Technologies identified from the response
What this check looks for
This is what the site's response and page source suggest it is built with. It is an observation, not a problem, and each entry carries how sure we are.
Why it matters
Knowing what is running is the starting point for keeping it patched, and it is also what an attacker establishes first. Anything listed here was readable by anyone who loaded the page.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- medium
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- Technology
- Module
- Web technology
- Fix owned by
- user
- In the ruleset since
- 2026.09
Technical detail
‹detail›
Each detection names the signal it rests on and a confidence:
- **confirmed** — the vendor documents the signal and the signal names the product, so no inference is involved.
- **high** — a marker only one vendor emits, but which does not name the product.
- **medium** — a marker the product emits which others plausibly emit too.
- **low** — a build artefact or a widely copied convention. Treat these as a hint, not a fact.
We never promote a confidence, and we never present a low match as an identification. Detection also only sees what the response carried: a site behind a cache, a page rendered entirely by JavaScript, or a body larger than the byte cap can all hide a technology that is genuinely in use, so an empty or short list is not evidence of absence.
Every fingerprint dotvitals uses was written from a primary source — the vendor's own documentation, a standards document, or a recorded observation of a named site — and its provenance is published in docs/30-technology-fingerprint-provenance.md.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.