See what a website is built with.

The CMS, the framework, the server, the CDN and who hosts it, with the evidence for each.

Searches are never stored for anyone but you, or sold.
Privacy policy
Try

Technologies it can detect

556 technologies in 31 groups. Scan a site and whichever of these it runs come back grouped like this, each with the evidence beside it.

Content management

57
  • Adobe Experience Manager
  • beehiiv
  • Blogger
  • Bubble
  • Builder.io
  • Carrd
  • Concrete CMS
  • Contao
  • Contentful
  • Contentstack
  • Craft CMS
  • DatoCMS
  • Divi
  • Docusaurus
  • Drupal

Ecommerce

20
  • Big Cartel
  • BigCommerce
  • Ecwid
  • Foxy
  • Gumroad
  • Lightspeed eCom
  • Magento
  • nopCommerce
  • OpenCart
  • PrestaShop
  • Recharge
  • Salesforce Commerce Cloud
  • SamCart
  • Shopify
  • Shoplazza

Framework

32
  • Alpine.js
  • Angular
  • Astro
  • Backbone.js
  • Blazor
  • Eleventy
  • Ember.js
  • Flutter
  • Fresh
  • Gatsby
  • Hotwire Turbo
  • htmx
  • Hugo
  • Inertia.js
  • Ionic

UI & libraries

45
  • Ant Design
  • AOS
  • Apache ECharts
  • Bootstrap
  • Bootstrap Icons
  • Boxicons
  • Bulma
  • Chakra UI
  • Chart.js
  • D3
  • Element Plus
  • Fancybox
  • Flickity
  • Flowbite
  • Font Awesome

Language & runtime

18
  • ASP.NET
  • Bun
  • Classic ASP
  • ColdFusion
  • Django
  • Express
  • FastAPI
  • Flask
  • Go
  • Java
  • Laravel
  • Node.js
  • Phoenix
  • PHP
  • Python

Web server

18
  • Apache
  • Apache Tomcat
  • Caddy
  • Envoy
  • Gunicorn
  • IIS
  • Jetty
  • Kestrel
  • Kong
  • lighttpd
  • LiteSpeed
  • nginx
  • OpenResty
  • Puma
  • Tengine

Hosting

21
  • Cloudflare Pages
  • Cloudflare Workers
  • Cloudways
  • Deno Deploy
  • Firebase Hosting
  • Fly.io
  • GitHub Pages
  • GitLab Pages
  • Google Cloud
  • Heroku
  • Hostinger
  • Kinsta
  • Microsoft Azure
  • Netlify
  • Pantheon

CDN & edge

13
  • Akamai
  • Amazon CloudFront
  • Bunny CDN
  • CDN77
  • cdnjs
  • Cloudflare
  • esm.sh
  • Fastly
  • Google Hosted Libraries
  • jsDelivr
  • KeyCDN
  • Skypack
  • unpkg

Speed & performance

8
  • Autoptimize
  • Cloudflare APO
  • NitroPack
  • Perfmatters
  • W3 Total Cache
  • WP Fastest Cache
  • WP Rocket
  • WP Super Cache

Analytics

31
  • Adobe Analytics
  • Amplitude
  • Chartbeat
  • Cloudflare Web Analytics
  • Comscore
  • Contentsquare
  • Crazy Egg
  • Fathom Analytics
  • FullStory
  • GoatCounter
  • Google Analytics
  • Heap
  • Hotjar
  • Lucky Orange
  • Matomo

Tag management

4
  • Commanders Act
  • Ensighten
  • Google Tag Manager
  • Tealium

Customer data

12
  • Adobe Experience Platform
  • Bloomreach Engagement
  • BlueConic
  • Freshpaint
  • Hightouch
  • Lytics
  • mParticle
  • Piano
  • RudderStack
  • Segment
  • Snowplow
  • Treasure Data

Testing & personalisation

16
  • AB Tasty
  • Convert
  • Dynamic Yield
  • Flagsmith
  • GrowthBook
  • Insider
  • Kameleoon
  • LaunchDarkly
  • Marketing Cloud Personalization
  • Monetate
  • Nosto
  • Optimizely
  • Qubit
  • Split
  • Statsig

Advertising

20
  • AdRoll
  • Criteo
  • Ezoic
  • Google Ad Manager
  • Google Ads
  • LinkedIn Insight Tag
  • Mediavine
  • Meta Pixel
  • Microsoft Advertising
  • Outbrain
  • Pinterest Tag
  • Prebid.js
  • Quora Pixel
  • Raptive
  • Reddit Pixel

Marketing & email

33
  • ActiveCampaign
  • Attentive
  • Bluecore
  • Blueshift
  • Braze
  • Brevo
  • ClickFunnels
  • Cordial
  • Customer.io
  • Dotdigital
  • Drip
  • HubSpot
  • Instapage
  • Iterable
  • Justuno

A group with nothing in it is not drawn on a result. Nothing detected is not the same as nothing there, and the limits further down say which is which.

And the rest of the report

The stack is the top of the page. Under it is everything else a site is willing to say about itself.

Who serves it

The network the site answers from, the country it is registered in, and the name that address goes by.

The certificate

Who issued it, when it runs out, and every other hostname it covers, which is where a site names the other properties it runs.

Security headers

The six a browser acts on, each shown as set or missing rather than scored.

Crawler policy

The sitemaps a site publishes, and which AI companies it asks to stay out of its content.

The way in

Every hop between the name typed and the page that answers, so a chain nobody has looked at in years is visible.

How a row is marked

Three states, and only the first one is something we watched happen.

Seen

The site said so itself, and the row prints the thing it was read from. A claim you can check beats a claim you have to believe.

Implied

It follows from something else: React under Next.js, WordPress under WooCommerce. Drawn quieter, because an inference is not an observation.

Versioned

Where a site publishes its own version number. That it publishes one at all is a finding: it tells a scanner which advisories to try.

What it will not show you

Said here rather than left to be inferred from a short report.

Code that keeps quiet

Plenty of stacks say nothing about themselves. Where one does not, the report shows what is in front of it and stops there. A gap is a gap, not a finding.

What a proxy hides

A site behind a CDN answers as that CDN, and the page says so rather than dressing the front door up as the building.

The pages you did not ask about

One name, one site: what runs only on a checkout, a docs section or an admin screen is not in it.

The rest of the name

A stack is one question about a domain. These answer the others.

  1. Whois lookupWho holds the name, through which registrar, and the date it has to be renewed by.
  2. DNS checkerThe zone itself: where mail goes, and which services the domain is verified with.
  3. Domain explorerEvery check on this site against one name at once, this one included.
  4. AppraisalWhat the name itself is worth, with every reason that moved the figure.

Questions

How does it know what a website is built with?

Sites say a great deal about themselves to anyone who opens them, and the scan reads what is on offer. Every detection on the result page carries the evidence behind it, so each line can be checked rather than taken on trust. That is the part that matters, because a list of logos with nothing under it is a guess in a nice font.

Why does it say a technology is 'implied'?

Because it follows from something else rather than from evidence of its own. A site running Next.js is running React whether or not React names itself, and a site running WooCommerce is running WordPress by definition. Those are drawn quieter and labelled, because an inference and an observation should not look alike.

It missed something I know is there. Why?

Three common reasons. Some technologies leave nothing visible from outside at all, which is why a site built on Go or Rust will only ever show the web server in front of it. Some appear only well after a page has started running. And some are simply not on the page you scanned: an analytics script that loads on the checkout is not on the front page. Nothing detected is not the same thing as nothing there.

Does it show the real server behind Cloudflare?

No, and nothing can. When a site is proxied, every request goes to the proxy and the origin never appears, which is what the proxy is for. The page says the address belongs to Cloudflare rather than claiming the site is hosted there, because the front door is not the building. Occasionally the origin still names itself through the proxy, and where that happens you will see both: the CDN in front and the server behind it.

Where does the hosting information come from?

The network that actually answered, rather than a registry record or a bought data set. That is why the name reads like 'AMAZON-02' or 'HETZNER-AS' instead of like a brand: it is the network's own registration, and the country beside it is where that network is registered, which is not always where the machine sits.

Does scanning a site notify its owner?

It appears in their server logs like any other visit, named honestly: the scan identifies itself as Onymu's and links back to this page. It is lighter than opening the site in a browser. A site that would rather not be read can refuse the scanner in robots.txt or block it outright, and some do.

How current is the answer?

A scan is live. The answer is then held briefly, so the same site checked twice within a few minutes can repeat itself rather than being fetched again. A stack only changes when somebody deploys, so that is well inside the interval that matters for almost every site. The exception is your own, in the minutes after you have changed something.

What are the AI crawlers it lists?

Lines in the site's own robots.txt that name a crawler belonging to an AI company and disallow it everything. Since 2023 most large publishers have added them, so it is a quick read on whether a site wants its content in training data or in an assistant's answers. robots.txt is honoured voluntarily rather than enforced, so it records an intention rather than a guarantee.

Can I use this to check a domain before buying it?

That is a large part of what it is for. A name sold as a going concern comes with whatever is running on it, and the scan shows what that is: whether there is a real site or a parking page, what it was built with, who hosts it, whether the certificate is being renewed, and what the previous owner will still be able to see if a third-party script stays in place after the transfer. Pair it with the Whois lookup for the registration and the DNS checker for the zone.