WordPress Theme Detector

Reads one page of HTML for theme and plugin paths, then the theme stylesheet header for its name, author and parent. No probing, no admin paths.

This tool needs JavaScript: the server makes the request, because a browser cannot read another site headers.

Any page of the site. The home page usually gives the most away.

Result

This is one of the few tools here that asks the server rather than your browser, because a browser cannot do it. Nothing you put in is stored; the request is rate limited by address and the answer is not cached.

What theme a WordPress site is running, from the one page of HTML it serves you. Plus the plugins whose asset paths appear in that HTML, and whatever the theme’s own stylesheet header says about its name, author, version and parent.

Nothing is probed. One page is fetched, plus the stylesheets it points at, which is the same traffic a browser makes when somebody visits.

How to use

Put in any page of the site. The home page usually gives the most away.

Example

Checked                                    https://example.com/

WordPress?                                 yes, from what the page references

Themes referenced
  acme-child
    name                                   Acme Child
    author                                 Acme Ltd
    version                                1.2.0
    child of                               twentytwentyfour

Plugins referenced (6)
  contact-form-7
  woocommerce
  wordpress-seo
  ...

Pitfalls

A block theme can be nearly invisible. Block themes inline much of their CSS and reference far fewer files under /wp-content/themes/, so a modern site can show almost nothing here and still be WordPress.

Caching and optimisation plugins rewrite asset paths. Combined and minified CSS served from /wp-content/cache/ loses the theme name entirely, which is why “none found” is not “not WordPress”.

A CDN can rewrite the paths too, to its own domain, with the same effect.

The generator meta tag is usually removed, and it is the only place the WordPress version appears in public HTML. If it is there, that is worth knowing: it tells anybody scanning exactly which vulnerabilities to try.

Plugin slugs are not plugin names. wordpress-seo is Yoast, wp-rocket is not always visible at all because it is a caching plugin that hides itself, and a plugin with no front-end assets never appears.

A child theme’s header names its parent, but only if style.css is readable. Some hosts block direct access to theme files, which is a sensible setting and means this shows less.

Seeing a plugin does not mean it is active or up to date. It means one page referenced a file inside its folder.

This is not a security tool. It reads what the site publishes. Anything more — probing paths, testing versions, requesting admin URLs — is a different activity against somebody else’s server, and this does not do it.

Compatibility

Two kinds of request: one GET to the page you name, and one GET to each candidate theme’s style.css. Nothing else. No admin paths, no readme.html, no version probing, and at most four stylesheets.

This is one of the handful of tools here that asks the server, because a browser cannot read another origin’s HTML.

The address goes through the same guard as the other server tools: https or http on the standard ports, the name resolved first with private and reserved addresses refused, redirects followed by hand with the same checks each time, and the response capped. Rate limited to 20 lookups a minute per address, with nothing stored.

Theme headers are read from the first 2KB of the stylesheet, which is where WordPress itself reads them from.

Frequently asked questions

It says no theme found. Is the site not WordPress?
Not necessarily. Caching plugins, CDNs and block themes all hide the paths this looks for. The other signals — /wp-json/, /wp-includes/, a generator tag — are listed separately for that reason.
Can I see the WordPress version?
Only when the site publishes it in a generator tag, which most do not, and should not.
Does this work on a site behind Cloudflare?
Usually yes, since it reads the HTML that Cloudflare serves. It cannot see anything Cloudflare does not pass on.
Why only four themes?
A page normally references one theme, or two when a child theme is in use. More than that is a misconfiguration, and fetching a stylesheet for each one would be more requests to somebody else’s server than the answer is worth.
Can I detect the page builder?
Often, from the plugin list: Elementor, Divi, Beaver Builder and the rest all ship front-end assets with recognisable paths.

From the people who built this tool

WP Adminify

The WordPress admin, rebuilt: a dashboard worth looking at, menu and column control, a real file manager and the login page your client sees.

See WP Adminify Free version on WordPress.org

Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.