Skip to content

Tech stack & vulnerabilities:What is this website built with, and is any of it vulnerable?

Detect the CMS, frameworks, libraries, analytics, CDN and server behind any page, with versions, and see which library versions have public security advisories.

  • Free, no account
  • Results in under a minute
  • 80+ technologies, advisories from OSV
Example result

example-shop.hr

WordPress 6.8

Sample shop · homepage · mobile Chrome · the same check you get for your own site

Run it on your site
Best practices

3 passed · 0 failed · 1 warning. Biggest issue: 1 JavaScript library has known security holes.

Detected technology

  • WordPress 6.8
  • WooCommerce
  • Elementor
  • jQuery 1.12.4
  • LiteSpeed
5 technologies detected1 of 1 versioned library has advisories

Known vulnerabilities

from OSV.dev, newest data daily

jQuery 1.12.4npm package jquery

  • mediumCVE-2015-9251Cross-Site Scripting in jqueryfixed in 3.0.0
  • mediumCVE-2019-11358XSS in jQuery as used in Drupal, Backdrop CMS, and other productsfixed in 3.4.0
  • mediumCVE-2020-11022Potential XSS vulnerability in jQueryfixed in 3.5.0
  • mediumCVE-2020-11023Potential XSS vulnerability in jQueryfixed in 3.5.0

Content and shop

3 found
Content and shop: each technology with its version and the evidence we matched
TechnologyVersionEvidenceAdvisories
WordPress6.8meta generator "WordPress 6.8"not checked
WooCommerce—script http://example-shop.hr/assets/style.css?woocommerce=1not checked
Elementor—html elementor class or assetnot checked

Frameworks and libraries

1 found
Frameworks and libraries: each technology with its version and the evidence we matched
TechnologyVersionEvidenceAdvisories
jQuery1.12.4window.jQuery4 known

Delivery and hosting

1 found
Delivery and hosting: each technology with its version and the evidence we matched
TechnologyVersionEvidenceAdvisories
LiteSpeed—header server: LiteSpeednot checked

What we found

0 failed1 warning2 to note3 passed
Show 3 passed checks

Fix these first

From the example above. Check your own site to get the fixes that apply to it.

  1. Warning: 1 JavaScript library has known security holes

    Old library versions have published attacks that anyone can copy, most often cross-site scripting.

    How to fix it: Update each library to at least the fixed version in the technical detail; on WordPress, update the theme and plugins that bundle it.

What this tool checks

Detection from the rendered page, its headers and scripts, matched against public advisories.

  • Vulnerable JavaScript libraries

    Matches library versions such as jQuery, Bootstrap and Lodash against public security advisories.

  • Technology stack

    Lists the CMS, framework, CDN and analytics behind the page, so you know which settings to use.

  • CMS version

    Compares the CMS version your page reveals with the latest release, since old versions have known holes.

  • Plugins closed on wordpress.org

    Flags detected plugins that wordpress.org has closed, often because of a security issue.

  • Abandoned plugins

    Flags detected plugins with no update in over 2 years, which no longer get security fixes.

  • Server version in headers

    Checks the Server header doesn't reveal the software version that automated scanners look for.

  • X-Powered-By header

    Checks the site doesn't announce its programming language and version to anyone who asks.

  • CDN in front of the site

    Checks for a CDN, which serves files from near each visitor and absorbs traffic spikes.

Show 4 more checks
  • Abandoned plugins

    Flags detected plugins with no update in over 2 years, which no longer get security fixes.

  • Server version in headers

    Checks the Server header doesn't reveal the software version that automated scanners look for.

  • X-Powered-By header

    Checks the site doesn't announce its programming language and version to anyone who asks.

  • CDN in front of the site

    Checks for a CDN, which serves files from near each visitor and absorbs traffic spikes.

How it works

  1. Load the page in Chromium

    The page runs in a real browser, so technology loaded by scripts counts too. We read the HTML, headers, cookies, script URLs and the library objects the page exposes, with their versions.

  2. Name what we find

    More than 80 signatures cover content systems, shop platforms, frameworks, libraries, analytics, tag managers, consent platforms, CDNs and web servers. Each finding shows the evidence behind it.

  3. Check for advisories

    Every library with a known version is matched against OSV.dev, the open vulnerability database that includes the GitHub advisories, and each advisory links to its source.

We only name what the page reveals, and only check versions we can read for certain. Server software and WordPress plugins are covered by their own checks; server-side code and anything behind a login are out of reach.

Questions

Is this really free?

Yes. getReport is funded by donations, not plans. The vulnerability data comes from OSV.dev, a free and open database, so there is nothing to pay for on either side.

How accurate is the detection?

Each technology comes with the evidence we matched (a meta generator tag, a script URL, a response header or a JavaScript object) and a confidence. Detection is passive: we never probe paths or guess, so a technology the page does not reveal is not listed. Versions come from the library itself where it exposes one (jQuery, Lodash, Moment.js, AngularJS, Bootstrap 5) or from a versioned script URL; when neither exists, we name the library without a version and do not look up advisories, rather than guess.

A library has advisories. Is my site hacked?

No. It means the version has publicly known weaknesses that an attacker could use, often only in particular circumstances. Update to the fixed version shown, then check again.

Why is my WordPress plugin not listed?

WordPress plugins are detected by the WordPress plugin detector, which also warns about closed and abandoned plugins using the wordpress.org directory.

Do you store my results?

The report is kept for 12 months at its shareable link so you can come back to it. Reports are not listed publicly and carry a noindex tag.

All 41 tools →

Free, funded by the people who use it

€0 of €75 this month. At €75, site crawl up to 500 pages + weekly re-check switches on for everyone.

Chip in