Website Tech Stack Detector
Pricing
from $2.00 / 1,000 results
Website Tech Stack Detector
Detect what technology any website runs: CMS, ecommerce, analytics, pixels, chat, payments, JS frameworks, hosting/CDN, ATS, email provider (DNS). Evidence + confidence per detection. HTTP-only, fast, pay per domain. BuiltWith alternative.
Pricing
from $2.00 / 1,000 results
Rating
0.0
(0)
Developer
Kurt Blair
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
3 days ago
Last modified
Categories
Share
Website Tech Stack Detector — What CMS, Analytics & Tools Any Site Uses
Find out what technology any company website runs — without BuiltWith's $295/month or Wappalyzer's paywall. Feed the Actor a list of domains and get one clean JSON row per company: CMS, ecommerce platform, analytics, tag managers, ad & marketing pixels, chat widgets, payment providers, JavaScript frameworks, hosting/CDN, applicant tracking system (ATS), and even the company's email provider from DNS — each with the exact evidence that triggered it and a confidence score.
HTTP-only and browser-free: 1–3 gentle GET requests per site plus two DNS lookups. Results stream in seconds and cost a fraction of headless-browser checkers.
What it detects (210+ signatures, 160+ technologies)
| Category | Examples |
|---|---|
| CMS | WordPress, Drupal, Joomla, Ghost, Squarespace, Wix, Webflow, HubSpot CMS, Craft, TYPO3, AEM, Sitecore, Contentful, Sanity |
| Ecommerce | Shopify, WooCommerce, Magento, BigCommerce, PrestaShop, Salesforce Commerce Cloud, Ecwid, Snipcart |
| Analytics | Google Analytics, Segment, Mixpanel, Amplitude, Hotjar, Plausible, Fathom, Matomo, Heap, FullStory, Clarity, PostHog |
| Tag managers | Google Tag Manager, Tealium, Adobe Launch |
| Ads / pixels | Meta Pixel, Google Ads, LinkedIn Insight, TikTok, X, Pinterest, Reddit, Bing, Criteo, Taboola, Outbrain |
| Marketing automation | HubSpot, Marketo, Pardot, Klaviyo, Mailchimp, Braze, Customer.io, ActiveCampaign |
| Chat / support | Intercom, Drift, Zendesk, LiveChat, Crisp, Tawk.to, Freshchat, Olark, Gorgias |
| Payments | Stripe, PayPal, Braintree, Square, Adyen, Klarna, Affirm, Afterpay, Shop Pay |
| JS frameworks | Next.js, Nuxt, Gatsby, Remix, SvelteKit, Astro, Angular, React, Vue, Ember, jQuery, htmx |
| Hosting / CDN | Cloudflare, Netlify, Vercel, Fastly, Akamai, CloudFront, S3, GitHub Pages, WP Engine, Kinsta, Pantheon, Heroku, Fly.io, Azure |
| Backend signals | Nginx, Apache, IIS, PHP, Laravel, Django, Rails, ASP.NET, Express |
| ATS (hiring) | Greenhouse, Lever, Ashby, Workday, BambooHR, SmartRecruiters, Workable, Recruitee, iCIMS |
| Email provider (DNS) | Google Workspace, Microsoft 365, Zoho, Proton, Fastmail, Mimecast, Proofpoint |
| Transactional email (DNS SPF) | SendGrid, Mailgun, Amazon SES, Postmark, Mandrill |
| Plus | A/B testing (Optimizely, VWO), consent (OneTrust, Cookiebot), monitoring (Sentry, Datadog, New Relic), CAPTCHA, embeds |
Every signature is high-precision by design: vendor-controlled hostnames, response headers, cookie names, and unambiguous markup markers — never fuzzy keywords. When you see "Shopify" in your dataset, the site set a x-shopify-stage header, loads cdn.shopify.com, or declares window.Shopify. Precision over recall, so your enrichment data stays trustworthy.
What can you do with technographics?
- Sales signals / ABM tech-qualification: sell a Shopify app? Filter 10,000 target domains down to actual Shopify stores before your SDRs touch them. Sell against Intercom? Find every account already paying for chat. Route accounts by CMS, pixel spend, or payment stack — straight into Clay, HubSpot, or your CRM.
- Competitor & churn analysis: track which analytics, A/B testing, and marketing tools your competitors' customers deploy — and when they switch.
- Market research: measure real-world market share of CMSs, checkout providers, or consent tools across any segment you define.
- Agency prospecting: find WordPress sites without a consent banner, stores still on Magento 1-era stacks, or sites with no analytics at all.
- Hiring intel bonus: the ATS detection (Greenhouse/Lever/Ashby links on careers pages) pairs directly with a job-postings scraper for a full company signal stack.
Input
{"domains": ["shopify.com", "hubspot.com", "vercel.com"],"checkCommonPaths": true,"dnsChecks": true,"maxTotalResults": 1000}
Bare domains or full URLs both work; www. and duplicates are merged so each domain is fetched and billed once. Options: follow careers/jobs pages for ATS detection (on by default, max 2 extra requests), DNS email-provider checks, evidence strings on/off, minimum confidence threshold, total result cap, concurrency, proxy.
Output (one item per domain)
{"domain": "allbirds.com","finalUrl": "https://www.allbirds.com/","httpStatus": 200,"techCount": 9,"ecommercePlatform": "Shopify","technologies": [{"name": "Shopify","category": "ecommerce","confidence": 100,"evidence": ["homepage:scriptSrc:https://cdn.shopify.com/s/files/1/1104/4168/t/303/assets/vendor.min.js","homepage:header:x-shopify-stage","homepage:cookie:_shopify_y"]},{"name": "Google Workspace","category": "email-provider","confidence": 100,"evidence": ["dns:mx:aspmx.l.google.com"]}],"categories": {"ecommerce": ["Shopify"],"email-provider": ["Google Workspace"]},"detectedAt": "2026-07-23T00:00:00.000Z"}
Flat cms / ecommercePlatform columns plus a categories map make the dataset spreadsheet- and Clay-ready without post-processing; the full technologies array carries evidence for auditability.
Pricing & typical cost
Pay per result — you only pay for reachable domains. Sites that time out or refuse to answer are logged to the ERRORS record and are not billed. Use maxTotalResults as a hard cost cap. A 10,000-domain enrichment run makes at most ~30,000 lightweight HTTP requests, no browser, no CAPTCHA solving — compare that with $295+/month for BuiltWith or per-lookup credit plans.
Is this legal / compliant?
Yes, by design:
- Company-level data only. The Actor reports what technologies a website uses. It collects no personal data, no emails, no names, no profiles — nothing in scope for GDPR/CCPA personal-data rules.
- Public information. Every signal comes from what any browser receives when loading the public homepage (HTML, headers, cookies set on an anonymous request) and from public DNS records — the same data BuiltWith, Wappalyzer, and W3Techs have published for years.
- Polite by construction. Hard-capped at the homepage plus at most two same-site careers/jobs pages per domain, gentle concurrency, retries with backoff, and it respects each page's robots meta tag (
noindex/nofollowstops link-following). No login walls, no paywalls, no circumvention.
As always, you are responsible for how you use the output in your jurisdiction.
FAQ
How accurate is it? Signatures are curated for precision: a match means the vendor's own hostname, header, or cookie was present. Corroborating evidence (e.g. header + cookie + script) pushes confidence to 100. Filter with minConfidence if you only want multi-evidence detections.
Why did a site return few/no technologies? Some sites render everything client-side through a bundler, hiding third-party hostnames from static HTML (a v2 browser mode is on the roadmap); some genuinely run minimal stacks. Header/cookie/DNS signals still work on every reachable site.
Does it work behind Cloudflare? Yes — Cloudflare fronting is itself detected. If a site's bot protection blocks datacenter IPs, the row reports the HTTP status and header-level detections; enable residential proxy for stubborn lists.
How fresh is the data? Every run fetches live. Schedule the Actor (daily/weekly) and diff technologies downstream to catch migrations — e.g. a competitor's customer moving off Magento is a sales trigger.
Integrations? Dataset export as JSON/CSV/Excel, Apify API, webhooks, plus native Make, Zapier, n8n, Google Sheets, and MCP for AI agents.