Website Tech Stack Detector (Wappalyzer API Scraper)
Pricing
from $0.50 / 1,000 output rows
Website Tech Stack Detector (Wappalyzer API Scraper)
Find out what technologies any website runs — JavaScript frameworks, CMS, CDNs, analytics, e-commerce platforms, web servers and more — via the Wappalyzer API. Feed it URLs or domains and get flat, CSV-ready rows, one per detected technology, with category and traffic rank. No API key needed.
Pricing
from $0.50 / 1,000 output rows
Rating
0.0
(0)
Developer
R.L.
Maintained by CommunityActor stats
1
Bookmarked
57
Total users
12
Monthly active users
6 days ago
Last modified
Categories
Share
Website Tech Stack Detector – Wappalyzer Technology Lookup
Find out what technologies a website uses. This Actor detects the tech stack behind any website — JavaScript frameworks, CMSs, CDNs, analytics tools, e-commerce platforms, web servers, and hundreds of other categories. Give it a list of URLs or domains and it returns the technologies each site runs, powered by the Wappalyzer API.
Run it on the Apify platform to get scheduling, a REST API, webhooks, and integrations with Make, Zapier, Google Sheets, and more — no infrastructure to manage.
What does this website tech stack detector do?
For every URL or domain you provide, the Actor queries the Wappalyzer lookup API and stores the detected technologies, including each technology's name, category, version (when known), traffic rank, and icon. It's the fastest way to check what software a website is built with — in bulk, across a whole list of domains, and exportable to CSV, JSON, or Excel. No Wappalyzer API key of your own is required.
Why detect a website's technology stack?
- Lead generation & sales intelligence — find sites running a specific platform (e.g. Shopify, HubSpot) to target prospects.
- Competitive analysis — see what frameworks and tools competitors rely on.
- Market research — measure technology adoption across a list of domains.
- Security & compliance — inventory the software exposed by your own web properties.
What technologies can it detect?
Wappalyzer fingerprints well over a thousand technologies. The categories that come up most often:
| Category | Examples |
|---|---|
| CMS | WordPress, Drupal, Joomla, Ghost, Contentful, Webflow |
| E-commerce | Shopify, WooCommerce, Magento, BigCommerce, PrestaShop |
| JavaScript frameworks | React, Vue.js, Angular, Next.js, Svelte, Nuxt |
| Analytics | Google Analytics, Matomo, Mixpanel, Hotjar, Plausible |
| CDN & hosting | Cloudflare, Akamai, Fastly, AWS, Vercel, Netlify |
| Marketing & CRM | HubSpot, Salesforce, Marketo, Klaviyo, Intercom |
| Payments | Stripe, PayPal, Adyen, Klarna, Shopify Payments |
| Web servers | Nginx, Apache, LiteSpeed, IIS |
Each detected technology becomes its own row, tagged with its category, so you can filter a whole list of domains down to just the ones running a particular platform.
How to detect what technology a website uses
- Open the Actor in Apify Console.
- In the Input tab, add the URLs or domains you want to analyze (one per line). Full URLs (
https://example.com) and bare domains (example.com) both work. - Click Start.
- When the run finishes, open the Output tab to view results, or download them in JSON, CSV, Excel, or HTML.
Input
The only input is a list of websites to analyze:
{"urls": ["https://nike.com","example.com","https://github.com"]}
| Field | Type | Description |
|---|---|---|
urls | array of strings | URLs or domains to look up. A missing scheme defaults to https://. Invalid entries are skipped. |
maxConcurrency | integer | Optional. How many lookups run at once (1-25). Leave empty to let the Actor pick a value that fits the run's memory. |
proxyConfiguration | object | Optional. Defaults to Apify residential proxy — see below. |
About the proxy
The Wappalyzer API rate-limits per IP, so a bulk run needs to spread its requests across several addresses. This Actor therefore defaults to Apify's residential proxy.
Datacenter proxies do not work for this API: that pool is small and shared
across Apify users, and Wappalyzer already rate-limits it, so requests through
it come back HTTP 429 and the results are empty. Running with no proxy at all
works for small inputs but sends every lookup from a single IP, which will be
rate-limited on a large run.
Residential proxy traffic is billed by the gigabyte and costs more than
datacenter traffic. The responses here are small JSON documents, so a typical
run moves only a few megabytes — but it is a real cost on top of the per-row
charge, and you can point proxyConfiguration at a different pool, or turn the
proxy off, if that suits you better.
Output
The output is flat — one row per detected technology — so it maps cleanly to a spreadsheet. You can download the dataset in various formats such as JSON, HTML, CSV, or Excel.
[{"domain": "wordpress.com","technologyName": "React","technologySlug": "react","versions": "18.3.1","cpe": "cpe:2.3:a:facebook:react:18.3.1:*:*:*:*:*:*:*","trafficRank": 2926,"confirmedAt": 1790429473,"iconUrl": "https://www.wappalyzer.com/images/icons/converted/React.png","categories": "JavaScript frameworks"},{"domain": "wordpress.com","technologyName": "WordPress","technologySlug": "wordpress","versions": null,"cpe": null,"trafficRank": 86209,"confirmedAt": 1790429473,"iconUrl": "https://www.wappalyzer.com/images/icons/converted/WordPress.png","categories": "CMS, Blogs"}]
Data fields
| Field | Description |
|---|---|
domain | The looked-up website's domain (scheme and leading www. stripped). |
technologyName | Technology name (e.g. React). |
technologySlug | Wappalyzer's stable slug for the technology (e.g. react) — a safer join key than the display name. |
versions | Detected version(s), comma-separated, or null when no version is exposed. Roughly one row in five carries one. |
cpe | CPE identifier, e.g. cpe:2.3:a:facebook:react:18.3.1:*:*:*:*:*:*:* — the key CVE databases use, so you can match a detection against known vulnerabilities. Only present where a version was detected (about 4% of rows). |
trafficRank | Wappalyzer traffic rank signal. |
confirmedAt | Unix timestamp of when the detection was last confirmed. |
iconUrl | Direct URL to the technology's PNG icon. |
categories | Comma-separated category names the technology belongs to (e.g. CDN, Analytics). |
error | Present only on a row when the lookup failed for that domain (e.g. invalid URL). |
Pricing
This Actor uses the pay-per-event pricing model:
| Event | Price | When it's charged |
|---|---|---|
| Output row | $0.50 per 1,000 rows ($0.0005 each) | Once for every technology row written to the dataset. |
You're charged once per technology row, so a run that produces 2,000 technology rows costs 2,000 × $0.0005 = $1.00.
You are not charged for a domain that delivered nothing. A domain where no technology was recognised, and a domain whose lookup failed, still get a row each — so you can see exactly which domains were processed — but those rows are free. A 100-domain run where 10 domains come back empty is billed for the technology rows only.
Apify platform usage (compute units, proxy, data transfer) is billed on top of the per-event price, as shown on your run's usage tab. This Actor defaults to the residential proxy, which is billed by the gigabyte — see About the proxy above.
You can cap a run's total cost with the maximum cost per run setting in the Console; the Actor stops writing rows once that limit is reached.
Tips
- Deduplication is automatic — repeated URLs are looked up only once.
- Bare domains are fine; the Actor normalizes them to
https://. - Requests rotate through residential proxy IPs automatically; failed lookups are retried on a fresh IP with backoff. Any URL that still fails is recorded with an
errorfield instead of stopping the run.
n8n integration
Use the n8n-nodes-wappalyzer-lookup community node (source) to run this Actor directly from an n8n workflow.
FAQ, disclaimers, and support
How do I find all the websites using Shopify (or WordPress, or any platform)? Feed in your list of domains, then filter the output rows where technologyName matches the platform you care about. Each technology is its own row, so a filter or spreadsheet pivot is all it takes.
Can I check what CMS a website is built with? Yes — CMS is one of the detected categories. Look for rows whose categories field contains CMS.
Can I find sites running something with a known CVE? Rows where a version was detected also carry a cpe — the CPE identifier that CVE databases key on — so the output joins directly against NVD or the CVE Scraper below. Only detections that expose a version get one, which is about 4% of rows.
Do I need a Wappalyzer account or API key? No. The key is bundled with the Actor, so you only pay the per-row Apify charge.
How many domains can I check at once? There is no fixed cap — pass a list of any length. Lookups run in parallel (tunable via Parallel lookups), duplicates are collapsed automatically, and you can bound total spend with the maximum-cost-per-run setting.
How accurate is the detection? Detections are fingerprint-based, so they identify technologies that leave an observable trace in the page, headers, or scripts. Something loaded only behind a login, or server-side with no client-visible signature, may not be detected. The confirmedAt timestamp tells you when Wappalyzer last verified the detection.
Is this affiliated with Wappalyzer? No. This Actor uses the public Wappalyzer API and is not an official Wappalyzer product.
Is web technology detection legal? The Actor only queries the Wappalyzer API for publicly available technology fingerprints. As with any data tool, ensure your use complies with applicable laws and the target services' terms.
Found a bug or have a feature request? Open an issue on the Actor's Issues tab. Custom solutions are available on request.
Cyber recon toolkit
Part of the Cyber recon toolkit — OSINT, attack-surface recon, and vulnerability-intel data collection for security research:
- Bugcrowd Scraper — Scrapes public Bugcrowd data: disclosed submissions, program directory, leaderboard.
- HackerOne Scraper — Scrapes public HackerOne data: Hacktivity disclosed reports, program directory, researcher leaderboard.
- Intigriti Scraper — Scrapes public Intigriti data: bug bounty/VDP program directory, researcher leaderboard and profiles.
- CVE Scraper — CVE.org vulnerability info scraper.
- TLSX - TLS Data Gathering and Analysis — Fast, configurable TLS grabber for TLS-based data collection and analysis.
- BGP.HE.NET Recon Scraper — Scrapes ASN, prefix, IP, and DNS recon data from bgp.he.net.
- gau - Get All URLs — Fetch known URLs from Wayback Machine, Common Crawl, AlienVault OTX, and URLScan.
- Git Email Extractor — Shallow-clones git repos and extracts contributor emails from commit history.
- Meta Tags Scraper — Web page metadata scraper (meta tags, Open Graph, Twitter Card).
- Universal Contact Extractor — Extract phone numbers, emails and social media URLs from web pages.
- Web Text Extractor — Extract clean text or Markdown content from web pages.
Did you find this useful?
⭐ Rate this actor on Apify! Your feedback helps other users find it and helps us keep improving it.