What a site runs on, and when it changed.

Type a domain. You get the technologies we can honestly see from one request, each finding with the exact line of evidence it came from, and the log of every change we have recorded for that domain since the day we first measured it.

20 checks a day, no account, no e-mail. Every finding comes with its evidence.

Free
Twenty live checks a day per visitor, with the full evidence list and all thirteen hygiene checks. Nothing is held back for a paid tier.
Paid
API packs, paid once, credits valid 24 months, no subscription and no card kept on file. They open when the service goes live.
Coverage
The live check works for any public domain in the world. The statistics cover .sk and .cz only, and the pages say why.
Data
No registrant names, no e-mail addresses, no contact lists. Not in version two either.

One request, five reads

We open one HTTPS connection to the homepage and read everything from it at once. No headless browser, no second handshake, no probing of admin paths.

  1. DNSA, AAAA, CNAME, NS, MX and TXT over DNS over HTTPS
  2. TLSissuer, validity, key type and ALPN from the peer certificate
  3. HeadersServer, X-Powered-By, Set-Cookie, Alt-Svc, cache and security headers
  4. HTMLmeta tags, script URLs, file paths, JSON-LD, markup markers
  5. Resulta finding, a confidence level, and the exact line it came from

Recent changes

Every change we record across the .sk and .cz panel lands here first. Domain, date, what changed. Nothing about a person.

Nothing here yet. The survey has not run, so this ledger is empty on purpose: it fills with measured changes or it stays empty.

What we report

Twelve categories, each with the signal types we read for it. A finding without its signal is not a finding.

  • Content managementmeta tag, file path, response header, cookie name
  • E-commerce platformfile path, response header, cookie name, script URL
  • Server side languageresponse header, cookie name, file path
  • JavaScript frameworkscript URL, markup marker, version banner
  • CSS frameworkstylesheet or class, script URL
  • Web serverresponse header
  • CDN and reverse proxyDNS record, response header
  • Hosting providerIP allocation (ASN)
  • DNS providerDNS record
  • E-mail providerDNS record
  • Certificate authoritycertificate field
  • Analyticsscript URL, markup marker

What we cannot do

  • We read one homepage. Not subpages, not subdomains.
  • We do not execute JavaScript, so anything rendered only in the browser or behind a login is invisible to us.
  • Behind a CDN that rewrites the headers we often cannot see the origin, and we say so instead of guessing.
  • HTTP/3 is reported as advertised, because we read Alt-Svc and do not open a QUIC connection.
  • Server country is the country of the IP allocation, not proof of where the machine stands.
  • History starts the day we first measure a domain. We never backfill.

How we measure, and where we are wrongStacklogBot

Questions

Is it really free?

Twenty live checks a day, no account and no e-mail address, with the full evidence list and all thirteen hygiene checks. Repeats of a result we already have, the statistics pages and the catalogue do not count against that. A check that fails, is refused or is blocked by robots.txt does not count either.

How do you know what a site runs on?

From signals the site itself sends: response headers, cookie names, meta tags, file paths, script URLs, markup markers, DNS records and the TLS certificate. Every finding is shown with the exact line it came from and one of four confidence levels: certain, likely, hint or implied. You never have to take our word for it.

Do you store anything about me or about the site owner?

No registrant data, no e-mail addresses, no contact details, ever. That is a permanent rule, not a version one limit. For rate limiting we keep a salted hash of the IP address with the salt rotated daily, so yesterday cannot be linked to today. Raw visitor IP addresses are never written down.

Why are the statistics only for .sk and .cz?

Because that is where we can afford a panel big enough to mean something. The global tools round Slovakia and Czechia to a fraction of a percent. The live check is global from day one; the aggregates are not, and pretending otherwise would be the dishonesty we built this against.

Do you respect robots.txt?

Yes, and not as a courtesy. Obeying it is the legal basis for measuring public pages under the text and data mining exception, so StacklogBot fetches robots.txt first, caches it for 24 hours, honours Crawl-delay and stops when it is told to. One e-mail also removes a domain within 24 hours.

Sources and licences

  • webappanalyzerGPL-3.0

    The open ruleset for international technologies. We pin one release and keep it on our own volume. github.com/enthec/webappanalyzer

  • Public Suffix ListMPL 2.0

    Mozilla snapshot, pinned. It decides what a registrable domain is, with no network call. publicsuffix.org

  • iptoasn.comPDDL 1.0

    The IP to ASN dump behind the hosting provider and the country of the IP allocation. Refreshed daily. iptoasn.com

  • CZ.NIC open dataCC BY 3.0 CZ

    The .cz population we draw the panel from. Attributed here and in SOURCES.md. stats.nic.cz

  • SK-NIC domains.txtopen question

    The daily .sk register file. Its licence is not stated on the page, so the operator must settle it before the first survey run. Until then the .sk panel is not drawn. sk-nic.sk/subory/domains.txt

  • Cloudflare RadarCC BY-NC 4.0

    Non commercial only, so it never enters this product. Internal reading at most. radar.cloudflare.com

  • RIPEstatno redistribution

    Its terms forbid redistribution and commercial use. Excluded for the same reason. stat.ripe.net

StatisticsComparisonsAPI