Tech Stack Detector API: Wappalyzer & BuiltWith Alternative
Pricing
from $2.80 / 1,000 domain analyzeds
Tech Stack Detector API: Wappalyzer & BuiltWith Alternative
Detect the tech stack of any list of domains — CMS, e-commerce platform, analytics, CDN, frameworks, hosting — with versions and confidence. Watch mode reports technologies added or removed since the last run.
Pricing
from $2.80 / 1,000 domain analyzeds
Rating
0.0
(0)
Developer
Kittiwake Data
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
5 days ago
Last modified
Categories
Share
See what any website is built with. A tech stack detector for a whole list of domains: CMS, e-commerce platform, analytics, tag managers, CDN, web server, frameworks, hosting and email provider, with versions where the site exposes them and a confidence score for each. A pay-per-domain Wappalyzer alternative and BuiltWith alternative with no subscription, and a watch mode that tells you when a site adds or drops a technology — "competitor moved from Shopify to BigCommerce".
Paste the domains, run once for a snapshot, or schedule it weekly in watch mode and receive only the changes.
What it is for
- Sales and lead qualification — filter a prospect list by stack: every Shopify store, every site still on an old WordPress, every company using HubSpot or Salesforce.
- Agencies — audit a client's or a prospect's stack before the first call.
- Competitive intelligence — watch competitors and get a row when they switch platform, add a new analytics tool or change CDN.
- Market research — count technology share across a list of domains.
Quick start
One-off scan of a list:
{"domains": ["shopify.com", "wordpress.org", "stripe.com"]}
Weekly watch — only baselines and changes:
{"domains": ["competitor-one.com", "competitor-two.com"],"mode": "watch","stateStoreName": "competitor-watch"}
The first run of a domain records a baseline. From then on, watch mode writes a row only when a technology is added, removed or changes version, or when the domain could not be read.
Input
| field | type | default | what it does |
|---|---|---|---|
domains | string[] | required | Domains or URLs. Only the host is used. Duplicates are read once; IP addresses and single-label names are skipped and listed in RUN_SUMMARY |
mode | scan | watch | scan | scan: a row for every domain. watch: rows only for baselines, changes and failures |
includeDns | boolean | true | Also read MX, NS, TXT and SOA records to detect email, DNS and verification services. Matched only, never output |
stateStoreName | string | tech-stack-detector-state | Named key-value store that keeps each domain's last stack. Use one name per list |
requestDelayMs | integer | 500 | Pause before each domain after the first |
maxDomains | integer | 1000 | Domains past this are not read and not charged |
Output
One row per domain:
{"domain": "wordpress.org","finalUrl": "https://wordpress.org/","httpStatus": 200,"status": "ok","technologies": [{ "name": "Nginx", "categories": ["Web servers", "Reverse proxies"], "version": null, "confidence": 100 },{ "name": "PHP", "categories": ["Programming languages"], "version": null, "confidence": 100 },{ "name": "WordPress", "categories": ["CMS", "Blogs"], "version": "7.2", "confidence": 100 }],"technologyNames": ["Nginx", "PHP", "WordPress"],"categories": { "Blogs": ["WordPress"], "CMS": ["WordPress"], "Programming languages": ["PHP"], "Reverse proxies": ["Nginx"], "Web servers": ["Nginx"] },"changeType": ["added", "removed"],"added": ["WordPress"],"removed": ["Drupal"],"versionChanges": [],"checkedAt": "2026-09-26T07:20:41.134Z","source": "https://wordpress.org/"}
statusisok,fetch-failed(no answer, a timeout, or HTTP 400 and above) orrobots-disallowed(the site's robots.txt closes its homepage to this Actor). Failed rows carry no technologies and are not charged.changeTypeisbaselineon a domain's first run, then any ofadded,removed,version-changed, or empty when nothing changed.confidenceis 0–100. Some fingerprints are hints rather than proof, and say so with a lower confidence; filter on it if you only want certain matches.- A run summary — domains analysed, failures, robots refusals, changes, the fingerprint snapshot
used — is saved as
RUN_SUMMARYin the run's key-value store.
What you pay for
| event | price | when |
|---|---|---|
| Domain analyzed | $0.004 | a domain's homepage read, matched and its state saved — only when all of it succeeds |
| Tech change detected | $0.02 | a technology was added or removed since the domain's last successful run. Once per domain per run, however many changed. Never on the first run, not for a version change alone |
1,000 domains cost about $4. Apify Store discounts apply by subscription plan: the prices above are Free-plan prices, and Bronze, Silver and Gold plans pay less on every event.
Nothing is charged for a domain whose robots.txt closes it, a failed request, an error page or an invalid domain. The run stops at the spending limit you set; rows already saved are yours.
How it works, and what it does not do
- One request per domain, plus robots.txt. It reads
robots.txtfirst and stops if/is disallowed for it (or for*), then makes ONE GET of the homepage, following redirects, with a 15-second timeout and an identifying User-Agent:kittiwake-tech-stack-detector/0.1 (+https://apify.com/kittiwake/tech-stack-detector). No crawling past the homepage, no proxies, no header rotation, no retries. - It matches what the server sends: response headers, cookie names, meta tags, script URLs, the page's HTML, the final URL and, optionally, DNS records.
- It does not run JavaScript. Technologies that only show up after scripts run in a browser (and are not referenced in the HTML) are not detected. That is the trade for speed and a low price per domain.
- No page text, no emails, no personal data in the output: technology names, categories, versions and confidence only. Cookie values are never read.
- A redirect to another host is followed, but that host's robots.txt is not fetched separately.
Fingerprints and licence
Detection uses the open fingerprint set enthec/webappanalyzer — a community-maintained continuation of the Wappalyzer fingerprints — vendored as a pinned, unmodified snapshot and refreshed from upstream. That data is licensed GPL-3.0; credit for it belongs to its contributors. This Actor is not affiliated with Wappalyzer, BuiltWith or enthec.
FAQ
Is this a Wappalyzer alternative? It uses the same open fingerprint format, maintained as enthec/webappanalyzer, without a browser extension or a subscription: you pay per domain.
How is it different from BuiltWith? BuiltWith sells subscriptions and historical lookups from its own crawl. This Actor reads the site live when you run it, and watch mode builds your own change history from then on.
Why is a technology I know the site uses missing? It is probably loaded by JavaScript after the page renders, or only on pages other than the homepage. This Actor reads the homepage HTML and headers only.
Why did a domain come back robots-disallowed? Its robots.txt disallows / for all robots or
for this one. The Actor respects that, writes the row so you know, and charges nothing.
Can I export to CSV or Excel? Yes. The dataset downloads as JSON, CSV, Excel or XML, or you can read it over the Apify API. The Technologies with versions view gives one line per technology.
Support
Use the Issues tab on this Actor. Include the run id and the input you used.