Tech Stack Detector — BuiltWith & Wappalyzer Alternative avatar

Tech Stack Detector — BuiltWith & Wappalyzer Alternative

Pricing

from $2.00 / 1,000 domain analyzeds

Go to Apify Store
Tech Stack Detector — BuiltWith & Wappalyzer Alternative

Tech Stack Detector — BuiltWith & Wappalyzer Alternative

Drop-in for nexgendata/wappalyzer-replacement at 1/50th the price. 275+ technologies: CMS, ecommerce, JS frameworks, analytics, ad pixels, payments, CDN, hosting, chat, reviews, consent. Every detection names the header, cookie or script it matched. One row per domain; no data, no charge.

Pricing

from $2.00 / 1,000 domain analyzeds

Rating

0.0

(0)

Developer

DIOPSIDE AI

DIOPSIDE AI

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

3 days ago

Last modified

Share

Drop-in compatible with nexgendata/wappalyzer-replacement — 50× cheaper, and it actually finds the stack. Same input field names, same output keys, same shapes. Change the actor id and your code keeps working.

Point it at a list of domains and get back the technologies behind each one: CMS, ecommerce platform, JavaScript frameworks, analytics, ad pixels, payment processors, CDN, hosting, live chat, review widgets and consent tools. No API key, no login, no proxy required.

Why this one

We ran the leading incumbent against allbirds.com on 2026-09-21, paid its $0.10, and got four technologies back:

Cloudflare, Content Security Policy, HSTS, HTTP/3

Every one of those is a response header. It did not notice that allbirds.com is a Shopify store — the single most valuable fact about that domain for anyone doing lead qualification, and one that is sitting in plain sight in a _shopify_y cookie and a cdn.shopify.com script tag.

Same domain, same moment, this actor at $0.002:

Shopify, Shop Pay, Cloudflare, Google Tag Manager, Swiper, Tailwind CSS, Subresource Integrity, Content Security Policy, HSTS, HTTP/3, X-Frame-Options

Three things follow from that, and they are the whole pitch:

  1. It reads the page, not just the headers. 275+ fingerprints across 33 categories, matched against response headers, cookies, meta tags, every script/stylesheet/iframe the page loads, the raw HTML, and robots.txt.
  2. Every detection shows its work. Each technology carries the exact signal that produced it — cookie: _shopify_y, header: x-powered-by: Next.js, meta generator: WordPress 6.5, script: https://cdn.shopify.com/.... You can audit a row instead of trusting it. No other actor in this cluster does this.
  3. It costs $0.002 per domain instead of $0.10. A 5,000-domain enrichment run is $10 here and $500 there.

Reliability

  • Every input gets exactly one output row, in your order — including the domains that turn out to be dead. An actor that silently drops unreachable domains turns your join back onto your own list into a guessing game. Failures come back with error filled in and status_code: null.
  • You are not charged for a row that carries no data. DNS failures, timeouts and empty responses ship free. You pay only for domains that answered and produced at least one detection.
  • A real Chrome TLS fingerprint. Measured on a 15-site sample during the build: plain httpx got 14/15, curl_cffi with Chrome impersonation got 15/15. Sites that fingerprint TLS (nytimes.com, for one) answer this actor and refuse a naive HTTP client.
  • Byte-capped reads. Homepages are getting absurd — cloudflare.com is 1.3 MB. Fingerprints live in the head and the first screens of markup, so each page stops downloading at maxBytesPerPage (400 KB by default). That is what keeps the price at $0.002.
  • A bad robots.txt never costs you the page. The robots read is a bonus signal; if it fails, the row still ships.
  • No proxy needed. Verified on the Apify platform with the proxy switched off. Turn proxyConfiguration on only if you are scanning at a scale where a target rate-limits the platform's IP range.

Input

FieldTypeDefaultNotes
urlsarray / string["stripe.com", "allbirds.com", "wordpress.org"]Bare hosts or full URLs. Also accepted as startUrls, domains, websites, targetUrls, url, domain. Comma- or newline-separated strings are split for you.
categories_filterarray[]Only return these categories. Case-, space- and dash-insensitive, so E-Commerce and ecommerce both work.
include_confidencebooleantrueAdd a 0–100 score to each detection.
include_versionsbooleantrueParse version numbers where a reliable signal exists. Never guessed.
timeout_secondsinteger15Per-request timeout, 3–60.
checkRobotsbooleantrueAddition. Also read /robots.txt: confirms themed-over CMS platforms and fills sitemap_urls.
maxConcurrencyinteger8Addition. Domains analysed in parallel, 1–25.
maxBytesPerPageinteger400000Addition. Stop reading a page after this many bytes.
maxItemsinteger—Addition. Hard cap on how many websites to analyse.
proxyConfigurationobject{"useApifyProxy": false}Addition. Off by default.

The first five rows are the incumbent's fields, with the incumbent's names and defaults.

Output

{
"url": "https://allbirds.com",
"status_code": 200,
"tech_count": 11,
"categories": {
"CDN": ["Cloudflare"],
"Ecommerce": ["Shopify"],
"Payment Processors": ["Shop Pay"],
"Security": ["Content Security Policy", "HSTS", "Subresource Integrity", "X-Frame-Options"]
},
"technologies": [
{ "name": "Cloudflare", "category": "CDN", "evidence": "header: cf-ray", "version": null, "confidence": 100, "website": "https://cloudflare.com" },
{ "name": "Shopify", "category": "Ecommerce", "evidence": "cookie: _shopify_y", "version": null, "confidence": 95, "website": "https://shopify.com" },
{ "name": "Shop Pay", "category": "Payment Processors", "evidence": "script: https://shop.app/checkouts/internal/preloads.js", "version": null, "confidence": 90, "website": null }
],
"scan_time_ms": 1212,
"final_url": "https://www.allbirds.com/",
"tech_names": "Cloudflare, Content Security Policy, HSTS, HTTP/3, Shopify, ...",
"category_list": "CDN, Ecommerce, Miscellaneous, Payment Processors, Security",
"tech_names_list": ["Cloudflare", "Content Security Policy", "..."],
"category_names": ["CDN", "Ecommerce", "Miscellaneous", "Payment Processors", "Security"],
"top_technologies": ["Cloudflare", "Shopify", "Shop Pay"],
"redirected": true,
"page_title": "Allbirds: Comfortable, Sustainable Shoes & Apparel",
"page_description": "Shop the world's most comfortable shoes...",
"server": "cloudflare",
"sitemap_urls": ["https://www.allbirds.com/sitemap.xml"],
"html_bytes": 409426,
"error": null,
"scanned_at": "2026-09-21T11:42:07+00:00"
}

Everything above the blank line is the incumbent's key set, byte for byte, including tech_names as a comma-joined string. Everything below it is an addition — tech_names_list is the same data as an array if you would rather not split a string.

Confidence

ScoreSource
100A response header. The server told us.
95A cookie name, or a meta generator tag.
90A script, stylesheet or iframe the page loads.
85A pattern in the raw HTML.
80A line in robots.txt.
60Implied by another technology (WooCommerce ⇒ WordPress ⇒ PHP).

Switching from nexgendata/wappalyzer-replacement

Change the actor id. That is the whole migration:

- const run = await client.actor('nexgendata/wappalyzer-replacement').call({
+ const run = await client.actor('diopside/tech-stack-detector').call({
urls: ['https://allbirds.com', 'https://gymshark.com'],
include_confidence: true,
include_versions: true,
});

urls, categories_filter, include_confidence, include_versions and timeout_seconds mean the same things. url, status_code, tech_count, categories, technologies, scan_time_ms, final_url, tech_names and category_list come back with the same names and the same types. Rows you used to lose for unreachable domains now arrive with error set, so expect one row per input rather than one row per reachable input.

What it detects

33 categories, 275+ technologies:

CMS (WordPress, Drupal, Joomla, Ghost, Craft, Sitecore, AEM, Contentful, Sanity, Storyblok, Wix, Squarespace, Webflow, Duda, Framer, HubSpot CMS) · Ecommerce (Shopify, WooCommerce, Magento, BigCommerce, PrestaShop, Shopware, Salesforce Commerce Cloud, SAP Commerce Cloud, VTEX, Ecwid, Snipcart, Recharge) · JavaScript frameworks (React, Vue, Angular, Svelte, Preact, Alpine, htmx, Stimulus, Turbo, Ember, Lit) · Web frameworks (Next.js, Nuxt, Remix, SvelteKit, Astro, Gatsby, Rails, Django, Laravel, Symfony, Express, Flask, ASP.NET, Spring, Phoenix) · Static site generators (Hugo, Jekyll, Eleventy, Docusaurus, Hexo) · Analytics (GA4, Adobe, Matomo, Plausible, Fathom, Umami, PostHog, Mixpanel, Amplitude, Heap, Hotjar, Clarity, Segment, FullStory, LogRocket, Contentsquare, New Relic, Datadog, Sentry, Pendo) · Tag managers · Advertising pixels (Meta, TikTok, LinkedIn, Pinterest, Reddit, Snap, X, Bing, Criteo, Taboola, Outbrain, AdRoll, Amazon) · Payment processors (Stripe, PayPal, Braintree, Adyen, Klarna, Afterpay, Affirm, Square, Checkout.com, Mollie, Razorpay, Shop Pay, Apple Pay, Google Pay, Amazon Pay) · Marketing automation & CRM (HubSpot, Marketo, Pardot, Salesforce, Klaviyo, Mailchimp, ActiveCampaign, Braze, Customer.io, Omnisend, Attentive, Iterable) · Live chat (Intercom, Drift, Zendesk, Crisp, Tawk.to, LiveChat, Freshchat, Tidio, Gorgias, Olark) · Reviews (Yotpo, Trustpilot, Bazaarvoice, Judge.me, Okendo, Loox, Stamped) · Search (Algolia, Searchspring, Klevu, Coveo) · A/B testing (Optimizely, VWO, AB Tasty, Dynamic Yield, Kameleoon) · Cookie consent (OneTrust, Cookiebot, CookieYes, Usercentrics, Didomi, Osano, TrustArc, Iubenda) · CDN & hosting (Cloudflare, Akamai, Fastly, CloudFront, Vercel, Netlify, Heroku, GitHub Pages, Firebase, Render, Fly.io, WP Engine, Kinsta, Pantheon, Bunny, jsDelivr, Cloudinary, imgix) · Web servers (nginx, Apache, IIS, LiteSpeed, OpenResty, Caddy, Envoy, Varnish) · Security & bot protection (CSP, HSTS, X-Frame-Options, SRI, reCAPTCHA, hCaptcha, Turnstile, Cloudflare Bot Management, DataDome, HUMAN, Imperva, Akamai Bot Manager, Sucuri, Wordfence) · Fonts, UI frameworks, video players, maps, JS libraries and build tools.

Use cases

  • Lead qualification. Filter a prospect list down to the Shopify stores, or the sites running a competitor's checkout. top_technologies is the field to put in a scoring rule.
  • Competitive research. Watch when a set of sites migrates CMS, adds a consent manager, or swaps analytics vendors. scanned_at makes a time series out of repeat runs.
  • Agency prospecting. Find sites still on an old stack, or sites with no consent tool in a GDPR market.
  • Security posture snapshots. CSP, HSTS, X-Frame-Options, SRI and bot-protection vendor across a whole portfolio in one run.
  • Enrichment pipelines. One row per input domain, always, so it drops straight into a join.

Sizes and cost

InputRuntimeCost
5 domains~10 s$0.01
100 domains~40 s$0.20
1,000 domains~6 min$2.00
10,000 domains~55 min$20.00

Pay per event: $0.002 per domain analysed, plus a $0.00005 actor start. Rows with an error are not charged. The same 1,000 domains cost $100 on the incumbent.

Notes

  • Public site fingerprinting only. This actor reads a homepage and /robots.txt — the same two things any browser or search crawler reads. No personal data, no logins, no paywalled content.
  • One request per domain (two with checkRobots). It is not a crawler; it does not walk your targets' sites.
  • version is null unless a version genuinely appears in a header, script URL or generator tag. It is never inferred.