How detection works

We look for known signatures in headers (Server, X-Powered-By), typical cookies, and path or script patterns in the public HTML, with no need for server access.

Detection from visible signals only

Only what is externally visible gets detected. A well-configured site can hide several of these signals without that implying a problem.