StackRay

StackRay

Inspect, compare, and track the technology behind websites

Open Source

Gallery

About StackRay

StackRay is a self-hosted site intelligence app for inspecting what a website is built with and keeping that information in one searchable place. A user gives it a domain or URL, starts a scan, and gets a report covering the technologies and public infrastructure signals that StackRay can detect. It addresses a broader problem than simply naming a content management system. Technical teams often need to understand how a site responds, which services sit around it, and whether that picture has changed since the last review. StackRay keeps the target, scan history, and findings together, so the result can become part of an ongoing inventory instead of disappearing after a one-time lookup.

A scan moves through several forms of inspection. StackRay probes HTTP responses, renders pages in a browser, reviews DNS and TLS details, looks for passive subdomains, adds IP and ASN context, and records visible server fingerprints. It can capture a screenshot, favicon, page title, redirect path, response metadata, and detected technologies. Its detection scope includes frameworks, content management systems, ecommerce platforms, analytics products, content delivery networks, web application firewalls, and hosting providers. It also uses Nuclei templates for structured checks across public HTTP, DNS, SSL, and exposure signals. Those methods make the report useful for seeing both the application layer and the public infrastructure around a target.

The web interface turns those scans into a working collection. Teams can browse targets, open past runs, compare the technology stacks of multiple sites, and schedule recurring scans. A scan history makes it possible to notice when a provider, framework, certificate, or other detected detail changes over time. The dashboard summarizes scan activity and discoveries, while recent cards put response status, server, CDN, detection totals, and report access together. StackRay also exposes an HTTP and JSON API, an SSE event stream for progress and results, and API keys for automation. That gives developers a way to queue scans from internal systems or let an authorized AI agent work with the resulting data. User accounts and team invitations are available inside a deployed instance, which is useful when asset knowledge needs to be shared rather than kept on one engineer's machine.

StackRay is designed around self-hosting. The project documents a Railway deployment that provisions the Next.js web app, separate HTTP, intelligence, and browser workers, a Postgres database, and S3-compatible storage. The services separate interactive application work from browser rendering and the heavier scanning jobs. A local development setup is also documented, with Docker used for scanner dependencies and MinIO standing in for object storage. The scanner builds on established ProjectDiscovery tools, including httpx for probing and technology detection, Nuclei for template-driven checks, and subfinder for passive subdomain discovery. Its source is published under the MIT license, so teams can inspect the implementation and adapt their own deployment.

The clearest fit is a developer, platform, security, or technical research team maintaining an authorized list of public web assets. It can support an internal technology inventory, a review of vendors and competitors, or an investigation into which public signals changed after a deployment. The product is also practical for agencies that repeatedly assess client sites and want results in a consistent format. What sets StackRay apart from a lightweight browser extension is the combination of richer scanning, saved history, comparisons, schedules, shared access, and an API. It behaves more like a small intelligence system than a single page that returns a list of JavaScript libraries.

StackRay's broader reach also sets reasonable boundaries. Detection is based on observable signals, so hidden services and deliberately obscured technologies may not appear, while fingerprints can still need human review. Some checks use security-oriented tooling, and the project explicitly limits its intended use to authorized asset inventory, security research, and site intelligence. Operators remain responsible for laws, site terms, and rate limits. There isn't a hosted subscription plan presented on the product site. The main offering is free, open-source software that a team runs on its own infrastructure, with a public live instance available for trying the interface. That removes a software fee, but the operator still owns deployment, storage, workers, updates, and infrastructure costs.

Key Features

  • Multi-phase website scanning
  • Web technology detection
  • Historical scan comparisons
  • Scheduled recurring scans
  • HTTP and JSON API
  • Self-hosted team workspace

Pros & Cons

What we like

  • Combines application and infrastructure signals in one report
  • Keeps searchable history instead of returning a one-time result
  • Supports automation through API keys and event streams
  • Open-source code can run on infrastructure you control

Room for improvement

  • Self-hosting requires several services and scanner workers
  • Detection quality depends on publicly observable signals
  • Security-oriented scans must stay within authorized scope
  • Infrastructure and maintenance remain the operator's responsibility

Frequently Asked Questions

What is StackRay?
StackRay is a self-hosted site intelligence app that scans domains and URLs for technologies and public infrastructure signals. It stores targets, results, and scan history in a searchable web interface.
What does a StackRay scan collect?
A scan can collect technology fingerprints, HTTP metadata, redirects, TLS and DNS details, passive subdomains, IP context, screenshots, and Nuclei-backed findings. Results depend on what the target exposes publicly and may still need human review.
Is StackRay free?
Yes. StackRay is free and open source under the MIT license, and its primary deployment model is self-hosting. Operators still pay for and maintain the infrastructure they choose to run it on.
Who is StackRay for?
It's aimed at developers, platform teams, security teams, agencies, and researchers who need repeatable intelligence about authorized web assets. It is best suited to people who want saved history, scheduled scans, comparisons, and API access rather than a quick browser lookup.

Best For

Tracking technology changes across company websitesBuilding an inventory of authorized web assetsComparing vendor or competitor technology stacksAutomating recurring public site intelligence checks

Featured in

Alternatives to StackRay

Reviews (0)

No reviews yet

Be the first to share your experience with StackRay

Sign in to write a review

Badge builder

Add StackRay to your website

Choose a badge style and size, preview it here, then copy the generated HTML. Badge images are self-contained SVGs and do not require an external script.

StackRay badge preview
<a href="https://toolindex.net/tools/stackray?ref=badge" target="_blank" rel="noopener">
  <img src="https://toolindex.net/badge/stackray/medium.svg" alt="StackRay - Listed on Tool Index" width="180" height="50" />
</a>

How to use the badge

  1. 1. Pick the style, size, and theme that fit your layout.
  2. 2. Copy the generated HTML from the code block.
  3. 3. Paste it into your footer, homepage, or press page.

Standard badge available

The standard listing badge is available now. Score and circle badges are limited to tools currently ranked in the top 10 of a category.

Badge clicks return visitors to this profile with a referral tag so the source remains identifiable.