Tech stack & vulnerabilities:What is this website built with, and is any of it vulnerable?
Detect the CMS, frameworks, libraries, analytics, CDN and server behind any page, with versions, and see which library versions have public security advisories.
- Free, no account
- Results in under a minute
- 80+ technologies, advisories from OSV
example-shop.hr
WordPress 6.8Sample shop · homepage · mobile Chrome · the same check you get for your own site
3 passed · 0 failed · 1 warning. Biggest issue: 1 JavaScript library has known security holes.
Detected technology
- WordPress 6.8
- WooCommerce
- Elementor
- jQuery 1.12.4
- LiteSpeed
Known vulnerabilities
from OSV.dev, newest data dailyjQuery 1.12.4npm package jquery
- mediumCVE-2015-9251Cross-Site Scripting in jqueryfixed in 3.0.0
- mediumCVE-2019-11358XSS in jQuery as used in Drupal, Backdrop CMS, and other productsfixed in 3.4.0
- mediumCVE-2020-11022Potential XSS vulnerability in jQueryfixed in 3.5.0
- mediumCVE-2020-11023Potential XSS vulnerability in jQueryfixed in 3.5.0
Content and shop
3 found| Technology | Version | Evidence | Advisories |
|---|---|---|---|
| WordPress | 6.8 | meta generator "WordPress 6.8" | not checked |
| WooCommerce | — | script http://example-shop.hr/assets/style.css?woocommerce=1 | not checked |
| Elementor | — | html elementor class or asset | not checked |
Frameworks and libraries
1 found| Technology | Version | Evidence | Advisories |
|---|---|---|---|
| jQuery | 1.12.4 | window.jQuery | 4 known |
Delivery and hosting
1 found| Technology | Version | Evidence | Advisories |
|---|---|---|---|
| LiteSpeed | — | header server: LiteSpeed | not checked |
What we found
Show 3 passed checks
Fix these first
From the example above. Check your own site to get the fixes that apply to it.
Warning: 1 JavaScript library has known security holes
Old library versions have published attacks that anyone can copy, most often cross-site scripting.
How to fix it: Update each library to at least the fixed version in the technical detail; on WordPress, update the theme and plugins that bundle it.
What this tool checks
Detection from the rendered page, its headers and scripts, matched against public advisories.
Vulnerable JavaScript libraries
Matches library versions such as jQuery, Bootstrap and Lodash against public security advisories.
Technology stack
Lists the CMS, framework, CDN and analytics behind the page, so you know which settings to use.
CMS version
Compares the CMS version your page reveals with the latest release, since old versions have known holes.
Plugins closed on wordpress.org
Flags detected plugins that wordpress.org has closed, often because of a security issue.
Abandoned plugins
Flags detected plugins with no update in over 2 years, which no longer get security fixes.
Server version in headers
Checks the Server header doesn't reveal the software version that automated scanners look for.
X-Powered-By header
Checks the site doesn't announce its programming language and version to anyone who asks.
CDN in front of the site
Checks for a CDN, which serves files from near each visitor and absorbs traffic spikes.
Show 4 more checks
Abandoned plugins
Flags detected plugins with no update in over 2 years, which no longer get security fixes.
Server version in headers
Checks the Server header doesn't reveal the software version that automated scanners look for.
X-Powered-By header
Checks the site doesn't announce its programming language and version to anyone who asks.
CDN in front of the site
Checks for a CDN, which serves files from near each visitor and absorbs traffic spikes.
How it works
Load the page in Chromium
The page runs in a real browser, so technology loaded by scripts counts too. We read the HTML, headers, cookies, script URLs and the library objects the page exposes, with their versions.
Name what we find
More than 80 signatures cover content systems, shop platforms, frameworks, libraries, analytics, tag managers, consent platforms, CDNs and web servers. Each finding shows the evidence behind it.
Check for advisories
Every library with a known version is matched against OSV.dev, the open vulnerability database that includes the GitHub advisories, and each advisory links to its source.
We only name what the page reveals, and only check versions we can read for certain. Server software and WordPress plugins are covered by their own checks; server-side code and anything behind a login are out of reach.
Questions
Is this really free?
Yes. getReport is funded by donations, not plans. The vulnerability data comes from OSV.dev, a free and open database, so there is nothing to pay for on either side.
How accurate is the detection?
Each technology comes with the evidence we matched (a meta generator tag, a script URL, a response header or a JavaScript object) and a confidence. Detection is passive: we never probe paths or guess, so a technology the page does not reveal is not listed. Versions come from the library itself where it exposes one (jQuery, Lodash, Moment.js, AngularJS, Bootstrap 5) or from a versioned script URL; when neither exists, we name the library without a version and do not look up advisories, rather than guess.
A library has advisories. Is my site hacked?
No. It means the version has publicly known weaknesses that an attacker could use, often only in particular circumstances. Update to the fixed version shown, then check again.
Why is my WordPress plugin not listed?
WordPress plugins are detected by the WordPress plugin detector, which also warns about closed and abandoned plugins using the wordpress.org directory.
Do you store my results?
The report is kept for 12 months at its shareable link so you can come back to it. Reports are not listed publicly and carry a noindex tag.
Related free tools
All 41 tools →Free, funded by the people who use it
€0 of €75 this month. At €75, site crawl up to 500 pages + weekly re-check switches on for everyone.