What CMS Is a Website Using? 7 Ways to Find Out
- Post By: FAISAL MUSTAFA
- Published: August 18, 2024

The quickest way to see what CMS a website is using is to paste its address into a free checker such as WhatCMS.org or Wappalyzer's lookup. If you'd rather check it yourself, open the page source (Ctrl+U on Windows, Cmd+Option+U on a Mac) and search for generator, wp-content or cdn.shopify.com. Most sites give themselves away in under a minute.
That covers the majority of websites. The rest are built on headless or custom systems, hide their tags, or run different platforms on different parts of the site, and those are the cases where a checker returns "unknown" or the wrong name. This guide walks through seven methods that handle both situations, a fingerprint table for the platforms you're most likely to meet, and what to do when nothing matches.
The Quick Check (Under Two Minutes)
- Run the URL through a free CMS checker. If it names a platform, skip to step 3.
- If it finds nothing, open the page source, search for generator, then search for the paths and domains in the fingerprint table below.
- Confirm with a second signal, such as a login page, a response header or an asset domain. One clue can mislead. Two clues that agree rarely do.
What a CMS Is, and Which Ones You'll Usually Find
A content management system (CMS) is software that lets people create, edit and publish website content from a dashboard instead of editing code files. Some are installed on your own hosting, such as WordPress, Joomla and Drupal. Others are hosted platforms where the CMS, hosting and templates come as one service, such as Shopify, Wix, Squarespace and Webflow. A third group, headless CMSs, store content and send it to a separately built front end through an API.
Each type leaves different traces, which is why knowing the categories makes identification easier. It also helps to know the odds before you start. According to W3Techs usage data for 29 September 2026, the most common systems are:
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The same survey finds that 31.5% of websites use none of the content management systems W3Techs monitors. Some of those are hand-coded, but many run custom or headless setups that simply don't advertise what they are. Keep that figure in mind when a checker comes back empty. It usually isn't the tool failing.
Method 1: Use a Free Online CMS Checker
Online checkers fetch the page, compare its code, headers and files against a library of known signatures, and report the closest match. For a one-off check, they're the right place to start.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
A checker only looks at the address you give it. If a company runs its blog on WordPress and its store on Shopify, check both. And when two tools disagree, trust the one that shows its evidence, then confirm it with Method 3.
Method 2: Install a Browser Extension
If you look up websites often, a browser extension saves the copy-and-paste step. Wappalyzer and BuiltWith both offer extensions for Chrome and Firefox. Click the icon on any page and you'll see the CMS, framework, analytics, ecommerce platform and other technology detected on the page you're viewing.
Extensions can only see what your browser receives. They're very reliable for WordPress, Shopify and the major website builders, and less reliable on headless sites, where the CMS never talks to the visitor's browser at all. If an extension lists a framework such as Next.js or Nuxt but no CMS, treat that as a clue rather than a dead end. The section on unknown results below explains what to look for next.
Method 3: View the Page Source and Look for Fingerprints
This is the method every checker automates, and once you know what to search for it takes about a minute.
- Open the site in a desktop browser. Check an inner page, such as a blog post or product page, as well as the home page, because home pages are sometimes built separately.
- Press Ctrl+U (Windows and Linux) or Cmd+Option+U (Mac) to open the source. On a phone, paste the URL into VISER X's Get Source Code of Webpage tool instead.
- Press Ctrl+F or Cmd+F and search for generator. Many platforms add a line such as <meta name="generator" content="WordPress ..."> that names the CMS and sometimes its version.
- If there's no generator tag, search for the paths and domains in the table below.
- Confirm your finding with the second signal listed for that platform.
The generator tag is a strong clue but not proof. Security plugins and careful developers often remove it, and a site that has moved platforms can leave old references behind.
CMS Fingerprint Table
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The last row is where most "unknown" results come from. Our own site is a good example: viserx.com loads its scripts and images from /_next/ paths and serves blog images from api.viserx.com. A checker will correctly report Next.js as the framework, but you won't find a classic CMS fingerprint, because the content is managed separately and delivered through an API.
Method 4: Check Login Pages, robots.txt and Sitemaps
Most self-hosted systems keep their admin login at a predictable address. Add these to the end of the domain and see what loads:
- WordPress: /wp-admin/ or /wp-login.php
- Joomla: /administrator/
- Drupal: /user/login
- Ghost: /ghost/
- Shopify: /admin redirects to a Shopify sign-in page
- Squarespace: /config leads to a Squarespace login
Only look at the page that loads. Don't try to sign in, and don't run tools that guess passwords or probe for hidden folders on a site you don't own. Many sites rename these paths for security, so a "page not found" result doesn't rule anything out.
Two public files are also worth a look. The robots.txt file (yourdomain.com/robots.txt) often lists system folders: WordPress sites commonly block /wp-admin/, Drupal sites list /core/ and /modules/, and Adobe Commerce stores tend to have a long list of system directories. Sitemap addresses help too. /wp-sitemap.xml is WordPress's built-in sitemap, and /sitemap_index.xml often points to a WordPress SEO plugin such as Yoast or Rank Math.
You may see advice to look for files like wp-config.php or configuration.php. Those files exist on WordPress and Joomla sites, but the server runs them rather than displaying them, so a visitor can't use them to identify anything.
Method 5: Read the Response Headers and Cookies
Headers are the information a server sends along with each page. You can read them in any desktop browser:
- Open DevTools with F12 (or Cmd+Option+I on a Mac) and select the Network tab.
- Reload the page and click the first request in the list, which is the page itself.
- Open the Headers section and scroll to the response headers.
Look for X-Generator (Drupal usually names itself here), x-wix-request-id (Wix) and headers beginning with x-shopify or x-shopid (Shopify). The X-Powered-By header often shows only PHP or a framework, which narrows the options without answering the question. The Server header tells you which web server or CDN delivered the page, not which system built it.
Cookies can add another clue. In DevTools, open the Application tab (Storage in Firefox) and look under Cookies. Drupal session cookies start with SESS or SSESS, and Adobe Commerce stores set cookies such as mage-cache-sessid. WordPress mostly sets its wordpress_ and wp- cookies after someone logs in or comments, so their absence proves very little.
If the site sits behind a CDN such as Cloudflare, some original headers may be replaced, which is one more reason to combine this method with Method 3.
Method 6: Look at URL Patterns and the Footer
URL structures can hint at the platform when nothing else does:
- WordPress default links look like /?p=123, with category archives under /category/
- Drupal content often lives at /node/123
- Joomla URLs may include index.php?option=com_content
- Shopify stores use /products/, /collections/ and /pages/
- Ghost blogs use /tag/ for topic archives
Most sites customize their URLs, so treat these as supporting evidence. The footer is also worth a glance. Smaller sites often keep a "Powered by WordPress" or "Powered by Shopify" line or a theme credit, though business sites usually remove it.
Method 7: Use a Command-Line Scanner
If you need to check many sites or want more detail, command-line tools can help. WhatWeb is an open-source scanner that identifies CMSs, frameworks and server software, and its default mode sends a single request per URL. CMSmap is built for security testing and can report CMS versions and known weaknesses. Use security-focused or aggressive scans only on sites you own or have written permission to test.
Methods That Won't Tell You the CMS
A few techniques come up in older guides but don't identify a CMS:
- Reverse IP lookup. It shows other domains that share a server's IP address. That's useful for hosting research, and our Reverse IP Domain Checker does exactly that, but hosting companies don't assign IP ranges by CMS. One server can run WordPress, Joomla and plain HTML sites side by side.
- Hosting lookups. A Domain Hosting Checker tells you who hosts a site, not what built it. The exception is hosted platforms: if a site is served by Shopify, Wix or Squarespace infrastructure, that's a strong clue in itself.
- WHOIS records. These show domain registration details, not software.
Why a CMS Checker Says "Unknown" (or Gets It Wrong)
When a tool can't name a CMS, one of these is usually the reason:
- The site uses a headless CMS. Content lives in a separate system and reaches the site through an API, so visitors only see the front end, often built with Next.js, Nuxt, Gatsby or Astro. Checkers report the framework. Search the source for content or image domains such as ctfassets.net, cdn.sanity.io or storyblok.com to find the CMS behind it.
- The CMS is custom-built. Many larger companies and agencies build their own. There's no public signature to match.
- The clues have been removed. Security plugins strip generator tags, rename login URLs and hide version numbers.
- A CDN or cache is in the way. Services like Cloudflare can serve cached pages and replace server headers.
- It's a static site. Generators such as Hugo, Jekyll and Eleventy output plain HTML. Some leave a generator tag, many don't, and there may be no CMS at all.
- Different sections run different systems. A shop subdomain on Shopify, a blog on WordPress and a custom main site is a common pattern. Check each section separately.
- Old signals survived a migration. Image paths like /wp-content/uploads/ can outlive a move to a new platform, so an outdated clue points to the previous CMS. Confirm with a live signal such as a header or login page.
If three methods turn up nothing, the honest answer is often that the site is custom or headless. At that point the framework, hosting and content domains tell you more about how it's built than a CMS name would.
How to Find Out What CMS Your Own Website Uses
It happens more often than you'd think. A previous developer or agency built the site, and nobody on the current team knows what it runs on. You can usually find out in a few minutes:
- Think about how you edit pages. If you log in at a /wp-admin address, it's WordPress. If you sign in at shopify.com, wix.com, squarespace.com or webflow.com, that's your platform.
- Check your email and billing. Subscription invoices from hosted platforms name the service.
- Look in your hosting control panel. On cPanel-style hosting, app installers such as Softaculous list installed applications, and the file manager will show folders like wp-content or administrator.
- Run the checks in this guide on your own domain. Methods 1 and 3 are enough in most cases.
- Ask whoever built or maintains the site. Request admin access and any documentation at the same time. A business website with no known owner and no admin login is worth fixing before any redesign.
Knowing your platform matters for security updates, for scoping a redesign or migration, and for hiring a developer with the right skills.
What to Do With the Answer
Once you know the platform, the useful part begins:
- Competitor research. Seeing what leading sites in your market use shows you what's workable. It doesn't tell you what's right for your budget or team.
- Migration and redesign planning. Moving from Wix to WordPress is a very different project from switching WordPress themes, and an accurate starting point makes estimates more realistic.
- Security checks. If a generator tag on your own site shows an old CMS version, that's a prompt to update.
- Choosing your own platform. If this research is feeding a decision, our guides to the best CMS for SEO and custom CMS vs WordPress vs headless go further.
How VISER X Can Help With Your CMS Decision
VISER X has spent 14 years building and optimizing websites for businesses in Bangladesh and abroad, on WordPress, headless and custom CMS setups. If you're not sure what your current site runs on, or whether it's still the right platform for where the business is going, our team can review the setup and recommend a path, whether that means staying put, cleaning up or migrating. Explore our web design and development services, or if the site simply needs to stay secure and up to date, our website maintenance service.
Frequently Asked Questions
Can I check what CMS a website uses for free?
Yes. WhatCMS.org, Wappalyzer and BuiltWith all offer free lookups, and viewing a page's source code costs nothing. For most WordPress, Shopify, Wix and Squarespace sites, a free check is all you need.
Why do two CMS checkers give different answers?
Each tool uses its own signature library and weighs clues differently. One might pick up a leftover path from a previous CMS while another reads a current header. Confirm the result with two independent signals from Methods 3 to 5.
Can I see which WordPress theme and plugins a site uses?
Often, yes. In the page source, theme files load from /wp-content/themes/theme-name/ and plugin files from /wp-content/plugins/plugin-name/. The theme's style.css file usually lists its name and author at the top. Plugins that load nothing on the front end won't appear, so any list you build will be partial.
Is it OK to check what CMS a website is using?
Viewing a page's source code, headers and public files uses the same information your browser already downloads to display the page. The line is anything beyond that: trying to log in, guessing hidden paths at scale, or running security scanners against a site without permission.
What is the most used CMS?
WordPress, by a wide margin. W3Techs data from 29 September 2026 puts it at 40.2% of all websites and 58.7% of sites with a detected CMS. Shopify and Wix follow at 5.4% and 4.2% of all websites.
Does every website use a CMS?
No. Small sites with a few pages that rarely change can be plain HTML, and many large sites run custom or headless systems that W3Techs can't classify. Its survey finds that 31.5% of websites use none of the systems it tracks. A CMS becomes worth it once several people need to publish or update content regularly without touching code
