WordPress Theme & Plugin Detector Online

Last updated:

Check whether a site uses WordPress, inspect theme candidates, and find public plugin-directory signals—with exact evidence and honest detection limits.

Enter any public page URL to check for WordPress, theme, and plugin signals:

How the WordPress Detector Works

This WordPress checker inspects public front-end evidence. It does not log in, execute the site's JavaScript, or inspect its server:

  1. Follow the submitted page, including safe public redirects, and analyze the final response rather than assuming the original domain or homepage.
  2. Check WordPress signals, including exact public core, theme and plugin asset URLs, generator metadata, and REST API discovery links. Each signal is shown with its confidence.
  3. Collect theme candidates from exact /wp-content/themes/ URLs. A linked stylesheet is read when safe; a canonical style.css probe is clearly labeled as derived evidence.
  4. Resolve child and parent themes when a linked child stylesheet exposes a valid Template header. The named parent stylesheet is then checked explicitly, even if the parent had no asset in the page HTML.
  5. Report plugin directory slugs from exact /wp-content/plugins/ asset paths without pretending the slug is a verified product name or version.

Why Use a WordPress Theme Detector?

Public WordPress asset paths can reveal useful implementation clues. Results remain partial because custom paths, caching, security controls and server-only plugins can hide them:

  • Competitive research, collect evidence about publicly exposed theme and plugin directories before doing deeper product research.
  • Design research, identify possible theme directories behind a site you like, while keeping parent, child, legacy and cached assets in mind.
  • Client discovery, give an agency or freelancer a fast, evidence-backed starting point before an authenticated technical audit.
  • Security triage, an exposed version can justify a closer authenticated review, but this detector cannot prove what is installed, active, current or vulnerable.

If you're evaluating a WordPress site's technical health, pair this with the PHP Version Checker to check whether the public response exposes a PHP version clue. Theme compatibility and PHP version compatibility go hand in hand. For other public platform, CDN, analytics and marketing clues, use the Website Technology Checker. You can assess a separate part of the site's public posture with the Security Headers Checker; missing headers do not identify a plugin or its maintenance status.

A count of exposed plugin directories is not a performance, bloat or security score. If an authenticated audit shows that WordPress no longer fits the project, a WordPress to Astro migration can replace the runtime with a static Astro site designed around the site's actual requirements.

Understanding Your Detection Results

When the scan completes, here's what each piece of information means:

  • Scanned URL, the final public page after redirects. Relative asset links are resolved against this URL, not the address originally entered.
  • WordPress evidence, the precise public signals used for the result, with high, medium or low confidence.
  • Theme candidate, a directory slug and exact asset URLs. A readable stylesheet header can add a name, author and version, but ordinary asset evidence cannot prove which theme is active.
  • Likely active child theme, a stronger—but still public-only—inference based on a linked stylesheet whose header names a parent with Template.
  • Parent theme, a theme checked explicitly from that child Template header. Its evidence explains whether the parent stylesheet was readable.
  • Plugin directory signal, an exposed slug plus exact asset URL. It is not a verified plugin name, version, active-state check, vulnerability finding, or complete inventory.

Next steps

WordPress Theme & Plugin Detector related tools and articles

Continue with the closest follow-up checks and guides based on this tool's topic, crawl intent, and optimization workflow.

WordPress Theme & Plugin Detector: FAQ

How does this WordPress theme checker identify a theme?
It follows the submitted page to its final URL, records exact public /wp-content/themes/ asset URLs, and reads a linked stylesheet when available. It may also probe that same public theme directory for its canonical style.css header. Every theme stays a candidate unless a linked child-theme header provides stronger evidence.
How does the WordPress plugin detector work?
It reports directory slugs exposed by exact /wp-content/plugins/ front-end asset URLs. A slug is evidence of a public asset path, not a verified product name, version, installation state, or activation state.
Does the plugin list include every installed or active plugin?
No. Hidden, admin-only, must-use, renamed, bundled, cached, and server-side plugins cannot be detected reliably from a public page. A plugin can also be active without loading an identifiable front-end asset on the scanned response.
Can the detected theme be wrong?
A page can reference a child theme, parent theme, inactive theme, old asset, or CDN copy. The tool therefore labels ordinary results as theme candidates. Only a linked stylesheet with a readable child Template header is identified as a likely active child theme, and you should still verify before making licensing or migration decisions.
Why are the theme name or version missing?
The public stylesheet may be blocked, omit the standard WordPress header, be bundled elsewhere, or load after JavaScript runs. The detector keeps the exact exposed directory slug and asset evidence instead of inventing a friendly name.
Does an exposed version mean a theme is vulnerable?
No. A theme version read from style.css can be cached or stale and is only an inventory clue. This scan does not infer plugin versions. Confirm the active software and compare it with vendor advisories before drawing a security conclusion.
Can this WP detector answer “is this site WordPress?”
It can identify public WordPress signals with confidence and evidence, but absence is not proof. Bot protection, headless WordPress, custom content paths, consent variants, redirects, or hidden assets can make a WordPress site look inconclusive.
Is the scanned URL or source stored?
The URL is sent to WebAloha's server to fetch that public page and a small bounded set of eligible public theme stylesheets. This endpoint does not save the URL, page source, stylesheet content, or result to a database or cache.

Free 48-Hour Website Audit

Not sure what to fix first on your own website? We'll review it and tell you, in plain English. Free & non-obligatory.

Need Help With Your WordPress Site?

We help small-to-medium businesses build, optimize, and maintain WordPress websites.