WordPress Theme Detector
Reads one page of HTML for theme and plugin paths, then the theme stylesheet header for its name, author and parent. No probing, no admin paths.
This tool needs JavaScript: the server makes the request, because a browser cannot read another site headers.
Any page of the site. The home page usually gives the most away.
This is one of the few tools here that asks the server rather than your browser, because a browser cannot do it. Nothing you put in is stored; the request is rate limited by address and the answer is not cached.
What theme a WordPress site is running, from the one page of HTML it serves you. Plus the plugins whose asset paths appear in that HTML, and whatever the theme’s own stylesheet header says about its name, author, version and parent.
Nothing is probed. One page is fetched, plus the stylesheets it points at, which is the same traffic a browser makes when somebody visits.
How to use
Put in any page of the site. The home page usually gives the most away.
Example
Checked https://example.com/
WordPress? yes, from what the page references
Themes referenced
acme-child
name Acme Child
author Acme Ltd
version 1.2.0
child of twentytwentyfour
Plugins referenced (6)
contact-form-7
woocommerce
wordpress-seo
...
Pitfalls
A block theme can be nearly invisible. Block themes inline much of their CSS and reference far fewer
files under /wp-content/themes/, so a modern site can show almost nothing here and still be
WordPress.
Caching and optimisation plugins rewrite asset paths. Combined and minified CSS served from
/wp-content/cache/ loses the theme name entirely, which is why “none found” is not “not WordPress”.
A CDN can rewrite the paths too, to its own domain, with the same effect.
The generator meta tag is usually removed, and it is the only place the WordPress version appears in public HTML. If it is there, that is worth knowing: it tells anybody scanning exactly which vulnerabilities to try.
Plugin slugs are not plugin names. wordpress-seo is Yoast, wp-rocket is not always visible at all
because it is a caching plugin that hides itself, and a plugin with no front-end assets never appears.
A child theme’s header names its parent, but only if style.css is readable. Some hosts block direct access to theme files, which is a sensible setting and means this shows less.
Seeing a plugin does not mean it is active or up to date. It means one page referenced a file inside its folder.
This is not a security tool. It reads what the site publishes. Anything more — probing paths, testing versions, requesting admin URLs — is a different activity against somebody else’s server, and this does not do it.
Compatibility
Two kinds of request: one GET to the page you name, and one GET to each candidate theme’s style.css.
Nothing else. No admin paths, no readme.html, no version probing, and at most four stylesheets.
This is one of the handful of tools here that asks the server, because a browser cannot read another origin’s HTML.
The address goes through the same guard as the other server tools: https or http on the standard ports, the name resolved first with private and reserved addresses refused, redirects followed by hand with the same checks each time, and the response capped. Rate limited to 20 lookups a minute per address, with nothing stored.
Theme headers are read from the first 2KB of the stylesheet, which is where WordPress itself reads them from.
Frequently asked questions
It says no theme found. Is the site not WordPress?
/wp-json/, /wp-includes/, a generator tag — are listed separately for that reason.