What Is The What
I've been using What Is The What for about three years now, mostly on projects where I needed quick website technology detection without building my own pipeline. It's a free tool that identifies the technologies a website runs on — CMS, analytics, web frameworks, CDNs, email providers, the usual stack markers. You drop a URL in and get back a breakdown of what's powering it. The service doesn't do anything fancy on the backend that isn't public knowledge. It hits the target site, scans the HTML source, response headers, JavaScript imports, and often makes requests to well-known asset paths like /wp-content/themes/ or /js/vendor/. Then it matches patterns against a database of known technology signatures. That database is updated regularly — which matters because a site might use an old version of React, and the tool can usually tell you the version number too. I started with it casually, just currying data for competitor research. Then I hit a case where a client insisted their site was hosted on AWS when the tech detection clearly showed a Pantheon infrastructure setup. Turns out the DNS was managed through Route53, which fooled a lot of people including the client's previous developer. What Is The What picked up the CDN headers and SSL cert info that pointed to the real host. That was useful.
Getting started with it
You don't need an account for basic lookups. Go to the site, paste a URL, and wait a couple seconds. The free tier gives you enough for light research — maybe 20-30 scans a day before you start seeing rate limits. If you're doing this repeatedly for work, the paid plans kick in at reasonable pricing, and they include API access which is where the real time savings happen. The API returns JSON, which means you can script it into a scraper, a CI/CD pipeline, or a content audit workflow. I wired mine up to a simple bash loop that checks our internal site list every morning against a known tech stack baseline. Anything that changed — new analytics vendor, switched payment processor, migrated to a different framework — triggers an alert so our team isn't caught off guard during updates.
Things the documentation doesn't emphasize
One issue beginners run into is false negatives on heavily JavaScript-rendered sites. If a technology's signature lives in a dynamically loaded bundle, What Is The What might miss it on the initial crawl. I learned this the hard way when a site showed zero ecommerce platform detection even though it was clearly running Shopify. The trick is to use the "fetch full page" option if available, or manually append query parameters that force the JS to execute. Browser-based rendering gives more complete results but usually costs API credits faster. Another thing nobody talks about is the version detection accuracy. It's decent for major releases but notoriously unreliable for minor patches. If a site runs Next.js 14.1.3 and the tool reports Next.js 14.x, that's normal. Don't treat version numbers as definitive — treat them as directional guidance. I once spent a day debugging a deployment issue because I assumed the detected version matched exactly. It didn't.
Get the Full Details

When it falls apart
Custom-built stacks are where this tool struggles. If a company writes their own analytics pixel and names it something that doesn't match known signatures, it won't show up. Same with private CDNs that don't use recognizable headers. I worked on a project last year where the client had a fully custom identity management system and the tool reported "unknown auth provider" across three separate domains. In those cases you need to fall back to manual inspection — check the network tab in DevTools, look at cookie domains, read the minified JS for identifiable function names. It also doesn't handle intranet or behind-login-wall sites. The crawlers can't get past authentication, so any tech detection for internal tools or member-only dashboards will come back empty. I had a situation where a SaaS product's public landing page showed everything correctly but the actual product UI — which used a completely different stack — was invisible to the tool. Two completely separate technology profiles for what looked like one product.
Alternatives worth knowing about
If you need deeper historical data — like what a site was running six months ago — What Is The What doesn't really offer that. BuiltWith has better archival capabilities. Wappalyzer, the browser extension version, is good for real-time spot checks but the free tier has scan limits. For a one-off lookup, What Is The What is fast and accurate enough. For ongoing competitive intelligence at scale, you'd probably want to combine it with another service rather than relying on a single data source. I use it as a first pass and then validate with Wappalyzer when the stakes are high. The two sometimes disagree on things like server-side frameworks, and when they do, checking the response headers directly usually settles it within five minutes. Not something I'd call a workflow, but it works when you need to be sure.