App Stack
Every third-party library, analytics tag, and platform a site loads — mapped from what actually ran.
Loading…
Couldn't verify this site's stack
The page returned a bot-protection challenge instead of its real content — mapping it would report the challenge page's scripts as the site's, so the scan refuses rather than showing a wrong map.
0
Technologies
0
Categories
0
Third-party origins
0
Other connections
Detected technologies
| Category | Technology | Party | Version | Evidence | URL |
|---|
Evidence, not inference. Every row shows how it was found —
global (a window object the page itself defined),
dom (a marker element like #__next),
script/link (a resource it loaded as a script or
stylesheet), pixel (an image-based tracking beacon), xhr
(a fetch/XHR call), beacon (navigator.sendBeacon or a
ping), iframe (an embedded sub-document — a captcha widget, an ad render),
meta, header, or bundled (a
known library's banner text found inside a same-origin script or stylesheet — the only way to catch a
vendored copy that exposes no window global). Versions and URLs are only shown
when actually observed — never guessed. Detection watches every request the page actually makes, not just
<script>/<link> tags, so pixels, XHR
beacons, and iframes are caught the same as scripts — anything third-party that doesn't match a known
signature is still listed above under Other third-party connections rather than dropped.
1st-party means no external request was involved (self-hosted, or a
page-native signal like a global/header); 3rd-party means it was
fetched from a different host — those tech nodes also get a ring in the map, same marker style as an
origin node. Drag any node to pin it wherever you drop it — double-click a pinned node to send it back
into orbit. Scroll to zoom, drag empty canvas space to pan, or expand to fullscreen — useful on a
busy site where the map has a lot to show.