How detection works
We look for known signatures in headers (Server, X-Powered-By), typical cookies, and path or script patterns in the public HTML, with no need for server access.
Detection from visible signals only
Only what is externally visible gets detected. A well-configured site can hide several of these signals without that implying a problem.