# Tech Stack Detector: Wappalyzer & BuiltWith Alternative (`deriverge/tech-stack-detector`) Actor

Detect what any website is built with, in bulk: CMS, ecommerce, analytics, ads, tag managers, frameworks, servers, CDN and hosting, plus email and SaaS tools from DNS. 7,600 fingerprints with version and evidence, change alerts. JSON, CSV, Excel, API.

- **URL**: https://apify.com/deriverge/tech-stack-detector.md
- **Developed by:** [deriverge s.r.o.](https://apify.com/deriverge) (community)
- **Categories:** Developer tools, SEO tools, Lead generation
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $0.50 / 1,000 website analyzeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## Tech Stack Detector

Find out **what any website is built with**, for one site or thousands: CMS, ecommerce platform, analytics and ad pixels, tag managers, JavaScript frameworks, web servers, CDN and hosting, cookie consent and payments, plus the **email provider and business tools** the company uses, read from public DNS records. It recognizes 7,628 technologies with the open Wappalyzer fingerprints, shows the **version**, a **confidence** score and the **evidence** behind every finding, and can alert you when a website adds or drops a tool.

You pay only for websites that answered, from $0.50 per 1,000, with no start fee. The $5 of monthly credit in Apify's Free plan covers about 5,000 websites, so you can try it for free.

### Why use Tech Stack Detector?

- **7,600 fingerprints, not 50.** The community-maintained Wappalyzer fingerprint set (github.com/enthec/webappanalyzer), refreshed with every release: CMS to cookie banners, Shopify apps and WordPress plugins included.
- **Sees the tags inside Google Tag Manager.** Pixels loaded through a tag manager (Meta Pixel, Google Analytics 4, Google Ads, Microsoft Advertising, TikTok, Hotjar) are not in the page HTML. The actor reads the site's Tag Manager container and reports them, which a plain HTML check misses.
- **Email and SaaS tools from DNS.** Mailbox provider from MX (Google Workspace, Microsoft 365), sending services from SPF (SendGrid, Mailgun, Amazon SES) and business tools from domain verification records (Atlassian, Zoom, DocuSign, Salesforce, OpenAI and many more).
- **Evidence you can check.** Each technology lists what matched: a header, a script URL, a meta tag, a cookie, a DNS record. No black box.
- **Spreadsheet-ready columns.** CMS, ecommerce, analytics, advertising, frameworks, CDN, hosting and email each get their own column, next to the full list.
- **Change alerts.** Schedule the same list with a watch name and every row shows the technologies added or removed since the last run.
- **Pay only for answers.** Unreachable websites, error pages and bot protection pages are returned with the reason and are never charged.

### What data does Tech Stack Detector return?

| Field | What it contains |
|---|---|
| `url` | Final URL after redirects |
| `status` | `ok`, `blocked`, `http_error`, `unreachable` or `invalid_input` |
| `title` | Page title |
| `technologyNames` | Every technology found |
| `cms` | CMS, blog or page builder |
| `ecommerce` | Ecommerce platform |
| `analytics` | Analytics and pixels |
| `tagManagers` | Tag managers |
| `advertising` | Ad networks and retargeting |
| `marketingAutomation` | Marketing automation and email marketing |
| `crm` | CRM |
| `liveChat` | Live chat |
| `payments` | Payment providers |
| `jsFrameworks` | JavaScript frameworks |
| `webFrameworks` | Server frameworks |
| `webServers` | Web servers |
| `cdn` | CDN |
| `hosting` | Hosting, cloud and DNS host |
| `cookieConsent` | Cookie consent tools |
| `reviews` | Review widgets |
| `shopifyApps` | Shopify apps on Shopify stores |
| `emailServices` | Mailbox provider and sending services |
| `verifiedServices` | Business tools verified in DNS |
| `technologies` | Each technology with `categories`, `version`, `confidence`, `foundIn`, `saas`, `pricing` and `evidence` |
| `sslIssuer` | Certificate issuer |
| `sslValidUntil` | Certificate expiry |
| `newTechnologies` | Added since the last run (watch mode) |
| `removedTechnologies` | Removed since the last run (watch mode) |

### Who uses Tech Stack Detector?

- **Sales and lead generation teams:** qualify a list of prospects by the tools they run, for example Shopify stores without a reviews app, or companies on HubSpot.
- **Agencies and freelancers:** audit a client or a pitch target in seconds: CMS, tracking setup, consent banner, hosting and email.
- **SaaS companies and competitive intelligence:** see who uses your product or a competitor's, and get told when an account switches.
- **Security and IT teams:** find outdated software versions and expiring certificates across many domains.
- **Market researchers and investors:** measure technology adoption across a market or a portfolio.
- **AI agents:** call it through the Apify API or MCP to enrich a company with its technology stack.

### How much does it cost to detect website technology stacks?

You pay per result. There is no start fee and no charge for compute time or proxies.

| | Free plan | Starter | Scale | Business |
|---|---|---|---|---|
| 1,000 websites | $1.00 | $0.80 | $0.65 | $0.50 |

For example, a list of 1,000 websites costs $1.00 on the Free plan and $0.50 on the Business plan. The $5 of monthly credit in Apify's Free plan covers about 5,000 websites.

Websites that are unreachable, answer with an error page or with a bot protection page are returned with the reason and never charged. Extra pages per website, DNS records and Tag Manager containers are included in the price.

### How to detect website technology stacks

1. Click **Try for free** (or **Start** if you are signed in) to open the actor in Apify Console.
2. In **Websites**, paste domains or URLs, one per line.
3. Optionally raise **Pages per website** to also check shop, pricing and blog pages.
4. Give the run a **Watch name** and schedule it if you want to be told about changes.
5. Click **Start**. Rows appear in the **Output** tab within seconds.
6. Download the results as JSON, CSV, Excel or HTML, or read them through the API.

### Input example

```json
{
  "websites": [
    "allbirds.com",
    "https://www.example.com/shop",
    "hubspot.com"
  ],
  "maxPagesPerSite": 3,
  "scanDns": true,
  "watchName": "prospects"
}
```

### Output example

A real row from a run in September 2026 (the technologies list is shortened to six of its entries). In the **Output** tab the **Overview** view shows the same data as a table.

```json
{
  "input": "allbirds.com",
  "url": "https://www.allbirds.com/",
  "domain": "allbirds.com",
  "status": "ok",
  "httpStatus": 200,
  "title": "Allbirds: Comfortable, Sustainable Shoes & Apparel",
  "description": "Allbirds: The world’s most comfortable shoes, flats, and clothing made with natural materials like merino wool and eucalyptus. FREE shipping & returns.",
  "language": "en-US",
  "generator": null,
  "technologyCount": 25,
  "technologyNames": [
    "Shopify",
    "Microsoft 365",
    "Apple Pay",
    "PayPal",
    "Adalyser",
    "Attentive",
    "Cloudflare",
    "Cursor",
    "Facebook Pixel",
    "Google Ads",
    "Google Ads Conversion Tracking",
    "Google Analytics",
    "Google Tag Manager",
    "HSTS",
    "ipify",
    "Let's Encrypt",
    "Microsoft Advertising",
    "Outbrain",
    "Priority Hints",
    "Swiper",
    "Yotpo Reviews",
    "DocuSign",
    "HTTP/3",
    "Miro",
    "Open Graph"
  ],
  "cms": [],
  "ecommerce": [
    "Shopify"
  ],
  "analytics": [
    "Facebook Pixel",
    "Google Ads Conversion Tracking",
    "Google Analytics"
  ],
  "tagManagers": [
    "Google Tag Manager"
  ],
  "advertising": [
    "Adalyser",
    "Google Ads",
    "Microsoft Advertising",
    "Outbrain"
  ],
  "marketingAutomation": [
    "Attentive"
  ],
  "crm": [],
  "liveChat": [],
  "payments": [
    "Apple Pay",
    "PayPal"
  ],
  "jsFrameworks": [],
  "webFrameworks": [],
  "uiFrameworks": [],
  "programmingLanguages": [],
  "webServers": [],
  "cdn": [
    "Cloudflare"
  ],
  "hosting": [],
  "security": [
    "HSTS"
  ],
  "cookieConsent": [],
  "emailServices": [
    "Microsoft 365"
  ],
  "verifiedServices": [
    "Cursor",
    "DocuSign",
    "Miro"
  ],
  "technologies": [
    {
      "name": "Shopify",
      "categories": [
        "Ecommerce"
      ],
      "version": null,
      "confidence": 100,
      "foundIn": "website",
      "website": "https://shopify.com",
      "saas": true,
      "pricing": [
        "low",
        "recurring"
      ],
      "evidence": [
        "script https://cdn.shopify.com/s/files/1/1104/4168/files/jsEncrypt.js?v=1756910700",
        "script https://cdn.shopify.com/shopifycloud/shop-js/modules/v2/loader.init-shop-cart-sync.en.esm.js"
      ]
    },
    {
      "name": "Microsoft 365",
      "categories": [
        "Webmail",
        "Email"
      ],
      "version": null,
      "confidence": 100,
      "foundIn": "dns",
      "website": "https://www.microsoft.com/microsoft-365",
      "saas": false,
      "pricing": [],
      "evidence": [
        "DNS MX allbirds-com.mail.protection.outlook.com",
        "DNS TXT MS=ms40651830"
      ]
    },
    {
      "name": "Cloudflare",
      "categories": [
        "CDN"
      ],
      "version": null,
      "confidence": 100,
      "foundIn": "website",
      "website": "https://www.cloudflare.com",
      "saas": false,
      "pricing": [],
      "evidence": [
        "header server: cloudflare",
        "header cf-cache-status: DYNAMIC"
      ]
    },
    {
      "name": "Facebook Pixel",
      "categories": [
        "Analytics"
      ],
      "version": null,
      "confidence": 100,
      "foundIn": "website",
      "website": "https://facebook.com",
      "saas": false,
      "pricing": [],
      "evidence": [
        "Google Tag Manager container GTM-TH8KRSBJ loads https://connect.facebook.net/en_US/fbevents.js"
      ]
    },
    {
      "name": "Google Analytics",
      "categories": [
        "Analytics"
      ],
      "version": "GA4",
      "confidence": 100,
      "foundIn": "website",
      "website": "https://google.com/analytics",
      "saas": false,
      "pricing": [],
      "evidence": [
        "Google Tag Manager container GTM-TH8KRSBJ sets up UA-73307718-8",
        "Google Tag Manager container GTM-TH8KRSBJ sets up G-KJL05B1DJZ"
      ]
    },
    {
      "name": "DocuSign",
      "categories": [
        "Miscellaneous"
      ],
      "version": null,
      "confidence": 100,
      "foundIn": "dns",
      "website": "https://www.docusign.com",
      "saas": true,
      "pricing": [
        "low",
        "recurring"
      ],
      "evidence": [
        "DNS TXT docusign=7de1885c-e938-41b0-9a4d-06213413de67"
      ]
    }
  ],
  "sslIssuer": "Let's Encrypt",
  "sslValidUntil": "2026-11-08T22:33:31.000Z",
  "sslValid": true,
  "pagesScanned": 1,
  "pageUrls": [
    "https://www.allbirds.com/"
  ],
  "blockedBy": null,
  "error": null,
  "responseTimeMs": 2808,
  "newTechnologies": null,
  "removedTechnologies": null,
  "checkedAt": "2026-09-27T05:52:54.163Z"
}
```

### Get told when a website changes its stack

Give the run a **Watch name** (`watchName`) or save it as a task, and schedule it weekly. Each row then shows `newTechnologies` and `removedTechnologies` since the previous run, and the **Changes since the last run** record lists every website that changed. A prospect that installs a competitor's tool, drops its analytics or moves to another platform shows up the day it happens. Websites that fail to load in a run keep their previous snapshot, so a temporary outage does not look like a change.

### Tips and limitations

- The actor reads websites the way a server sends them, without running their JavaScript. Tools that a page injects only from its own scripts (not from Google Tag Manager) can be missed; raising **Pages per website** helps.
- Some websites answer automated requests with a bot protection page (Cloudflare, DataDome, AWS WAF). They are returned as `blocked` with what the headers and DNS reveal, free of charge.
- `foundIn` tells whether a technology was seen on the website, only in DNS, or both. DNS-only tools (for example Atlassian or DocuSign) are services the company uses, not parts of its website, so they are listed in `verifiedServices` and not in the website columns.
- `confidence` below 100 means a weaker signal, for example a single generic pattern.
- Summary columns are also available as the full `technologies` list with categories, for filters that the columns do not cover.

### Integrations and API

Connect the actor to **Make**, **Zapier**, **n8n**, **Google Sheets**, **Slack** or any webhook, or call it from your own code. With the Python client:

```python
from apify_client import ApifyClient

client = ApifyClient("<YOUR_API_TOKEN>")
run = client.actor("deriverge/tech-stack-detector").call(run_input={"websites": ["allbirds.com", "hubspot.com"], "maxPagesPerSite": 2})
for w in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(w["url"], w["cms"], w["ecommerce"], w["analytics"])
```

The **API** tab on this page has the same call for Node.js and cURL, and AI agents can run the actor through the Apify MCP server.

### Is it legal to detect the technology stack of a website?

Yes. The actor reads what any visitor's browser receives: public web pages, HTTP headers, the public Tag Manager container and public DNS records, one request at a time per website. It collects no personal data. As with any automated tool, respect the terms of the websites you check and applicable law.

### FAQ

#### How accurate is it?

Findings come from explicit signals (script URLs, headers, cookies, meta tags, DNS records), each listed in `evidence`. Tools that exist only after the page runs its own JavaScript can be missed; nothing is guessed.

#### Can it find all websites that use a technology?

It checks the websites you give it. Combine it with any list of domains, for example from our Domain WHOIS and DNS Lookup or your CRM, and filter the results by the technology you need.

#### Is it a Wappalyzer or BuiltWith API alternative?

Yes. It uses the open Wappalyzer fingerprint format and adds DNS and Tag Manager insight, with no API key, no subscription and a price per website.

#### Do I need proxies or an API key?

No.

#### What does "Services verified in DNS" mean?

Many business tools ask the domain owner to add a TXT record to prove ownership, for example atlassian-domain-verification or docusign. These records are public, so they show which tools the company has set up.

### Related scrapers

- [Domain WHOIS and DNS Lookup](https://apify.com/deriverge/domain-whois-dns-lookup): registry data plus DNS and mail setup
- [WHOIS Domain Lookup](https://apify.com/deriverge/whois-domain-lookup): registrar, age, expiry, status

### Support and feedback

Missing a field or found something that does not work? Open an issue in the **Issues** tab and it will be answered, usually within a day. If the actor saves you time, a short review helps other people find it.

# Actor input Schema

## `websites` (type: `array`):

Domains or URLs, one per line: example.com, www.example.com or https://www.example.com/shop. A domain is checked at its homepage; a URL is checked at that page. Paste thousands at once. Through the API the list is also accepted as urls, url, startUrls or domains.

## `maxPagesPerSite` (type: `integer`):

Also check up to this many pages of each site in total, picked from homepage links (shop, pricing, blog, contact, login). Tools that load only on some pages are found this way. The price per website stays the same.

## `scanDns` (type: `boolean`):

Detect the email provider (MX), email sending services (SPF), the DNS host and business tools the domain is verified with (TXT records of Atlassian, Zoom, DocuSign, OpenAI and many more).

## `watchName` (type: `string`):

Give the run a name such as "competitors" and schedule it. Every later run with the same name fills newTechnologies and removedTechnologies on each row and lists all changes in the CHANGES record. Runs from a saved task are compared automatically.

## Actor input object example

```json
{
  "websites": [
    "apify.com",
    "allbirds.com",
    "wordpress.org"
  ],
  "maxPagesPerSite": 1,
  "scanDns": true
}
```

# Actor output Schema

## `websites` (type: `string`):

One row per website with the detected technologies, summary columns, DNS services and certificate.

## `changes` (type: `string`):

Technologies each website added or removed since the previous run with the same watch name or task.

## `summary` (type: `string`):

Websites analyzed, blocked, unreachable and billed, and the fingerprint version used.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "websites": [
        "apify.com",
        "allbirds.com",
        "wordpress.org"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("deriverge/tech-stack-detector").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "websites": [
        "apify.com",
        "allbirds.com",
        "wordpress.org",
    ] }

# Run the Actor and wait for it to finish
run = client.actor("deriverge/tech-stack-detector").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "websites": [
    "apify.com",
    "allbirds.com",
    "wordpress.org"
  ]
}' |
apify call deriverge/tech-stack-detector --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,deriverge/tech-stack-detector"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/t0kpLNB14bmrFCSnV/builds/sLd7vaeTE0DKIzK1T/openapi.json
