Skip to content
Hivex tools · WebsiteFree · No account

What github.net is built with.

What a website is built with and served by, from its CMS to its analytics, each with the header, cookie or file that gave it away.

Looking up…

What it reads.

  • Headers, such as Server, X-Powered-By, cf-ray or x-vercel-id: most hosts and CDNs sign every answer.
  • Cookie names, never their values: PHPSESSID means PHP, laravel_session Laravel.
  • The HTML: the generator tag, file paths (/wp-content/, /_next/static/) and the addresses of the scripts, fonts and widgets the page loads.

Reading the result.

  • Each technology shows the clue that gave it away, so you can check it yourself in the page source or the browser's network panel.
  • Implied ones (React under Next.js, PHP under WordPress) were not seen directly.
  • Versions appear only when the site states them; a missing version is good practice, not a gap.
  • No result is not proof: tools that load later, or only on other pages, stay out of view.

Questions people ask.

How does the checker know what a site uses?

Every tool leaves traces: a header it sets (x-vercel-id, cf-ray), a cookie it names (PHPSESSID), a generator tag, or a file path or script address it loads (/wp-content/, /_next/, a Shopify storefront script). Hivex reads the home page once and matches it against nearly 200 fingerprints of its own.

Why is a technology I know the site uses missing?

Only the home page is read, as it arrives and before any script runs. Tools added later by a tag manager, loaded only on other pages, or behind a proxy that strips headers do not show.

What does 'implied' mean?

Some technologies always come with another: a Next.js site runs on React, WordPress runs on PHP. Those are listed as implied rather than seen directly.

Can a site hide what it is built with?

Partly. Removing the Server and X-Powered-By headers and the generator tag hides versions, which is worth doing because old versions attract automated attacks, but the files and scripts a page loads usually still show what it uses.

Does it run the site's scripts or log in?

No. It makes one ordinary request for the home page, follows its redirects, and reads the headers, cookie names and HTML. Cookie values are never kept.

Hivex index

Short names, still free to register.

Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.

Browse free names

From code, or an AI assistant.

Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.

The API guideThe MCP serverOpenAPI schema

Sources

  1. OWASP Web Security Testing Guide: fingerprint web application frameworks
  2. RFC 9110 section 10.2.4: the Server header
  3. HTML Standard: the generator meta tag
  4. OWASP Secure Headers Project: headers to remove

By Hivex. Updated 11 October 2026. Each check fetches the home page once from Cloudflare, like a browser that runs no scripts; the page is matched and dropped, nothing is stored.