Website Tech Stack Detector API: CMS, Frameworks, Analytics avatar

Website Tech Stack Detector API: CMS, Frameworks, Analytics

Pricing

Pay per event + usage

Go to Apify Store
Website Tech Stack Detector API: CMS, Frameworks, Analytics

Website Tech Stack Detector API: CMS, Frameworks, Analytics

Detect the technologies behind any website: CMS, ecommerce platform, analytics, JavaScript frameworks, CDN, hosting and 7,600+ more. One fast HTTP request per domain, no browser. Batch lists or call it one URL at a time from AI agents.

Pricing

Pay per event + usage

Rating

0.0

(0)

Developer

Rod Services

Rod Services

Maintained by Community

Actor stats

0

Bookmarked

1

Total users

0

Monthly active users

a day ago

Last modified

Share

What does Website Tech Stack Detector do?

Website Tech Stack Detector finds out which technologies any website uses: CMS, ecommerce platform, analytics and marketing tools, JavaScript frameworks, CDN, hosting, web server, payment and chat widgets. It knows 7,600+ technologies in 100+ categories and returns clean JSON for every domain.

It sends one fast HTTP request per domain, no browser, so it is cheap and quick: about $1.80 per 1,000 domains. Give it a list of domains, or call it one URL at a time as a real-time API from your app or AI agent. It is a low-cost website technology lookup tool you can run on the Apify platform with API access, scheduling, integrations (Make, Zapier, n8n, Google Sheets, webhooks) and monitoring.

Try it now: press Start with the prefilled example (WordPress.org, Shopify, GitHub). It finishes in a few seconds.

Why use Website Tech Stack Detector?

  • Lead generation and sales prospecting. Find every store on Shopify, every site on WordPress or HubSpot, every company using a competitor's product. Build lead lists that match your ideal customer profile.
  • Competitor research. See which analytics, A/B testing, chat, CDN and frameworks your competitors use.
  • Market and technographic research. Measure market share of platforms across thousands of domains.
  • Lead enrichment in your CRM. Add CMS, ecommerce platform and hosting to company records.
  • AI agents and LLM tools. A fast, predictable, single-URL JSON endpoint. Agents ask "what is example.com built on?" and get an answer in about a second.
  • Security and IT audits. Spot outdated jQuery, WordPress or server versions exposed in headers.

How to detect the tech stack of a website

  1. Open the Input tab.
  2. Paste domains or URLs into Websites or domains, one per line. example.com is fine.
  3. Optional: pick Only these categories, for example CMS, Ecommerce, Analytics.
  4. Press Start.
  5. Open the Output tab. Download results as JSON, CSV, Excel or HTML, or fetch them by API.

Input

All fields are on the Input tab. Only urls is required.

FieldTypeDefaultDescription
urlsarray of stringsDomains or URLs. Duplicates are removed. Redirects are followed.
includeCategoriesarray of strings[]Keep only these categories. Case-insensitive.
includeRawSignalsbooleanfalseAdd headers, cookie names, meta tags, script and link URLs, plus the evidence behind each detection.
detectJsGlobalsbooleantrueMatch known JS global names in inline scripts. Reported with 50% confidence.
maxConcurrencyinteger10Websites fetched in parallel (1 to 50).
timeoutSecsinteger15Timeout per website (3 to 60).
proxyConfigurationobjectoffOptional. Apify datacenter proxy or your own proxy URLs. No residential.
{
"urls": ["wordpress.org", "https://www.shopify.com", "github.com"],
"includeCategories": ["CMS", "Ecommerce", "Analytics", "CDN"],
"maxConcurrency": 10,
"timeoutSecs": 15
}

Output

One item per domain. You can download the dataset in various formats such as JSON, HTML, CSV, or Excel. The One row per technology view flattens it for spreadsheets.

{
"url": "wordpress.org",
"finalUrl": "https://wordpress.org/",
"statusCode": 200,
"title": "Blog Tool, Publishing Platform, and CMS – WordPress.org",
"technologies": [
{
"name": "WordPress",
"categories": ["CMS", "Blogs"],
"version": "7.2",
"confidence": 100,
"website": "https://wordpress.org"
},
{
"name": "Gutenberg",
"categories": ["WordPress plugins", "Editors"],
"version": "24.0.0",
"confidence": 100,
"website": "https://github.com/WordPress/gutenberg"
},
{
"name": "PHP",
"categories": ["Programming languages"],
"version": null,
"confidence": 100,
"website": "http://php.net"
},
{
"name": "MySQL",
"categories": ["Databases"],
"version": null,
"confidence": 100,
"website": "http://mysql.com"
},
{
"name": "Nginx",
"categories": ["Web servers", "Reverse proxies"],
"version": null,
"confidence": 100,
"website": "http://nginx.org/en"
},
{
"name": "Google Tag Manager",
"categories": ["Tag managers"],
"version": null,
"confidence": 100,
"website": "http://www.google.com/tagmanager"
}
],
"technologyNames": ["WordPress", "Gutenberg", "PHP", "MySQL", "Nginx", "Google Tag Manager"],
"technologyCount": 6,
"categoriesSummary": {
"CMS": ["WordPress"],
"Blogs": ["WordPress"],
"WordPress plugins": ["Gutenberg"],
"Editors": ["Gutenberg"],
"Databases": ["MySQL"],
"Programming languages": ["PHP"],
"Reverse proxies": ["Nginx"],
"Web servers": ["Nginx"],
"Tag managers": ["Google Tag Manager"]
},
"detectedAt": "2026-09-27T10:11:46.836Z",
"error": null
}

If a site cannot be reached, the item has error set (for example getaddrinfo ENOTFOUND) and an empty technologies list. Failed domains are not charged.

Data fields

FieldDescription
urlDomain or URL as you entered it
finalUrlURL after redirects
statusCodeHTTP status of the final response
titlePage title
technologies[].nameTechnology name, e.g. Shopify
technologies[].categoriesCategories, e.g. ["Ecommerce"]
technologies[].versionVersion when the site exposes it, else null
technologies[].confidence1 to 100, see below
technologies[].websiteVendor website
technologyNamesNames only, handy for filters
categoriesSummaryCategory to technology names
detectedAtISO timestamp
errorError message, or null
rawSignalsOnly with includeRawSignals

Real-time API for AI agents (Standby mode)

The Actor also runs as an always-ready HTTP endpoint. One GET request, one JSON answer:

curl -H "Authorization: Bearer YOUR_APIFY_TOKEN" \
"https://rod-analytics--tech-stack-detector.apify.actor/?url=shopify.com"
curl -H "Authorization: Bearer YOUR_APIFY_TOKEN" \
"https://rod-analytics--tech-stack-detector.apify.actor/?url=example.com&includeCategories=CMS,Analytics&includeRawSignals=true"

Query parameters: url (required), includeCategories (comma separated), includeRawSignals, detectJsGlobals, timeoutSecs. The answer is the same JSON item as in a batch run. A warm endpoint answers in about a second; the first call after a quiet period takes a few seconds more while a container starts.

  • Invalid or private URL: HTTP 400 with {"error": "..."}. Not charged.
  • Site unreachable (DNS error, timeout): HTTP 200 with error filled in. Not charged.
  • Your maximum cost per run reached: HTTP 402.

AI agents can also use it through the Apify MCP server.

How much does it cost to detect a website's tech stack?

Pay per result. $1.80 per 1,000 domains ($0.0018 per domain) plus a $0.001 start fee per run. One flat price on every Apify plan. No subscription and no proxy costs. Failed domains are free. Apify's $5 free monthly credit covers about 2,500 domains.

Tips for speed and accuracy

  • Use bare domains (shopify.com). The Actor tries https first and falls back to http.
  • Use includeCategories when you only care about, say, CMS and Ecommerce. Items get smaller.
  • Raise maxConcurrency to 20 or 30 for large lists. Use 1,024 MB memory for the fastest runs.
  • Turn on includeRawSignals to see why something was detected, or to run your own rules on headers and scripts.
  • Pages behind bot protection (DataDome, Cloudflare challenge) return a challenge page. You still get the CDN and WAF, but not the CMS. These pages answered, so they are charged like any other page. Try Apify datacenter proxy or your own proxy URLs for those.
  • Files that are not web pages (PDF, images) are reported with an error and not charged.

FAQ

How does it work?

It downloads the page once and matches response headers, cookies, meta tags, script and link URLs, inline HTML, CSS and known JavaScript global names against an open fingerprint database. It also applies rules like "WooCommerce implies WordPress" and "WordPress implies PHP".

Where do the fingerprints come from?

It uses the open community fingerprint database enthec/webappanalyzer, bundled as a pinned snapshot. It is not affiliated with any commercial tech lookup service. Unlike tools that answer from a historical index, it checks the site live, right now.

What does confidence mean?

100 means a clear fingerprint, such as a generator meta tag or a cdn.shopify.com script. Lower values mean weaker evidence:

  • 50%: a JavaScript global name seen in an inline script (no browser runs the code).
  • 50%: a domain seen only in the Content-Security-Policy header. A CSP allows a service; it does not prove the page uses it.
  • 50%: one generic hint such as a link to /cart or /order (Cart Functionality). Two different hints give 100%.
  • Implied technologies (for example PHP from WordPress) take the confidence of the technology that implies them.

Filter on confidence >= 100 if you only want strong matches.

What can it not detect?

Technologies that only appear after JavaScript runs in a browser, on pages other than the one you give it, or in DNS and TLS records. Versions are shown only when the site exposes them.

Which proxies can I use?

No proxy (the default), Apify datacenter proxy, or your own proxy URLs. Residential and SERP proxies are not supported. A run that asks for them stops at the start with a clear message and does no work.

It fetches one public page per domain, like a browser would, and reads only public technical signals. It does not collect personal data. Check the target site's terms if you plan heavy use.

Is the source code open?

Yes. The Actor and its fingerprint data are licensed under GPL-3.0, and the full source is public on this Actor's Source code tab. The fingerprints are a filtered snapshot of enthec/webappanalyzer with a few local false-positive fixes (src/overrides.ts).

I need something custom

Missing a technology, need DNS or robots.txt checks, or a bulk export for millions of domains? Open an issue on the Issues tab. Custom solutions are available.