# Website Tech Stack Detector API: CMS, Frameworks, Analytics (`rod_analytics/tech-stack-detector`) Actor

Detect the technologies behind any website: CMS, ecommerce platform, analytics, JavaScript frameworks, CDN, hosting and 7,600+ more. One fast HTTP request per domain, no browser. Batch lists or call it one URL at a time from AI agents.

- **URL**: https://apify.com/rod\_analytics/tech-stack-detector.md
- **Developed by:** [Rod Services](https://apify.com/rod_analytics) (community)
- **Categories:** Lead generation, Developer tools, Open source
- **Stats:** 1 total users, 0 monthly users, 0.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

Pay per event + usage

This Actor is paid per event and usage. You are charged both the fixed price for specific events and for Apify platform usage.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

### What does Website Tech Stack Detector do?

**Website Tech Stack Detector** finds out **which technologies any website uses**: CMS, ecommerce platform, analytics and marketing tools, JavaScript frameworks, CDN, hosting, web server, payment and chat widgets. It knows **7,600+ technologies in 100+ categories** and returns clean JSON for every domain.

It sends **one fast HTTP request per domain**, no browser, so it is cheap and quick: about **$1.80 per 1,000 domains**. Give it a list of domains, or call it **one URL at a time as a real-time API** from your app or AI agent. It is a low-cost **website technology lookup tool** you can run on the Apify platform with API access, scheduling, integrations (Make, Zapier, n8n, Google Sheets, webhooks) and monitoring.

Try it now: press **Start** with the prefilled example (WordPress.org, Shopify, GitHub). It finishes in a few seconds.

### Why use Website Tech Stack Detector?

- **Lead generation and sales prospecting.** Find every store on Shopify, every site on WordPress or HubSpot, every company using a competitor's product. Build lead lists that match your ideal customer profile.
- **Competitor research.** See which analytics, A/B testing, chat, CDN and frameworks your competitors use.
- **Market and technographic research.** Measure market share of platforms across thousands of domains.
- **Lead enrichment in your CRM.** Add CMS, ecommerce platform and hosting to company records.
- **AI agents and LLM tools.** A fast, predictable, single-URL JSON endpoint. Agents ask "what is example.com built on?" and get an answer in about a second.
- **Security and IT audits.** Spot outdated jQuery, WordPress or server versions exposed in headers.

### How to detect the tech stack of a website

1. Open the **Input** tab.
2. Paste domains or URLs into **Websites or domains**, one per line. `example.com` is fine.
3. Optional: pick **Only these categories**, for example `CMS`, `Ecommerce`, `Analytics`.
4. Press **Start**.
5. Open the **Output** tab. Download results as JSON, CSV, Excel or HTML, or fetch them by API.

### Input

All fields are on the Input tab. Only `urls` is required.

| Field                | Type             | Default | Description                                                                                          |
| -------------------- | ---------------- | ------- | ---------------------------------------------------------------------------------------------------- |
| `urls`               | array of strings |         | Domains or URLs. Duplicates are removed. Redirects are followed.                                     |
| `includeCategories`  | array of strings | `[]`    | Keep only these categories. Case-insensitive.                                                        |
| `includeRawSignals`  | boolean          | `false` | Add headers, cookie names, meta tags, script and link URLs, plus the evidence behind each detection. |
| `detectJsGlobals`    | boolean          | `true`  | Match known JS global names in inline scripts. Reported with 50% confidence.                         |
| `maxConcurrency`     | integer          | `10`    | Websites fetched in parallel (1 to 50).                                                              |
| `timeoutSecs`        | integer          | `15`    | Timeout per website (3 to 60).                                                                       |
| `proxyConfiguration` | object           | off     | Optional. Apify datacenter proxy or your own proxy URLs. No residential.                             |

```json
{
    "urls": ["wordpress.org", "https://www.shopify.com", "github.com"],
    "includeCategories": ["CMS", "Ecommerce", "Analytics", "CDN"],
    "maxConcurrency": 10,
    "timeoutSecs": 15
}
```

### Output

One item per domain. You can download the dataset in various formats such as JSON, HTML, CSV, or Excel. The **One row per technology** view flattens it for spreadsheets.

```json
{
    "url": "wordpress.org",
    "finalUrl": "https://wordpress.org/",
    "statusCode": 200,
    "title": "Blog Tool, Publishing Platform, and CMS – WordPress.org",
    "technologies": [
        {
            "name": "WordPress",
            "categories": ["CMS", "Blogs"],
            "version": "7.2",
            "confidence": 100,
            "website": "https://wordpress.org"
        },
        {
            "name": "Gutenberg",
            "categories": ["WordPress plugins", "Editors"],
            "version": "24.0.0",
            "confidence": 100,
            "website": "https://github.com/WordPress/gutenberg"
        },
        {
            "name": "PHP",
            "categories": ["Programming languages"],
            "version": null,
            "confidence": 100,
            "website": "http://php.net"
        },
        {
            "name": "MySQL",
            "categories": ["Databases"],
            "version": null,
            "confidence": 100,
            "website": "http://mysql.com"
        },
        {
            "name": "Nginx",
            "categories": ["Web servers", "Reverse proxies"],
            "version": null,
            "confidence": 100,
            "website": "http://nginx.org/en"
        },
        {
            "name": "Google Tag Manager",
            "categories": ["Tag managers"],
            "version": null,
            "confidence": 100,
            "website": "http://www.google.com/tagmanager"
        }
    ],
    "technologyNames": ["WordPress", "Gutenberg", "PHP", "MySQL", "Nginx", "Google Tag Manager"],
    "technologyCount": 6,
    "categoriesSummary": {
        "CMS": ["WordPress"],
        "Blogs": ["WordPress"],
        "WordPress plugins": ["Gutenberg"],
        "Editors": ["Gutenberg"],
        "Databases": ["MySQL"],
        "Programming languages": ["PHP"],
        "Reverse proxies": ["Nginx"],
        "Web servers": ["Nginx"],
        "Tag managers": ["Google Tag Manager"]
    },
    "detectedAt": "2026-09-27T10:11:46.836Z",
    "error": null
}
```

If a site cannot be reached, the item has `error` set (for example `getaddrinfo ENOTFOUND`) and an empty `technologies` list. Failed domains are not charged.

### Data fields

| Field                       | Description                                   |
| --------------------------- | --------------------------------------------- |
| `url`                       | Domain or URL as you entered it               |
| `finalUrl`                  | URL after redirects                           |
| `statusCode`                | HTTP status of the final response             |
| `title`                     | Page title                                    |
| `technologies[].name`       | Technology name, e.g. `Shopify`               |
| `technologies[].categories` | Categories, e.g. `["Ecommerce"]`              |
| `technologies[].version`    | Version when the site exposes it, else `null` |
| `technologies[].confidence` | 1 to 100, see below                           |
| `technologies[].website`    | Vendor website                                |
| `technologyNames`           | Names only, handy for filters                 |
| `categoriesSummary`         | Category to technology names                  |
| `detectedAt`                | ISO timestamp                                 |
| `error`                     | Error message, or `null`                      |
| `rawSignals`                | Only with `includeRawSignals`                 |

### Real-time API for AI agents (Standby mode)

The Actor also runs as an always-ready HTTP endpoint. One GET request, one JSON answer:

```bash
curl -H "Authorization: Bearer YOUR_APIFY_TOKEN" \
  "https://rod-analytics--tech-stack-detector.apify.actor/?url=shopify.com"
curl -H "Authorization: Bearer YOUR_APIFY_TOKEN" \
  "https://rod-analytics--tech-stack-detector.apify.actor/?url=example.com&includeCategories=CMS,Analytics&includeRawSignals=true"
```

Query parameters: `url` (required), `includeCategories` (comma separated), `includeRawSignals`, `detectJsGlobals`, `timeoutSecs`. The answer is the same JSON item as in a batch run. A warm endpoint answers in about a second; the first call after a quiet period takes a few seconds more while a container starts.

- Invalid or private URL: HTTP 400 with `{"error": "..."}`. Not charged.
- Site unreachable (DNS error, timeout): HTTP 200 with `error` filled in. Not charged.
- Your maximum cost per run reached: HTTP 402.

AI agents can also use it through the [Apify MCP server](https://mcp.apify.com/).

### How much does it cost to detect a website's tech stack?

Pay per result. **$1.80 per 1,000 domains** ($0.0018 per domain) plus a $0.001 start fee per run. One flat price on every Apify plan. No subscription and no proxy costs. Failed domains are free. Apify's $5 free monthly credit covers about 2,500 domains.

### Tips for speed and accuracy

- Use bare domains (`shopify.com`). The Actor tries https first and falls back to http.
- Use `includeCategories` when you only care about, say, CMS and Ecommerce. Items get smaller.
- Raise `maxConcurrency` to 20 or 30 for large lists. Use 1,024 MB memory for the fastest runs.
- Turn on `includeRawSignals` to see why something was detected, or to run your own rules on headers and scripts.
- Pages behind bot protection (DataDome, Cloudflare challenge) return a challenge page. You still get the CDN and WAF, but not the CMS. These pages answered, so they are charged like any other page. Try Apify datacenter proxy or your own proxy URLs for those.
- Files that are not web pages (PDF, images) are reported with an error and not charged.

### FAQ

#### How does it work?

It downloads the page once and matches response headers, cookies, meta tags, script and link URLs, inline HTML, CSS and known JavaScript global names against an open fingerprint database. It also applies rules like "WooCommerce implies WordPress" and "WordPress implies PHP".

#### Where do the fingerprints come from?

It uses the open community fingerprint database [enthec/webappanalyzer](https://github.com/enthec/webappanalyzer), bundled as a pinned snapshot. It is not affiliated with any commercial tech lookup service. Unlike tools that answer from a historical index, it checks the site live, right now.

#### What does confidence mean?

100 means a clear fingerprint, such as a `generator` meta tag or a `cdn.shopify.com` script. Lower values mean weaker evidence:

- 50%: a JavaScript global name seen in an inline script (no browser runs the code).
- 50%: a domain seen only in the `Content-Security-Policy` header. A CSP allows a service; it does not prove the page uses it.
- 50%: one generic hint such as a link to `/cart` or `/order` (`Cart Functionality`). Two different hints give 100%.
- Implied technologies (for example PHP from WordPress) take the confidence of the technology that implies them.

Filter on `confidence >= 100` if you only want strong matches.

#### What can it not detect?

Technologies that only appear after JavaScript runs in a browser, on pages other than the one you give it, or in DNS and TLS records. Versions are shown only when the site exposes them.

#### Which proxies can I use?

No proxy (the default), Apify datacenter proxy, or your own proxy URLs. Residential and SERP proxies are not supported. A run that asks for them stops at the start with a clear message and does no work.

#### Is it legal?

It fetches one public page per domain, like a browser would, and reads only public technical signals. It does not collect personal data. Check the target site's terms if you plan heavy use.

#### Is the source code open?

Yes. The Actor and its fingerprint data are licensed under GPL-3.0, and the full source is public on this Actor's **Source code** tab. The fingerprints are a filtered snapshot of enthec/webappanalyzer with a few local false-positive fixes (`src/overrides.ts`).

#### I need something custom

Missing a technology, need DNS or robots.txt checks, or a bulk export for millions of domains? Open an issue on the **Issues** tab. Custom solutions are available.

# Actor input Schema

## `urls` (type: `array`):

Domains or URLs to analyse, one per line. Example: shopify.com, https://www.example.com/pricing. Only the given page is fetched (redirects are followed).

## `includeCategories` (type: `array`):

Optional. Return only technologies in these categories, for example CMS, Ecommerce, Analytics, JavaScript frameworks, CDN, PaaS, Web servers. Case-insensitive. Leave empty for everything.

## `includeRawSignals` (type: `boolean`):

Adds response headers, cookie names, meta tags, script and link URLs to each item, plus the evidence behind every detection. Useful for debugging. Makes items larger.

## `detectJsGlobals` (type: `boolean`):

Also match known JavaScript global names found in inline scripts (for example Shopify.theme). No browser is used, so these hits get 50% confidence.

## `maxConcurrency` (type: `integer`):

How many websites to fetch in parallel.

## `timeoutSecs` (type: `integer`):

Maximum time to wait for each website to respond, including redirects. A site that times out is retried once, then reported with an error and not charged.

## `proxyConfiguration` (type: `object`):

Optional. Most websites work without a proxy. Use Apify datacenter proxy or your own proxy URLs only if many sites block you. Residential and SERP proxies are not supported.

## Actor input object example

```json
{
  "urls": [
    "https://wordpress.org",
    "https://www.shopify.com",
    "https://github.com"
  ],
  "includeCategories": [],
  "includeRawSignals": false,
  "detectJsGlobals": true,
  "maxConcurrency": 10,
  "timeoutSecs": 15,
  "proxyConfiguration": {
    "useApifyProxy": false
  }
}
```

# Actor output Schema

## `overview` (type: `string`):

No description

## `technologies` (type: `string`):

No description

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "urls": [
        "https://wordpress.org",
        "https://www.shopify.com",
        "https://github.com"
    ],
    "proxyConfiguration": {
        "useApifyProxy": false
    }
};

// Run the Actor and wait for it to finish
const run = await client.actor("rod_analytics/tech-stack-detector").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "urls": [
        "https://wordpress.org",
        "https://www.shopify.com",
        "https://github.com",
    ],
    "proxyConfiguration": { "useApifyProxy": False },
}

# Run the Actor and wait for it to finish
run = client.actor("rod_analytics/tech-stack-detector").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "urls": [
    "https://wordpress.org",
    "https://www.shopify.com",
    "https://github.com"
  ],
  "proxyConfiguration": {
    "useApifyProxy": false
  }
}' |
apify call rod_analytics/tech-stack-detector --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,rod_analytics/tech-stack-detector"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/6xuONbPnuZEttUiwN/builds/jUau3Fqvte1HStghi/openapi.json
