Website Tech Stack Detector (Wappalyzer API Scraper) avatar

Website Tech Stack Detector (Wappalyzer API Scraper)

Pricing

from $0.50 / 1,000 output rows

Go to Apify Store
Website Tech Stack Detector (Wappalyzer API Scraper)

Website Tech Stack Detector (Wappalyzer API Scraper)

Find out what technologies any website runs — JavaScript frameworks, CMS, CDNs, analytics, e-commerce platforms, web servers and more — via the Wappalyzer API. Feed it URLs or domains and get flat, CSV-ready rows, one per detected technology, with category and traffic rank. No API key needed.

Pricing

from $0.50 / 1,000 output rows

Rating

0.0

(0)

Developer

R.L.

R.L.

Maintained by Community

Actor stats

1

Bookmarked

57

Total users

12

Monthly active users

6 days ago

Last modified

Share

Website Tech Stack Detector – Wappalyzer Technology Lookup

Find out what technologies a website uses. This Actor detects the tech stack behind any website — JavaScript frameworks, CMSs, CDNs, analytics tools, e-commerce platforms, web servers, and hundreds of other categories. Give it a list of URLs or domains and it returns the technologies each site runs, powered by the Wappalyzer API.

Run it on the Apify platform to get scheduling, a REST API, webhooks, and integrations with Make, Zapier, Google Sheets, and more — no infrastructure to manage.

What does this website tech stack detector do?

For every URL or domain you provide, the Actor queries the Wappalyzer lookup API and stores the detected technologies, including each technology's name, category, version (when known), traffic rank, and icon. It's the fastest way to check what software a website is built with — in bulk, across a whole list of domains, and exportable to CSV, JSON, or Excel. No Wappalyzer API key of your own is required.

Why detect a website's technology stack?

  • Lead generation & sales intelligence — find sites running a specific platform (e.g. Shopify, HubSpot) to target prospects.
  • Competitive analysis — see what frameworks and tools competitors rely on.
  • Market research — measure technology adoption across a list of domains.
  • Security & compliance — inventory the software exposed by your own web properties.

What technologies can it detect?

Wappalyzer fingerprints well over a thousand technologies. The categories that come up most often:

CategoryExamples
CMSWordPress, Drupal, Joomla, Ghost, Contentful, Webflow
E-commerceShopify, WooCommerce, Magento, BigCommerce, PrestaShop
JavaScript frameworksReact, Vue.js, Angular, Next.js, Svelte, Nuxt
AnalyticsGoogle Analytics, Matomo, Mixpanel, Hotjar, Plausible
CDN & hostingCloudflare, Akamai, Fastly, AWS, Vercel, Netlify
Marketing & CRMHubSpot, Salesforce, Marketo, Klaviyo, Intercom
PaymentsStripe, PayPal, Adyen, Klarna, Shopify Payments
Web serversNginx, Apache, LiteSpeed, IIS

Each detected technology becomes its own row, tagged with its category, so you can filter a whole list of domains down to just the ones running a particular platform.

How to detect what technology a website uses

  1. Open the Actor in Apify Console.
  2. In the Input tab, add the URLs or domains you want to analyze (one per line). Full URLs (https://example.com) and bare domains (example.com) both work.
  3. Click Start.
  4. When the run finishes, open the Output tab to view results, or download them in JSON, CSV, Excel, or HTML.

Input

The only input is a list of websites to analyze:

{
"urls": [
"https://nike.com",
"example.com",
"https://github.com"
]
}
FieldTypeDescription
urlsarray of stringsURLs or domains to look up. A missing scheme defaults to https://. Invalid entries are skipped.
maxConcurrencyintegerOptional. How many lookups run at once (1-25). Leave empty to let the Actor pick a value that fits the run's memory.
proxyConfigurationobjectOptional. Defaults to Apify residential proxy — see below.

About the proxy

The Wappalyzer API rate-limits per IP, so a bulk run needs to spread its requests across several addresses. This Actor therefore defaults to Apify's residential proxy.

Datacenter proxies do not work for this API: that pool is small and shared across Apify users, and Wappalyzer already rate-limits it, so requests through it come back HTTP 429 and the results are empty. Running with no proxy at all works for small inputs but sends every lookup from a single IP, which will be rate-limited on a large run.

Residential proxy traffic is billed by the gigabyte and costs more than datacenter traffic. The responses here are small JSON documents, so a typical run moves only a few megabytes — but it is a real cost on top of the per-row charge, and you can point proxyConfiguration at a different pool, or turn the proxy off, if that suits you better.

Output

The output is flat — one row per detected technology — so it maps cleanly to a spreadsheet. You can download the dataset in various formats such as JSON, HTML, CSV, or Excel.

[
{
"domain": "wordpress.com",
"technologyName": "React",
"technologySlug": "react",
"versions": "18.3.1",
"cpe": "cpe:2.3:a:facebook:react:18.3.1:*:*:*:*:*:*:*",
"trafficRank": 2926,
"confirmedAt": 1790429473,
"iconUrl": "https://www.wappalyzer.com/images/icons/converted/React.png",
"categories": "JavaScript frameworks"
},
{
"domain": "wordpress.com",
"technologyName": "WordPress",
"technologySlug": "wordpress",
"versions": null,
"cpe": null,
"trafficRank": 86209,
"confirmedAt": 1790429473,
"iconUrl": "https://www.wappalyzer.com/images/icons/converted/WordPress.png",
"categories": "CMS, Blogs"
}
]

Data fields

FieldDescription
domainThe looked-up website's domain (scheme and leading www. stripped).
technologyNameTechnology name (e.g. React).
technologySlugWappalyzer's stable slug for the technology (e.g. react) — a safer join key than the display name.
versionsDetected version(s), comma-separated, or null when no version is exposed. Roughly one row in five carries one.
cpeCPE identifier, e.g. cpe:2.3:a:facebook:react:18.3.1:*:*:*:*:*:*:* — the key CVE databases use, so you can match a detection against known vulnerabilities. Only present where a version was detected (about 4% of rows).
trafficRankWappalyzer traffic rank signal.
confirmedAtUnix timestamp of when the detection was last confirmed.
iconUrlDirect URL to the technology's PNG icon.
categoriesComma-separated category names the technology belongs to (e.g. CDN, Analytics).
errorPresent only on a row when the lookup failed for that domain (e.g. invalid URL).

Pricing

This Actor uses the pay-per-event pricing model:

EventPriceWhen it's charged
Output row$0.50 per 1,000 rows ($0.0005 each)Once for every technology row written to the dataset.

You're charged once per technology row, so a run that produces 2,000 technology rows costs 2,000 × $0.0005 = $1.00.

You are not charged for a domain that delivered nothing. A domain where no technology was recognised, and a domain whose lookup failed, still get a row each — so you can see exactly which domains were processed — but those rows are free. A 100-domain run where 10 domains come back empty is billed for the technology rows only.

Apify platform usage (compute units, proxy, data transfer) is billed on top of the per-event price, as shown on your run's usage tab. This Actor defaults to the residential proxy, which is billed by the gigabyte — see About the proxy above.

You can cap a run's total cost with the maximum cost per run setting in the Console; the Actor stops writing rows once that limit is reached.

Tips

  • Deduplication is automatic — repeated URLs are looked up only once.
  • Bare domains are fine; the Actor normalizes them to https://.
  • Requests rotate through residential proxy IPs automatically; failed lookups are retried on a fresh IP with backoff. Any URL that still fails is recorded with an error field instead of stopping the run.

n8n integration

Use the n8n-nodes-wappalyzer-lookup community node (source) to run this Actor directly from an n8n workflow.

FAQ, disclaimers, and support

How do I find all the websites using Shopify (or WordPress, or any platform)? Feed in your list of domains, then filter the output rows where technologyName matches the platform you care about. Each technology is its own row, so a filter or spreadsheet pivot is all it takes.

Can I check what CMS a website is built with? Yes — CMS is one of the detected categories. Look for rows whose categories field contains CMS.

Can I find sites running something with a known CVE? Rows where a version was detected also carry a cpe — the CPE identifier that CVE databases key on — so the output joins directly against NVD or the CVE Scraper below. Only detections that expose a version get one, which is about 4% of rows.

Do I need a Wappalyzer account or API key? No. The key is bundled with the Actor, so you only pay the per-row Apify charge.

How many domains can I check at once? There is no fixed cap — pass a list of any length. Lookups run in parallel (tunable via Parallel lookups), duplicates are collapsed automatically, and you can bound total spend with the maximum-cost-per-run setting.

How accurate is the detection? Detections are fingerprint-based, so they identify technologies that leave an observable trace in the page, headers, or scripts. Something loaded only behind a login, or server-side with no client-visible signature, may not be detected. The confirmedAt timestamp tells you when Wappalyzer last verified the detection.

Is this affiliated with Wappalyzer? No. This Actor uses the public Wappalyzer API and is not an official Wappalyzer product.

Is web technology detection legal? The Actor only queries the Wappalyzer API for publicly available technology fingerprints. As with any data tool, ensure your use complies with applicable laws and the target services' terms.

Found a bug or have a feature request? Open an issue on the Actor's Issues tab. Custom solutions are available on request.

Cyber recon toolkit

Part of the Cyber recon toolkit — OSINT, attack-surface recon, and vulnerability-intel data collection for security research:

Did you find this useful?

⭐ Rate this actor on Apify! Your feedback helps other users find it and helps us keep improving it.