What is that website built with?
Enter a domain and see its stack — CMS, framework, server, CDN and WAF — read from a single homepage request, alongside the security headers it does and doesn't set.
Fingerprinting, and why it cuts both ways
Every website broadcasts clues about how it was built — in its headers, its cookies, the shape of its HTML. Developers use this to research competitors and check their own leakage; attackers use the exact same signals to decide which exploit to reach for. Knowing your stack is the difference between guessing and going straight for a known weakness.
This tool reads those clues from one ordinary request and reports the stack plus your security-header posture. It is the same fingerprinting step our audits begin with — the difference is that an audit then goes on to test whether what it found is actually exploitable.
Common questions
How can you tell what a website is built with?
Why would an attacker want to know my tech stack?
Should I hide my technology stack?
Is checking a website’s technology legal?
Keep reading
See what attackers see — free
Run the free passive check on your domain. No login, no impact on your site, results in seconds.