Prismic Page Audit Free online audit tool
Home › All tools › Website CMS checker

Website CMS checker

The content management system decides what editors can change and what stays locked in templates or code. Judging which CMS a public site runs on means reading structural evidence — path prefixes, response headers, asset hosts — not hunting for a brand name inside marketing copy. A documentation page that mentions several vendors is not the same thing as a live install. This hub explains the outside signals, lists every CMS detector on this site, and separates a keyword hit from a confirmed stack.

How a CMS can be identified from the outside

Proprietary resource paths. Installs leave folders and URL prefixes that almost never appear on unrelated stacks. Examples include /wp-content/ for classic PHP blogs, /cdn.sanity.io for structured headless assets, and similar prefixes tied to one vendor's media pipeline. When those paths show up as real script, stylesheet or image URLs — not only as plain text in an article — they are strong structure.

Response headers and generator tags. Some platforms still emit x-powered-by values or a meta generator string that names the publishing engine and often a version. Headers can be stripped by a reverse proxy, so absence proves nothing; presence is one more structural vote when it agrees with path and host evidence.

Branded domains and API hosts. Media and API traffic often rides vendor hostnames such as images.prismic.io or cdn.shopify.com. Those hosts appear in src and href attributes of resources the browser must fetch. A blog post that merely discusses the same hostname is weaker than an actual resource request on the page you opened.

Page structure and draft or preview endpoints. Slice markup, data attributes, preview query parameters and draft toolbar scripts can reveal a CMS even when marketing copy never says the product name. Preview endpoints that leak into production are especially telling because they are part of the editing workflow, not something a competitor article would invent on someone else's domain.

Thirteen CMS detectors on this site

Each card below opens a dedicated checker. Paste a URL there to see match counts and the exact evidence strings. The roster covers every CMS checker shipped here today — headless, classic PHP, and hosted builders alike.

Why a keyword hit is not a confirmation

Brand strings appear in places that have nothing to do with the live stack. Vendor documentation sites discuss many products on one page. Job posts list tools the team hopes to hire for. Comparison articles name every platform in a category. In those cases a plain-text keyword can fire while no proprietary path, header or asset host is present.

This site therefore distinguishes suspected from confirmed. A suspected label means the brand token appeared without structural backing. A confirmed label means at least one structural pattern matched — a path, header, host or markup shape that ordinary prose does not produce. Prefer under-reporting over claiming an install that is only mentioned in copy.

What usually needs fixing once the CMS is known

Image pipelines. Most CMS installs resize or transform media through a vendor URL grammar. Oversized heroes, missing width and height, and transforms that still ship multi-megabyte files are common once you know which pipeline is in play.

Fonts and scripts. Themes and slices often pull webfonts and widgets from third party hosts. Knowing the CMS tells you whether those tags live in a theme file, a slice, a tag manager, or a site-builder app panel.

Caching and rendering strategy. Headless setups lean on CDN caching of API JSON and HTML shells; classic PHP stacks lean on page caches and object caches; hosted builders expose fewer knobs. The CMS category narrows which of those levers actually exist before anyone starts changing code.

Start from the detector that matches the strongest structural clue you already see. If nothing is obvious, pick any CMS checker below and read the evidence list — a miss with a clear “likely” note is still useful, because it tells you the brand appeared without an install signature.

Going further

If this build is yours, three things usually explain the score: media that enters the CMS without dimensions, slices that re-render the same block, and fonts loaded from a third-party host.

If you would rather hand these fixes over, the contact page lists what I take on.

→ Contact