CoreScanWP v1.4

Identify the CMS
behind any website.

CoreScanWP weighs eight or more independent fingerprints to confirm whether a site runs WordPress and shows you every signal it found. When a site clearly isn't WordPress, you get a confident, plainly-worded answer instead of a guess.

How CMS detection works.

WordPress powers an estimated 43% of the internet, so the most useful CMS-detection question for most sites is "is this WordPress?" CoreScanWP weighs the answer across many independent signals.

  1. 1

    HTML fingerprints

    /wp-content/ and /wp-includes/ asset paths in the markup. The <meta name="generator"> tag. The api.w.org link element. The RSD discovery link.

  2. 2

    Response headers

    A Link: header that points to the wp-json REST API. An X-Powered-By header that mentions WordPress or WordPress VIP. Cache headers from managed-WordPress hosts like Kinsta and WP Engine.

  3. 3

    Endpoint probes

    A live wp-json/ REST API response with the wp/v2 namespace. An RSS feed whose generator is wordpress.org. A readme.html at the canonical WordPress path.

8+

Independent signals weighed per scan

3

Layers : HTML + headers + REST/feed probes

~2s

Average time to a confident verdict

100%

Evidence shown : every signal that contributed

When the answer is "not WordPress."

A confident negative is more useful than a hedged maybe. If the signal score doesn't cross the threshold, CoreScanWP says so plainly and shows the absence of evidence.

What does "Not WordPress" actually mean?

Either the site is built on a different CMS (Shopify, Drupal, Joomla, Wix, Squarespace, Webflow, Ghost), or it's a custom-coded site with no recognizable CMS fingerprint at all.

Will I get hosting details either way?

Yes. The hosting detector runs on every scan regardless of CMS : you get the resolved IP, reverse DNS, ASN, network owner, CDN, and country.

Can a site hide it's WordPress?

Hardened sites can strip the generator tag, block the REST API, and rewrite asset paths. But three or four independent signals usually survive, and CoreScanWP shows you all of them so you can judge for yourself.

What if I need to detect Shopify or Drupal?

CoreScanWP specializes in WordPress. For other CMS platforms the report tells you clearly that WordPress was not detected, and the hosting card still gives you the CDN and origin signals that often hint at the platform.