StackRay
Inspect, compare, and track the technology behind websites
Gallery
About StackRay
StackRay is a self-hosted site intelligence app for inspecting what a website is built with and keeping that information in one searchable place. A user gives it a domain or URL, starts a scan, and gets a report covering the technologies and public infrastructure signals that StackRay can detect. It addresses a broader problem than simply naming a content management system. Technical teams often need to understand how a site responds, which services sit around it, and whether that picture has changed since the last review. StackRay keeps the target, scan history, and findings together, so the result can become part of an ongoing inventory instead of disappearing after a one-time lookup.
A scan moves through several forms of inspection. StackRay probes HTTP responses, renders pages in a browser, reviews DNS and TLS details, looks for passive subdomains, adds IP and ASN context, and records visible server fingerprints. It can capture a screenshot, favicon, page title, redirect path, response metadata, and detected technologies. Its detection scope includes frameworks, content management systems, ecommerce platforms, analytics products, content delivery networks, web application firewalls, and hosting providers. It also uses Nuclei templates for structured checks across public HTTP, DNS, SSL, and exposure signals. Those methods make the report useful for seeing both the application layer and the public infrastructure around a target.
The web interface turns those scans into a working collection. Teams can browse targets, open past runs, compare the technology stacks of multiple sites, and schedule recurring scans. A scan history makes it possible to notice when a provider, framework, certificate, or other detected detail changes over time. The dashboard summarizes scan activity and discoveries, while recent cards put response status, server, CDN, detection totals, and report access together. StackRay also exposes an HTTP and JSON API, an SSE event stream for progress and results, and API keys for automation. That gives developers a way to queue scans from internal systems or let an authorized AI agent work with the resulting data. User accounts and team invitations are available inside a deployed instance, which is useful when asset knowledge needs to be shared rather than kept on one engineer's machine.
StackRay is designed around self-hosting. The project documents a Railway deployment that provisions the Next.js web app, separate HTTP, intelligence, and browser workers, a Postgres database, and S3-compatible storage. The services separate interactive application work from browser rendering and the heavier scanning jobs. A local development setup is also documented, with Docker used for scanner dependencies and MinIO standing in for object storage. The scanner builds on established ProjectDiscovery tools, including httpx for probing and technology detection, Nuclei for template-driven checks, and subfinder for passive subdomain discovery. Its source is published under the MIT license, so teams can inspect the implementation and adapt their own deployment.
The clearest fit is a developer, platform, security, or technical research team maintaining an authorized list of public web assets. It can support an internal technology inventory, a review of vendors and competitors, or an investigation into which public signals changed after a deployment. The product is also practical for agencies that repeatedly assess client sites and want results in a consistent format. What sets StackRay apart from a lightweight browser extension is the combination of richer scanning, saved history, comparisons, schedules, shared access, and an API. It behaves more like a small intelligence system than a single page that returns a list of JavaScript libraries.
StackRay's broader reach also sets reasonable boundaries. Detection is based on observable signals, so hidden services and deliberately obscured technologies may not appear, while fingerprints can still need human review. Some checks use security-oriented tooling, and the project explicitly limits its intended use to authorized asset inventory, security research, and site intelligence. Operators remain responsible for laws, site terms, and rate limits. There isn't a hosted subscription plan presented on the product site. The main offering is free, open-source software that a team runs on its own infrastructure, with a public live instance available for trying the interface. That removes a software fee, but the operator still owns deployment, storage, workers, updates, and infrastructure costs.
Key Features
- Multi-phase website scanning
- Web technology detection
- Historical scan comparisons
- Scheduled recurring scans
- HTTP and JSON API
- Self-hosted team workspace
Pros & Cons
What we like
- Combines application and infrastructure signals in one report
- Keeps searchable history instead of returning a one-time result
- Supports automation through API keys and event streams
- Open-source code can run on infrastructure you control
Room for improvement
- Self-hosting requires several services and scanner workers
- Detection quality depends on publicly observable signals
- Security-oriented scans must stay within authorized scope
- Infrastructure and maintenance remain the operator's responsibility
Frequently Asked Questions
What is StackRay?
What does a StackRay scan collect?
Is StackRay free?
Who is StackRay for?
Best For
Featured in
Alternatives to StackRay

1Password
Password and secrets manager for individuals, families, and developer teams with strong CLI and SSH agent support.
Clerk
Drop-in authentication and user management for modern apps

Tailscale
WireGuard-based mesh VPN that connects your devices, servers, and cloud resources into one private network in minutes.

BackPedal
UK bike theft protection that sends recovery agents after your stolen bike
Reviews (0)
Badge builder
Add StackRay to your website
Choose a badge style and size, preview it here, then copy the generated HTML. Badge images are self-contained SVGs and do not require an external script.
<a href="https://toolindex.net/tools/stackray?ref=badge" target="_blank" rel="noopener">
<img src="https://toolindex.net/badge/stackray/medium.svg" alt="StackRay - Listed on Tool Index" width="180" height="50" />
</a> How to use the badge
- 1. Pick the style, size, and theme that fit your layout.
- 2. Copy the generated HTML from the code block.
- 3. Paste it into your footer, homepage, or press page.
Standard badge available
The standard listing badge is available now. Score and circle badges are limited to tools currently ranked in the top 10 of a category.
Badge clicks return visitors to this profile with a referral tag so the source remains identifiable.
Related Tools
Clerk
Drop-in authentication and user management for modern apps
DomeSOC
Autonomous SOC that grades every AI claim against evidence before it reaches an analyst

Reel
Forensic evidence capture for regulated Kubernetes, plus a free open-source VEX hub

HeimWall
Menu bar app that catches secrets and PII before you paste them into AI coding tools
Work on StackRay? Request listing access or correction