﻿---
title: "Website technology checker with versions and CVEs"
description: "Free website technology checker. See the JavaScript libraries a page uses, their versions, end-of-life status and known CVEs, then export a CycloneDX SBOM."
url: "https://centralcsp.com/en/tools/tech-checker/"
lang: "en"
---

Tools

# Technology Checker

A free website technology checker. Enter a URL to see the libraries and frameworks the page uses, their versions, where each one comes from, and the known CVEs affecting them.

### Check a URL

We list the libraries and frameworks the page uses and check each version against public vulnerability data.

Check technologies

Only check sites you own or are authorised to assess. Results stay in this tab and are deleted from our servers 30 minutes after the check.

Want to pin a CDN script to the exact file you reviewed? [Generate an SRI hash](https://centralcsp.com/en/tools/sri-hash/)

Guide

## Understanding your technology report

Most of the code a visitor's browser runs on your site was written by someone else: a framework, a UI library, an analytics loader, a payment SDK. This checker lists what a page uses and flags the versions with publicly known vulnerabilities.

### How to check what technology a website uses

Some of it can be read by hand: view the page source, watch the Network tab in your browser's developer tools, or type a library's version variable in the console, such as jQuery.fn.jquery. That answers one question about one library you already suspect. A website technology checker lists the libraries and frameworks a page uses, with their versions, and says which versions are outdated, at end of life, or affected by known CVEs.

### Check the version of a library, like jQuery

Enter the page URL and find the library in the table. Version shows the exact release, Latest in line the newest release of the same line, and Version status whether that line is still maintained. Expand the row to see where it was detected and each known CVE with the version that fixes it. For jQuery in particular, read [which jQuery versions are vulnerable](https://centralcsp.com/en/blog/vulnerable-jquery-version).

### How it compares with Wappalyzer, BuiltWith and Retire.js

Each tool answers a different question. Wappalyzer and BuiltWith identify a site's stack, Retire.js finds vulnerable libraries in files you have or sites you point its scanner at, and this checker starts from a URL and reports versions, end of life and known CVEs together.

What each technology detection tool reports
| Tool | Starts from | Known CVEs | End of life | SBOM export |
| --- | --- | --- | --- | --- |
| CentralCSP Technology Checker | Any public URL | Yes | Yes | CycloneDX, CSV, PDF |
| Wappalyzer | Browser extension or website lookup | No | No | No |
| BuiltWith | Website lookup | No | No | No |
| Retire.js | Local files or a headless site scanner | Yes | No | CycloneDX (command line) |

### What the report shows

For every technology identified on the page:

-   The version in use, or a dash when no version could be read.
-   The version status: up to date, outdated, dormant, or end of life.
-   The latest release in the same line, so you know the smallest upgrade that helps.
-   Where it was detected on the page.
-   The known vulnerabilities affecting that version, with severity, a summary, the version that fixes each one, and links to the advisories.

### How to read a known vulnerability

A listed CVE means the detected version falls in a range a public advisory marks as affected. It does not prove the site is exploitable: the vulnerable function may never be called, and some vendors backport fixes without changing the version number. Start with critical and high findings in scripts that touch forms, sessions or payments, and upgrade to the fixed version shown.

### Why third-party scripts matter

An outdated jQuery or a forgotten widget is an easy way into a page, and a compromised third-party script runs with the same access as your own code. PCI DSS 4.0 requirement 6.3.2 asks for an inventory of the software components you run, third-party scripts included. A one-off check gives you a snapshot; a [continuous script inventory](https://centralcsp.com/en/docs/platform/features/script-inventory) keeps it current from your real visitors' browsers.

### Exports: CSV, CycloneDX and PDF

The CycloneDX 1.6 JSON export is a standard SBOM: each technology is a component with its version, status and origin, and each known vulnerability is linked to the component it affects. The CSV has one row per technology and vulnerability for spreadsheets and tickets. The PDF is a dated report in the same layout as our scanner reports. Results are not stored for sharing, so export before you leave the page.

Keep reading

-   [Script inventory in CentralCSP](https://centralcsp.com/en/docs/platform/features/script-inventory)
-   [Technologies, versions and CVEs in CentralCSP](https://centralcsp.com/en/docs/platform/features/technologies)
-   [Detect vulnerable JavaScript libraries](https://centralcsp.com/en/blog/detect-vulnerable-javascript-libraries)
-   [Is your jQuery version vulnerable?](https://centralcsp.com/en/blog/vulnerable-jquery-version)
-   [How to detect a client-side skimmer](https://centralcsp.com/en/blog/magecart-formjacking-detection)

More free tools

## Keep auditing with the other free tools

Every tool is free, runs without an account, and scores with the same severity scale.

### SRI hash generator

Turn a CDN script or stylesheet URL into its Subresource Integrity hash, with a ready-to-paste tag and a CORS check.

-   SHA-256, 384 and 512
-   CORS verified for you

[Generate an SRI hash](https://centralcsp.com/en/tools/sri-hash/)

### CSP scanner

Fetch a URL's live Content-Security-Policy and score it against known bypasses, wildcard sources and missing directives.

-   Directive-level findings
-   Shareable results link

[Run the CSP scanner](https://centralcsp.com/en/tools/csp-scanner/)

### Security headers scanner

Grade every security header a URL sends, from HSTS to Permissions-Policy, with each finding explained and prioritized.

-   Every header, one grade
-   Fix list ordered by impact

[Scan your security headers](https://centralcsp.com/en/tools/security-headers/)

### Website compare

See where your score stands: your site beside the dataset average and the year's best-configured sites, control by control.

-   Published, auditable references
-   Radar view per category

[Compare your site to the best](https://centralcsp.com/en/tools/compare/)

FAQ

## Frequently asked questions

Versions, CVEs, end of life and SBOM exports, answered.

### How do I find out which JavaScript libraries a website uses?

Enter the page URL in the checker above. It lists the libraries and frameworks the page uses, with their versions and where each one was detected. By hand, you would open DevTools, list the scripts in the Network tab and read version banners one file at a time.

### How do I check which jQuery version a website uses?

Enter the page URL in the checker above and find jQuery in the results. The Version column shows the exact release, and Version status says whether it is up to date, outdated or at end of life. Expand the row to see the known CVEs affecting that version and the release that fixes each one. By hand, you can type jQuery.fn.jquery in the browser console on the page.

### Is the technology checker an alternative to Wappalyzer?

For security questions, yes. Wappalyzer and BuiltWith are built to identify a site's whole stack, including its CMS, hosting and marketing tools. This checker focuses on the JavaScript libraries and frameworks a page uses, and adds what matters for security: how current each version is, whether it is at end of life, and the known CVEs affecting it, with a CycloneDX SBOM export.

### Does a listed CVE mean the site is vulnerable?

Not on its own. A listed CVE is a publicly known vulnerability affecting the detected version. Whether it can be exploited depends on how the library is used, and some vendors backport a fix without changing the version number. Treat the list as the set of versions worth upgrading or checking first, not as a verdict.

### What does end of life mean for a library version?

The maintainers no longer publish fixes for that release line. A vulnerability found tomorrow will stay open in it, so an end-of-life version is a risk even when no CVE is listed today. Outdated means a newer release exists in the same line; dormant means the project has not shipped a release for a long time.

### Can I export the results as an SBOM?

Yes. Export a CycloneDX 1.6 JSON file, with each technology as a component and each known vulnerability linked to it, a CSV with one row per technology and vulnerability, or a PDF report. Results are not stored for sharing, so export them before you leave the page; the PDF export works for 30 minutes after the check.

### Is the technology checker free?

Yes, it is free and needs no account. Each check fetches one public page and the public scripts it loads, the same requests a browser makes. Only check sites you own or are authorised to assess.

## Know when a vulnerable script appears

A check is one snapshot. CentralCSP inventories every script your visitors' browsers run, flags vulnerable versions as they appear, and keeps the evidence PCI DSS asks for. Add one header, no code changes.

[Start with CentralCSP](https://app.centralcsp.com) [See supply-chain protection](https://centralcsp.com/en/platform/supply-chain/)

---

Available in: [en](https://centralcsp.com/en/tools/tech-checker/), [fr](https://centralcsp.com/fr/tools/tech-checker/)
