Tools
Technology Checker
A free website technology checker. Enter a URL to see the libraries and frameworks the page uses, their versions, where each one comes from, and the known CVEs affecting them.
Check a URL
We list the libraries and frameworks the page uses and check each version against public vulnerability data.
Guide
Understanding your technology report
Most of the code a visitor's browser runs on your site was written by someone else: a framework, a UI library, an analytics loader, a payment SDK. This checker lists what a page uses and flags the versions with publicly known vulnerabilities.
How to check what technology a website uses
Some of it can be read by hand: view the page source, watch the Network tab in your browser's developer tools, or type a library's version variable in the console, such as jQuery.fn.jquery. That answers one question about one library you already suspect. A website technology checker lists the libraries and frameworks a page uses, with their versions, and says which versions are outdated, at end of life, or affected by known CVEs.
Check the version of a library, like jQuery
Enter the page URL and find the library in the table. Version shows the exact release, Latest in line the newest release of the same line, and Version status whether that line is still maintained. Expand the row to see where it was detected and each known CVE with the version that fixes it. For jQuery in particular, read which jQuery versions are vulnerable.
How it compares with Wappalyzer, BuiltWith and Retire.js
Each tool answers a different question. Wappalyzer and BuiltWith identify a site's stack, Retire.js finds vulnerable libraries in files you have or sites you point its scanner at, and this checker starts from a URL and reports versions, end of life and known CVEs together.
| Tool | Starts from | Known CVEs | End of life | SBOM export |
|---|---|---|---|---|
| CentralCSP Technology Checker | Any public URL | Yes | Yes | CycloneDX, CSV, PDF |
| Wappalyzer | Browser extension or website lookup | No | No | No |
| BuiltWith | Website lookup | No | No | No |
| Retire.js | Local files or a headless site scanner | Yes | No | CycloneDX (command line) |
What the report shows
For every technology identified on the page:
- The version in use, or a dash when no version could be read.
- The version status: up to date, outdated, dormant, or end of life.
- The latest release in the same line, so you know the smallest upgrade that helps.
- Where it was detected on the page.
- The known vulnerabilities affecting that version, with severity, a summary, the version that fixes each one, and links to the advisories.
How to read a known vulnerability
A listed CVE means the detected version falls in a range a public advisory marks as affected. It does not prove the site is exploitable: the vulnerable function may never be called, and some vendors backport fixes without changing the version number. Start with critical and high findings in scripts that touch forms, sessions or payments, and upgrade to the fixed version shown.
Why third-party scripts matter
An outdated jQuery or a forgotten widget is an easy way into a page, and a compromised third-party script runs with the same access as your own code. PCI DSS 4.0 requirement 6.3.2 asks for an inventory of the software components you run, third-party scripts included. A one-off check gives you a snapshot; a continuous script inventory keeps it current from your real visitors' browsers.
Exports: CSV, CycloneDX and PDF
The CycloneDX 1.6 JSON export is a standard SBOM: each technology is a component with its version, status and origin, and each known vulnerability is linked to the component it affects. The CSV has one row per technology and vulnerability for spreadsheets and tickets. The PDF is a dated report in the same layout as our scanner reports. Results are not stored for sharing, so export before you leave the page.
More free tools
Keep auditing with the other free tools
Every tool is free, runs without an account, and scores with the same severity scale.
SRI hash generator
Turn a CDN script or stylesheet URL into its Subresource Integrity hash, with a ready-to-paste tag and a CORS check.
- SHA-256, 384 and 512
- CORS verified for you
CSP scanner
Fetch a URL's live Content-Security-Policy and score it against known bypasses, wildcard sources and missing directives.
- Directive-level findings
- Shareable results link
Security headers scanner
Grade every security header a URL sends, from HSTS to Permissions-Policy, with each finding explained and prioritized.
- Every header, one grade
- Fix list ordered by impact
Website compare
See where your score stands: your site beside the dataset average and the year's best-configured sites, control by control.
- Published, auditable references
- Radar view per category
FAQ
Frequently asked questions
Versions, CVEs, end of life and SBOM exports, answered.
Know when a vulnerable script appears
A check is one snapshot. CentralCSP inventories every script your visitors' browsers run, flags vulnerable versions as they appear, and keeps the evidence PCI DSS asks for. Add one header, no code changes.
