Short answer: enter a URL. The result names the CMS or site builder, framework, host or CDN, analytics and common tools the site gives away, and shows what we saw for each one.
How detection works
We look for what a site can’t easily hide, in four places:
- Response headers, such as
server,x-powered-by,cf-rayandx-vercel-id. - Cookie names the response sets, for example Shopify’s
_shopify_y. - Generator tags in the HTML, where WordPress, Ghost, Hugo, Astro and Gatsby put their name and often their version.
- Files the page loads and markers in its code:
/wp-content/,cdn.shopify.com,framerusercontent.com,__NEXT_DATA__, analytics and chat scripts.
How to read a detection
High confidence means a signal only that technology produces, or two good ones. Medium is one signal that nearly always means it. Version numbers are what the site says about itself. This is a heuristic: sites can remove generator tags and fake headers, so a missing technology proves nothing, and a headless setup (a Next.js front end on a WordPress back end) may show only the front end.
Cloudflare in the list tells you a site sits behind that CDN, not where its server is. A Universal Analytics tag is flagged as retired because Google stopped processing Universal Analytics data on July 1, 2023; a site that still carries only that tag isn’t collecting data in Google Analytics.
If your site is on one of these platforms
When the site runs on WordPress, Webflow, Shopify, Framer, Wix, Ghost or Notion, AI SEO Autopilot publishes to it directly. Next.js sites can use our hosted blog or a GitHub pull request per article, and Markdown or MDX sites such as Astro, Hugo, Jekyll and Gatsby can use the pull request too. Anything else gets a signed webhook, or you download each article as Markdown or HTML. The result says which applies to the site you checked.
Want every header the server sent? Use the HTTP header checker. To see the security headers graded, use the security headers checker.