignored); `technologyList` as one comma-separated text column for CSV and Excel exports.
- **Email security grade.** `emailSecurity` reports the SPF policy (`-all`, `~all`, ...) and the DMARC policy (`reject`, `quarantine`, `none`) with a simple grade from A (enforced DMARC and strict SPF) to F (neither). Useful for MSPs, security vendors and deliverability consultants.
- **Tech spend tier.** Based on the pricing level of the paid tools detected (from the fingerprint database), each domain gets `paidTools` and a `techSpendTier` of low, medium or high. This is a lead-scoring heuristic, not a budget figure.
- **Adoption summary.** The key-value store record `TECH_ADOPTION` counts how many of your input domains use each technology, ready for market-share analysis.
- **Fast and light.** One homepage request plus a few DNS-over-HTTPS queries per domain. No browser, no proxies. Roughly 1-2 seconds per domain, processed 8 at a time.
- **Fair billing.** Domains that are invalid, unreachable or where nothing is detected are free.

### Input

| Field | Type | Description |
|---|---|---|
| `domains` | array of strings | Domains or URLs to analyze. Required. |
| `includeDns` | boolean | Detect email provider, email senders and internal SaaS from DNS (default `true`). |
| `trackChanges` | boolean | Store the stack per domain and report `added`/`removed` on the next run (default `true`). |
| `onlyChanges` | boolean | Only return domains whose stack changed since the previous run. |
| `categories` | array | Only report technologies in matching categories, e.g. `Ecommerce`, `Analytics`, `CRM`, `Live chat`. |
| `minConfidence` | integer | Minimum confidence 0-100 (default 50). |
| `includeEvidence` | boolean | Add evidence snippets per technology (default `true`). |
| `respectRobotsTxt` | boolean | Skip the homepage when robots.txt disallows all bots; DNS still runs (default `true`). |

### Output

One dataset item per domain (shortened):

```json
{
  "domain": "stripe.com",
  "status": "ok",
  "siteTitle": "Stripe",
  "siteDescription": "Stripe is a financial infrastructure platform for businesses...",
  "language": "en-us",
  "socialProfiles": { "linkedin": "https://www.linkedin.com/company/stripe", "x": "https://x.com/stripe", "youtube": "https://www.youtube.com/@stripe" },
  "emailSecurity": { "spf": true, "spfPolicy": "softfail", "dmarc": true, "dmarcPolicy": "reject", "grade": "A" },
  "paidTools": 4,
  "techSpendTier": "medium",
  "technologyCount": 25,
  "ecommercePlatform": null,
  "cms": null,
  "emailProvider": "Google Workspace",
  "emailSenders": ["Greenhouse", "Qualtrics", "Stripe"],
  "hosting": ["Amazon Web Services", "Amazon S3", "Nginx"],
  "internalSaas": ["Atlassian Cloud", "Canva", "Cursor", "Docker", "DocuSign", "Greenhouse", "HackerOne", "Linear", "OpenAI", "Postman", "Salesforce"],
  "technologies": [
    {
      "name": "Atlassian Cloud",
      "categories": ["Issue trackers"],
      "version": null,
      "confidence": 100,
      "sources": ["dns"],
      "evidence": ["dns TXT: atlassian-domain-verification="],
      "website": "https://www.atlassian.com",
      "saas": true
    }
  ],
  "byCategory": { "CRM": ["Salesforce", "Linear"], "Webmail": ["Google Workspace"] },
  "added": ["OpenAI"],
  "removed": [],
  "previousRunAt": "2026-09-22T08:00:00.000Z",
  "signals": [
    "Email hosted on Google Workspace; sends via Greenhouse, Qualtrics, Stripe.",
    "Internal SaaS seen in DNS: Atlassian Cloud, Canva, Cursor, Docker, DocuSign, Greenhouse, HackerOne, Linear +3 more.",
    "Added since 2026-09-22: OpenAI."
  ]
}
```

`status` is `ok`, `partial` (robots.txt disallowed the homepage, DNS only), `blocked` (the website refuses automated requests, DNS only), `unreachable` or `invalid`.

### Use cases

- **Sales and lead qualification (technographics):** find prospects that use a competitor's product, a complementary tool, or a platform you integrate with, and personalize outreach by stack.
- **Agencies:** audit a prospect's marketing and analytics setup before the first call; check which clients run outdated CMS versions.
- **Competitive intelligence:** get an alert when a competitor adds a chat widget, switches payment provider or moves to a new e-commerce platform.
- **Market research:** measure adoption of technologies across a list of companies with `TECH_ADOPTION`.
- **Security and IT vendors, MSPs:** identify the email gateway (Proofpoint, Mimecast), weak email security (no DMARC enforcement) and the SaaS footprint of target accounts.
- **Lead list enrichment:** turn a bare list of domains into company name, description, language, social profiles, tech stack and a spend tier in one run.
- **Data enrichment for AI agents:** one call answers "what does this company use?" with evidence.

### Pricing

Pay per event, no subscription:

- **domain-result:** $0.01 per domain with at least one detected technology
- **tech-change:** $0.02 per domain whose stack changed since the previous run (scheduled monitoring)
- Invalid, unreachable and empty results are free.

Examples: enriching 1,000 leads costs about $10. Monitoring 200 competitors weekly costs $2 per run plus $0.02 for each domain that actually changed. Set a maximum charge per run in the Apify Console to cap spending; the Actor stops cleanly at the limit.

### Legal

The Actor requests only the public homepage of each domain, like a regular browser visit, identifies itself with its own user agent, respects robots.txt by default and does not bypass bot protection (blocked websites are reported as `blocked`). DNS records are public by design. No personal data is collected: results describe the technology used by organizations.

The fingerprint data comes from [enthec/webappanalyzer](https://github.com/enthec/webappanalyzer) (GPL-3.0). It is downloaded at run time from a pinned commit and is not bundled with this Actor. The Actor's own code and DNS vendor tables are separate work. Wappalyzer and BuiltWith are trademarks of their respective owners; this Actor is not affiliated with them.

### FAQ

**Q: How accurate is it?**
A: Detections are only as good as the public signals. Server-rendered platforms (Shopify, WordPress, Webflow, HubSpot CMS, Next.js) and DNS-based SaaS are detected very reliably. Marketing pixels that are loaded later through Google Tag Manager are not in the initial HTML, so they can be missed. Every detection includes its evidence so you can verify it.

**Q: Why does the internal SaaS list show tools that are not on the website?**
A: Companies add verification records to their DNS when they connect a SaaS tool to their domain (for single sign-on, email sending or domain ownership). Those records are public and are a strong sign that the company uses the tool.

**Q: Why is `added` null?**
A: The first run for a domain creates the baseline. Schedule the Actor with `trackChanges` enabled to get changes from the second run on.

**Q: The website blocks bots. Do I still get results?**
A: Yes, the DNS part still runs, and you only pay when something was detected. The web stack is kept from the last successful run for change tracking.

**Q: Can I find all websites that use a specific technology?**
A: Not in this version: that needs a crawl index of millions of sites. Pass your own list of domains instead.

### Related Actors

- **[Google Ads Transparency Monitor](https://apify.com/CodeClouds/google-ads-transparency-monitor)**: see which ads a company runs next to the tools it uses.
- **[French Company Register Lookup (SIRENE)](https://apify.com/codeclouds/fr-sirene-company-register-lookup)**: add official registry data for French companies in your lead list.

### Keywords

tech stack detector, technology lookup, Wappalyzer alternative, BuiltWith alternative, technographics, website technology checker, CMS detector, Shopify detector, WordPress detector, what does this website use, DNS TXT verification, SPF email senders, email provider lookup, Google Workspace or Microsoft 365, DMARC checker, SPF checker, email security grade, company social profiles, tech spend, SaaS stack, lead enrichment, sales intelligence, competitor monitoring, technology change alerts, market share, MCP tool

### Changelog

#### 0.1.0

- First release: 7,000+ web technology fingerprints, internal SaaS from DNS (TXT verifications, SPF senders, MX provider), evidence and confidence per detection, separate web/DNS change tracking, category filter and technology adoption summary; lead fields (site title, description, language, social profiles, technology list), SPF/DMARC email security grade and tech spend tier.

# Actor input Schema

## `domains` (type: `array`):

One domain or URL per line, e.g. stripe.com or https://www.notion.com. Duplicates are removed; the homepage of each domain is analyzed.

## `includeDns` (type: `boolean`):

Reads public DNS records (MX, TXT, SPF, NS) to find the email provider, email-sending services and SaaS tools the company verified its domain with (e.g. Atlassian, Linear, 1Password, OpenAI). Works even when the website blocks bots.

## `trackChanges` (type: `boolean`):

Stores the detected stack per domain so the next run reports added and removed technologies. The first run creates the baseline; most useful on a schedule.

## `onlyChanges` (type: `boolean`):

Skip domains whose stack is unchanged since the previous run (the first run still returns everything as the baseline). Ideal for weekly tech-change alerts.

## `categories` (type: `array`):

Optional: only report technologies whose category contains one of these words, e.g. Ecommerce, Analytics, CRM, Marketing automation, CMS, Live chat, Payment processors.

## `minConfidence` (type: `integer`):

Only report detections with at least this confidence (0-100). 50 filters out weak single-signal guesses.

## `includeEvidence` (type: `boolean`):

Adds up to three evidence snippets per technology (the header, script URL, meta tag or DNS record that matched).

## `respectRobotsTxt` (type: `boolean`):

Skip the homepage request when robots.txt disallows it for all bots; DNS detection still runs.

## Actor input object example

```json
{
  "domains": [
    "stripe.com",
    "notion.com",
    "allbirds.com",
    "hubspot.com",
    "gymshark.com"
  ],
  "includeDns": true,
  "trackChanges": true,
  "onlyChanges": false,
  "categories": [],
  "minConfidence": 50,
  "includeEvidence": true,
  "respectRobotsTxt": true
}
```

# Actor output Schema

## `results` (type: `string`):

One dataset item per domain.

## `techAdoption` (type: `string`):

Top 200 technologies across the input list with domain count and share.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "stripe.com",
        "notion.com",
        "allbirds.com",
        "hubspot.com",
        "gymshark.com"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("codeclouds/tech-stack-detector").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domains": [
        "stripe.com",
        "notion.com",
        "allbirds.com",
        "hubspot.com",
        "gymshark.com",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("codeclouds/tech-stack-detector").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "stripe.com",
    "notion.com",
    "allbirds.com",
    "hubspot.com",
    "gymshark.com"
  ]
}' |
apify call codeclouds/tech-stack-detector --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,codeclouds/tech-stack-detector"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/CmyMtJcTVFWHFhgJa/builds/PMJ5F1cd1DjMX42PQ/openapi.json
