WordPress Theme & Plugin Detector Online
Last updated:
Check whether a site uses WordPress, inspect theme candidates, and find public plugin-directory signals—with exact evidence and honest detection limits.
Enter any public page URL to check for WordPress, theme, and plugin signals:
We upgrade & secure WordPress sites, safely.
Backups, PHP upgrades, plugin compatibility checks, rollback safety. You saw the problem above; fixing it is literally our day job.
Stack looks healthy. Want it kept that way?
Our WordPress care plans handle updates, security, backups, and PHP upgrades from $49/mo, so it stays healthy.
Want us to act on this result? Fix these findings →
Prefer the partnership route? Refer clients to us, earn 10% →
How the WordPress Detector Works
This WordPress checker inspects public front-end evidence. It does not log in, execute the site's JavaScript, or inspect its server:
- Follow the submitted page, including safe public redirects, and analyze the final response rather than assuming the original domain or homepage.
- Check WordPress signals, including exact public core, theme and plugin asset URLs, generator metadata, and REST API discovery links. Each signal is shown with its confidence.
- Collect theme candidates from exact
/wp-content/themes/URLs. A linked stylesheet is read when safe; a canonicalstyle.cssprobe is clearly labeled as derived evidence. - Resolve child and parent themes when a linked child stylesheet exposes a valid
Templateheader. The named parent stylesheet is then checked explicitly, even if the parent had no asset in the page HTML. - Report plugin directory slugs from exact
/wp-content/plugins/asset paths without pretending the slug is a verified product name or version.
Why Use a WordPress Theme Detector?
Public WordPress asset paths can reveal useful implementation clues. Results remain partial because custom paths, caching, security controls and server-only plugins can hide them:
- Competitive research, collect evidence about publicly exposed theme and plugin directories before doing deeper product research.
- Design research, identify possible theme directories behind a site you like, while keeping parent, child, legacy and cached assets in mind.
- Client discovery, give an agency or freelancer a fast, evidence-backed starting point before an authenticated technical audit.
- Security triage, an exposed version can justify a closer authenticated review, but this detector cannot prove what is installed, active, current or vulnerable.
If you're evaluating a WordPress site's technical health, pair this with the PHP Version Checker to check whether the public response exposes a PHP version clue. Theme compatibility and PHP version compatibility go hand in hand. For other public platform, CDN, analytics and marketing clues, use the Website Technology Checker. You can assess a separate part of the site's public posture with the Security Headers Checker; missing headers do not identify a plugin or its maintenance status.
A count of exposed plugin directories is not a performance, bloat or security score. If an authenticated audit shows that WordPress no longer fits the project, a WordPress to Astro migration can replace the runtime with a static Astro site designed around the site's actual requirements.
Understanding Your Detection Results
When the scan completes, here's what each piece of information means:
- Scanned URL, the final public page after redirects. Relative asset links are resolved against this URL, not the address originally entered.
- WordPress evidence, the precise public signals used for the result, with high, medium or low confidence.
- Theme candidate, a directory slug and exact asset URLs. A readable stylesheet header can add a name, author and version, but ordinary asset evidence cannot prove which theme is active.
- Likely active child theme, a stronger—but still public-only—inference based on a linked stylesheet whose header names a parent with
Template. - Parent theme, a theme checked explicitly from that child
Templateheader. Its evidence explains whether the parent stylesheet was readable. - Plugin directory signal, an exposed slug plus exact asset URL. It is not a verified plugin name, version, active-state check, vulnerability finding, or complete inventory.
Next steps
WordPress Theme & Plugin Detector related tools and articles
Continue with the closest follow-up checks and guides based on this tool's topic, crawl intent, and optimization workflow.
WordPress Theme & Plugin Detector: FAQ
How does this WordPress theme checker identify a theme?
How does the WordPress plugin detector work?
Does the plugin list include every installed or active plugin?
Can the detected theme be wrong?
Why are the theme name or version missing?
Does an exposed version mean a theme is vulnerable?
Can this WP detector answer “is this site WordPress?”
Is the scanned URL or source stored?
Free 48-Hour Website Audit
Not sure what to fix first on your own website? We'll review it and tell you, in plain English. Free & non-obligatory.
Need Help With Your WordPress Site?
We help small-to-medium businesses build, optimize, and maintain WordPress websites.