New: the free Technology Checker finds outdated libraries and known CVEs on any page. Check your site

Tools

Technology Checker

A free website technology checker. Enter a URL to see the libraries and frameworks the page uses, their versions, where each one comes from, and the known CVEs affecting them.

Check a URL

We list the libraries and frameworks the page uses and check each version against public vulnerability data.

Want to pin a CDN script to the exact file you reviewed?Generate an SRI hash

Guide

Understanding your technology report

Most of the code a visitor's browser runs on your site was written by someone else: a framework, a UI library, an analytics loader, a payment SDK. This checker lists what a page uses and flags the versions with publicly known vulnerabilities.

How to check what technology a website uses

Some of it can be read by hand: view the page source, watch the Network tab in your browser's developer tools, or type a library's version variable in the console, such as jQuery.fn.jquery. That answers one question about one library you already suspect. A website technology checker lists the libraries and frameworks a page uses, with their versions, and says which versions are outdated, at end of life, or affected by known CVEs.

Check the version of a library, like jQuery

Enter the page URL and find the library in the table. Version shows the exact release, Latest in line the newest release of the same line, and Version status whether that line is still maintained. Expand the row to see where it was detected and each known CVE with the version that fixes it. For jQuery in particular, read which jQuery versions are vulnerable.

How it compares with Wappalyzer, BuiltWith and Retire.js

Each tool answers a different question. Wappalyzer and BuiltWith identify a site's stack, Retire.js finds vulnerable libraries in files you have or sites you point its scanner at, and this checker starts from a URL and reports versions, end of life and known CVEs together.

What each technology detection tool reports
ToolStarts fromKnown CVEsEnd of lifeSBOM export
CentralCSP Technology CheckerAny public URLYesYesCycloneDX, CSV, PDF
WappalyzerBrowser extension or website lookupNoNoNo
BuiltWithWebsite lookupNoNoNo
Retire.jsLocal files or a headless site scannerYesNoCycloneDX (command line)

What the report shows

For every technology identified on the page:

  • The version in use, or a dash when no version could be read.
  • The version status: up to date, outdated, dormant, or end of life.
  • The latest release in the same line, so you know the smallest upgrade that helps.
  • Where it was detected on the page.
  • The known vulnerabilities affecting that version, with severity, a summary, the version that fixes each one, and links to the advisories.

How to read a known vulnerability

A listed CVE means the detected version falls in a range a public advisory marks as affected. It does not prove the site is exploitable: the vulnerable function may never be called, and some vendors backport fixes without changing the version number. Start with critical and high findings in scripts that touch forms, sessions or payments, and upgrade to the fixed version shown.

Why third-party scripts matter

An outdated jQuery or a forgotten widget is an easy way into a page, and a compromised third-party script runs with the same access as your own code. PCI DSS 4.0 requirement 6.3.2 asks for an inventory of the software components you run, third-party scripts included. A one-off check gives you a snapshot; a continuous script inventory keeps it current from your real visitors' browsers.

Exports: CSV, CycloneDX and PDF

The CycloneDX 1.6 JSON export is a standard SBOM: each technology is a component with its version, status and origin, and each known vulnerability is linked to the component it affects. The CSV has one row per technology and vulnerability for spreadsheets and tickets. The PDF is a dated report in the same layout as our scanner reports. Results are not stored for sharing, so export before you leave the page.

More free tools

Keep auditing with the other free tools

Every tool is free, runs without an account, and scores with the same severity scale.

SRI hash generator

Turn a CDN script or stylesheet URL into its Subresource Integrity hash, with a ready-to-paste tag and a CORS check.

  • SHA-256, 384 and 512
  • CORS verified for you
Generate an SRI hash

CSP scanner

Fetch a URL's live Content-Security-Policy and score it against known bypasses, wildcard sources and missing directives.

  • Directive-level findings
  • Shareable results link
Run the CSP scanner

Security headers scanner

Grade every security header a URL sends, from HSTS to Permissions-Policy, with each finding explained and prioritized.

  • Every header, one grade
  • Fix list ordered by impact
Scan your security headers

Website compare

See where your score stands: your site beside the dataset average and the year's best-configured sites, control by control.

  • Published, auditable references
  • Radar view per category
Compare your site to the best

FAQ

Frequently asked questions

Versions, CVEs, end of life and SBOM exports, answered.

Know when a vulnerable script appears

A check is one snapshot. CentralCSP inventories every script your visitors' browsers run, flags vulnerable versions as they appear, and keeps the evidence PCI DSS asks for. Add one header, no code changes.