My Tool Studio
Brand Extractors·4 min read

Reading a Site's Tech Stack: Evidence, Not Guesses

A website's stack says a lot before anyone answers the phone: what the site cost to build, who maintains it, how seriously the team measures, and where email lives. Wappalyzer and BuiltWith made stack lookups a habit for sales and agency teams. The Tech Stack Detector does the same quick read for free, from the HTML, response headers, cookies and DNS records, and shows the evidence for every match. This guide explains what each signal means and how far to trust it.

SVGPNG

What a tech stack reveals

A site is a list of decisions.

The CMS tells you how the site is edited: WordPress means themes and plugins, Shopify or BigCommerce means a hosted store, Webflow or Framer means a design-led team. Analytics and ad pixels show how much the business measures and where it advertises. Email hosting says whether the company runs on Google Workspace or Microsoft 365, and live chat or CRM tags show how it talks to customers.

For a sales call, that is enough to open with a relevant question. For an agency scoping a rebuild, it is the first page of the migration plan.

Four places a stack leaves marks

HTML is only the start.

The page HTML carries asset paths such as wp-content or cdn.shopify.com, framework markers such as __NEXT_DATA__, generator meta tags, and the script addresses of every tag the site loads. Response headers name the web server, the CDN and sometimes the platform, through fields such as server, x-powered-by, cf-ray or x-vercel-id. Cookie names give away frameworks and platforms too, such as PHPSESSID or _shopify_y.

DNS records cover what never appears on the page. MX records show the email host, TXT records list the services allowed to send email for the domain, such as SendGrid or Mailchimp, and NS records show the DNS provider. The detector reads all four and matches about 230 technologies across more than 40 categories.

Confidence and evidence

Why every match shows its source.

Open any result to see the evidence behind it. A header, cookie, generator tag or DNS record comes from the server or the platform itself, so one of those alone earns a high confidence badge. A single pattern in the HTML or one script address gets medium, because it can also appear on a page that only writes about a tool. Implied results, such as PHP under WordPress or React under Next.js, were not seen directly but follow from something that was.

Versions appear when the site exposes them, most often in a generator tag, a file name such as jquery-3.7.1.min.js, a ver parameter, or a server header. Many sites hide versions on purpose, so a blank version is normal.

A worked detection

One agency lead, five minutes.

Run a local furniture retailer. The results group into categories: WordPress 6.5 with WooCommerce and Elementor, jQuery, Google Tag Manager and Google Analytics, the Meta Pixel, Cloudflare in front of LiteSpeed, Google Workspace for email and Klaviyo for marketing mail. The WordPress box lists the theme folder hello-elementor and plugin folders such as woocommerce, elementor and wordfence, each linked to wordpress.org.

That is a clear brief: a page-builder site on shared hosting with paid social running, a likely candidate for a performance and conversion project. Copy the list into the CRM note, or export CSV for the proposal appendix.

Checking many sites at once

Lists, not tabs.

Paste up to 20 addresses into the Bulk tab and the sites are checked one after another, with a progress bar and a Stop button. A comparison table shows the CMS or store, framework, hosting and CDN, analytics and ads, and email for each site. Export CSV writes one row per technology per site with category, version, confidence and evidence, which filters neatly in a spreadsheet.

For prospecting, paste a list exported from a CRM or a trade directory, run it, and sort the CSV by technology. Every store on an old Magento version, every WordPress site without a cookie consent tool, or every company still on a basic host becomes a short list in a few minutes. Keep the export date in the file name, because stacks change: a site that switches CMS or email provider next quarter will read differently, and a dated file tells you how fresh the evidence is.

Mistakes that mislead a stack readout

Most wrong conclusions come from reading one match too literally.

  • Treating a medium match on a blog post as proof. The article may only mention the tool.
  • Reading an empty result as no stack. Sites behind strict firewalls or custom builds can hide every marker.
  • Assuming the homepage shows every plugin. WordPress plugins that load nothing on the homepage stay invisible, so test a product or blog page too.
  • Confusing the CDN with the host. Cloudflare in front says nothing about the server behind it.
  • Quoting versions as current. They are what the page exposes today, and updates can land tomorrow.

Tech Stack Detector vs related tools

Use the detector for a fast, evidence-backed read of one site or a short list. Pair it with the Website Font Detector and Website Color Extractor for a design teardown, the Logo Extractor for the brand mark, and the HTTP Header Checker and DNS Lookup when you want the raw records. For market-wide lead lists and history, paid databases such as BuiltWith go further.

Try it now

Open Tech Stack Detector

The tool is one click away. No sign up, no upload, no payment.

Open Tech Stack Detector