Revealera
Back to Blog
September 17, 2026

10 BuiltWith Alternatives for Tech Lookups in 2026

BuiltWith has been the go-to tool for tech stack detection since 2007. It tracks over 85,000 technologies across 673 million websites. But it's not perfect.

Pricing starts at $295/month. The data skews heavily toward frontend technologies. Backend tools like Slack, Okta, or internal CRMs rarely show up. And the crawl-based approach means data can lag behind real-time changes.

I tested ten alternatives:

  1. Bloomberry - best for backend tech detection plus adoption and churn timing
  2. Wappalyzer - best for real-time browser-based detection
  3. Store Leads - best for ecommerce store and Shopify app data
  4. TechPeeker - best for lead generation based on CMS and frameworks
  5. JobsPipe - best for technographics pulled from job postings
  6. Hunter TechLookup - best for prospect list building
  7. Tagstack - best for analyzing GTM containers (Google Tag Manager)
  8. WhatRuns - best free alternative
  9. urlscan.io - best for security research
  10. MerkleMap - best for finding internal infrastructure

1. Bloomberry - Backend Tech Detection and Timing

Best for: Sales teams targeting enterprise buyers who need backend visibility and the date a company adopted or dropped a product.

Bloomberry works differently from the rest of this list. Instead of scanning websites for scripts and tags, it reads infrastructure signals: new subdomains, DNS records, certificate transparency logs, and signals specific to how each product gets deployed. It crawls websites too, but goes further than checking whether a tag exists, reading the configuration inside script files and checking whether they still return a working response.

That approach surfaces software that never appears on a public website, such as CRMs, ERPs, security tools, devops platforms and AI products, across 1,700+ B2B products in 190 categories.

The second difference is timing. Give it a product and it returns the companies using it, with dates attached. Their GitHub page is a good look at the format: active accounts sit alongside the ones that dropped it recently and the ones with a renewal coming up.

Purchase signals typically surface within 3 days of adoption, across roughly 400,000 subscribe and churn events per month. You can also set alerts to get notified by email or Slack when a tracked product is adopted or dropped, or when a renewal window opens.

Churn is where it separates from script-based tools. Companies routinely cancel a subscription and leave the tag on their site, so most tools keep reading them as an active customer. Bloomberry verifies the endpoint is genuinely dead before reporting churn, which also means a site redesign doesn't get miscounted as a lost customer.

Where it falls short

Bloomberry has almost no data on JavaScript frameworks or WordPress themes. You will not find a list of companies using jQuery, or React, or even WordPress itself. If that is what you need, BuiltWith is the better tool and it is not close (they'll give you a list of millions of sites using them). Bloomberry is built around commercial software that companies pay for, so open-source frontend libraries mostly sit outside its scope.

Lastly, as of this writing, Bloomberry doesn't have a Chrome extension. if you want to find out what technologies a company is using, you'll need to log into their tool instead.

Strengths:

  • Detects backend software with no website footprint
  • Adoption and churn events with dates attached, not static snapshots
  • Churn verified by checking whether the integration still works
  • Email and Slack alerts on adoption, churn and renewals
  • Adds newer GTM and AI tools continuously
  • REST API for platforms embedding the data

Limitations:

  • Almost no coverage of JavaScript frameworks, CMS platforms or WordPress themes
  • Not built for massive general-purpose frontend lists
  • No contact data, company-level signals only
  • Churn signals lag adoption by 1-2 weeks because they're validated first

Pricing: Free trial, no credit card required. Paid plans from $199/month

2. Wappalyzer - Real-Time Detection

Best for: Sales reps needing instant tech visibility during prospect research, and anyone who needs technologies that only appear on deeper pages.

Like BuiltWith, Wappalyzer does frontend detection well. The interesting difference is in how it gets its data. Wappalyzer relies on people running its browser extension, and it detects technologies on whatever pages those users visit.

That matters more than it sounds. Plenty of sites do not embed payment processing scripts on their homepage, only on checkout pages. A crawler is unlikely to get that far, but Wappalyzer's users do, so those technologies show up. The same applies to anything living behind a login, a cart, or a multi-step form.

The tradeoff is the same one BuiltWith has. Wappalyzer cannot detect backend technologies at all. It has no way of knowing whether a company runs NetSuite, because NetSuite leaves no trace on a website.

Strengths:

  • Detects technologies on checkout and deep pages that crawlers miss
  • Real-time lookups
  • Crowdsourced accuracy
  • Clean interface

Limitations:

  • No backend technology detection at all
  • Coverage depends on where its extension users happen to browse
  • Free tier capped at 50 lookups

Pricing: Free (50 lookups/month); Pro from $250/month

3. Store Leads - Ecommerce Store and App Data

Best for: Agencies, Shopify app developers and SaaS teams selling to ecommerce brands.

Store Leads is narrower than the rest of this list and better within its lane. It tracks 13.7+ million active ecommerce stores across 405 platforms, including Shopify, WooCommerce, Magento and BigCommerce, with around 6,900 tracked apps and technologies, refreshed weekly.

The part people underuse is app-level data. It is not just for finding stores on a given ecommerce platform, it will tell you which stores have a specific Shopify app installed, and which ones installed it recently. If you build a Shopify app, that is a list of your competitor's customers.

The filtering is genuinely deep. You can segment by country, installed apps, theme and theme vendor, number of products sold, and category based on what a store actually sells, with region and city available on paid plans. So a query like "UK stores selling skincare with more than 200 products running Klaviyo" is a normal thing to ask it.

The catch is that Store Leads maps stores, not people. It will tell you a Shopify store runs Klaviyo and gets 50,000 monthly visitors, but not who to email. For that, you'll need to either scrape the emails yourself (Protip: Klaviyo configuration scripts often show the email of the store owner), or rely on a service like Apollo.io or FullEnrich.

Strengths:

  • Deepest ecommerce store coverage available
  • Shopify app install data, including recent installs
  • Around 60 filters including country, product count, category, theme and apps
  • Weekly data refresh
  • Chrome extension and CRM integrations

Limitations:

  • Ecommerce only
  • No verified contact data for decision-makers
  • CSV export and API require the $250/month plan

Pricing: Premium $75/month; Pro $250/month (adds CSV export and API); Elite $450/month; Enterprise $950/month

4. TechPeeker - best for lead generation based on CMS and frameworks

Best for: Agencies and sales teams who need WordPress themes, Shopify themes and CMS data without BuiltWith or Wappalyzer pricing.

TechPeeker covers more than 17 million websites and 800+ technologies. It does not do backend detection anywhere near as well as it does frontend, but that is the point: it is a cheaper way to get the CMS, theme and framework data that BuiltWith and Wappalyzer charge a lot more for.

You search for websites using a specific technology, then filter by CMS, framework, domain suffix, language and website popularity. In testing, I searched for sites running Ruby on Rails and filtered to German-language websites, which produced a targeted prospect list in one step.

The keyword filter is the feature that sets it apart. You can narrow results by words in a site's title or meta description, so a search for Shopify stores filtered to the keyword "skincare" returns skincare brands specifically rather than every Shopify store in the index. For niche outreach that is the difference between a usable list and a scrape.

Coverage spans the popular CMS and ecommerce platforms such as WordPress, Shopify, Drupal and Magento, plus frontend frameworks including React, Vue.js, Angular, Next.js and Svelte, and backend frameworks like Laravel and Ruby on Rails.

It also ships several free tools worth knowing about: a Shopify theme detector, WordPress theme detector, CMS detector and Shopify app detector, all usable without an account for one-off lookups.

Strengths:

  • Much cheaper than BuiltWith or Wappalyzer for the same frontend data
  • Strong WordPress theme, Shopify theme and CMS coverage
  • Keyword filtering on title and meta description
  • Free standalone detector tools
  • Bulk enrichment and API on the Business plan

Limitations:

  • Weak backend detection
  • Public-facing web technologies only
  • Smaller technology database than BuiltWith

Pricing: From $99/month; Business plan $149/month adds API access and bulk enrichment

5. JobsPipe - Technographics From Job Postings

Best for: Teams who need backend and back-office software that leaves no website footprint at all, and developers building technographic data into their own product.

JobsPipe is pretty unique from the other Builtwith alternatives in. Instead of looking at a company's website, it searches through job postings from 30+ sources (including LinkedIn and a long list of ATS systems) then lets you find the companies that mention a specific technology anywhere in a job description or job title.

As a result, you can find lists of companies using tools that don't leave a footprint on their website. For instance, no amount of crawling will tell you which HR platform a company runs, what tool they use for compliance, or which identity and access management tool their engineers log into every morning. That's because none of it touches the public website. But it shows up constantly in job descriptions, because the people writing them have to describe the tools the role will actually use.

To test out JobsPipe, I signed up for the free tier. Let's say I want US companies using HubSpot: I typed "Hubspot" into the description filter, set location to United States, and got back 11,743 job postings mentioning it in the job description.

The pricing model is the best part - as it's pay per usage. You're not paying for the whole result set. Each row comes back masked, and you click "Reveal" on the specific rows you want, which costs 1 credit each. If I only care about the first posting, that's 1 credit. You can export the whole list instead, which costs the same number of credits as rows.

JobsPipe has an easy to use UI if all you need is exporting data, but it's clearly built for people putting this data inside something else, whether that's a job board, an enrichment pipeline or a GTM workflow. There's a REST API, real SDKs and an MCP server you can point Claude at. The nice touch is the "API Request" button in the search UI: build your filters visually, click it, and it hands you the equivalent API call to drop straight into your code.

There's also a separate tech-stack scan endpoint that runs the reverse query. You give it a domain such as hubspot.com and it returns the technologies it detects that company running. Worth being clear about what that is: it's a website scan, not job posting data, so it behaves like the frontend tools further up this list (ie. Wappalyzer/TechPeeker) rather than like the rest of JobsPipe.

Limitations

Most of the limitations here are inherent to job posting data rather than anything JobsPipe is doing wrong. But the big one is that a mention is a mention. Job descriptions get written by recruiters, and they'll happily list the entire stack a team touches, plus tools/technologies that are "nice to have", but they don't actually use.

Whether that matters depends on what you're doing with it. If you're targeting companies that mention HubSpot because you want companies doing marketing automation, the mention is probably signal enough. But if you're actually selling Hubspot services to companies using Hubspot, then you probably want to target actual customers of Hubspot instead.

The other limitation is timing. Companies tend to mention a technology in postings long after they adopted it, so this is not the source for catching recent adopters. If you're a Salesforce consultancy hunting for fresh implementations, job postings will mostly point you at companies that rolled it out years ago, not companies that adopted it today.

Where it shines is account research and automation. If you're already in a conversation with a prospect and want a read on their stack, their postings will tell you what they've been hiring against. And if you're building on top of technographic data, an API, an MCP server and real SDKs matter a lot more than a pretty interface.

Strengths:

  • Detects backend and back-office software that has no website footprint
  • Pay per revealed row rather than per full export
  • REST API, SDKs and an MCP server
  • "API Request" button turns UI filters into a ready-made API call
  • 30+ posting sources normalized into one schema
  • Generous free tier

Limitations:

  • A mention in a posting is not proof of use
  • Postings lag adoption, so it's poor for catching new adopters
  • Only covers companies that are actively hiring
  • The UI is built for research, not for building big lead lists

Pricing: Free tier includes 1,000 jobs/month. Builder is $49/month for 25,000 jobs, Scale is $349/month for 300,000 (roughly $1.16 per 1,000). One credit equals one job returned.

6. Hunter TechLookup - Free Prospect Lists

Best for: SDRs and marketers building outbound campaigns with limited budgets.

Hunter.io's TechLookup integrates email discovery with technology filtering across 4.5 million domains. The first 5,000 rows export completely free, which makes it the cheapest way to test whether technographic targeting works for your motion at all.

Strengths:

  • Minimal interface
  • Email discovery built in
  • Quality-focused dataset

Limitations:

  • No browser extension
  • List-building only, not individual analysis
  • Small domain coverage relative to the others here

Pricing: Free for 5,000 rows; paid Hunter plans unlock 50,000 rows

7. Tagstack - GTM-Focused Analysis

Best for: Analytics agencies and MarTech consultants auditing implementations, and anyone hunting for scripts a crawler never sees.

Tagstack analyzes Google Tag Manager containers, scoring container health and identifying tracking gaps across 1.4 million+ scanned containers. It also tells you which technologies and scripts a site has configured inside GTM.

A lot of that overlaps with what BuiltWith already gives you, and in many cases it is a subset. But sometimes it is a genuine complement. Some sites do not load certain scripts on the homepage, only when a visitor reaches a specific page, and that includes crawlers and bots. The script still sits in the GTM config, so Tagstack can surface technologies BuiltWith never sees fire.

The catch runs the other way too. A script sitting in a GTM container is not proof anyone is using it. Plenty of entries are inactive or stale, left behind long after the team stopped using the tool.

Strengths:

  • Surfaces scripts that only load on specific pages
  • Granular GTM audits
  • Consent mode analysis
  • JSON export

Limitations:

  • GTM-specific only
  • Stale entries can look like active technologies
  • Minimal CMS or general tech coverage

Pricing: Free tier; unlimited audits on paid plans

8. WhatRuns - Free Alternative

Best for: Freelancers, solo operators and casual researchers.

WhatRuns is a completely free browser extension providing basic technology detection with no account required.

And my basic technology detection, I mean basic. It'll show you the basic frontend technologies a website uses (ie JQuery, Google Analytics, Facebook Ads, etc), but it lacks data on a lot of modern technologies.

Use it if you're short on money and can't afford to pay money for any paid product. But keep in mind, you're not going to get much detailed data :)

Strengths:

  • Zero cost
  • Instant setup

Limitations:

  • Thinner coverage
  • No list building
  • Individual lookup only

Pricing: Free

9. urlscan.io - Security Research

Best for: Security researchers and OSINT investigators.

urlscan.io analyzes submitted URLs comprehensively, logging scripts and third-party services across internal pages that crawlers typically never reach. It's not a sales tool, but for understanding what a site actually loads it goes deeper than anything else here.

Some examples of how powerful it can be:

Let's say you're interested in knowing sites that load a particular Javascript. Perhaps you already use Builtwith/Wappalyzer but think there's more. Just do a search in urlscan.io for the domain of the Javascript file (ie stripe.com, or klaviyo.com) and it'll show you the most recent pages it found those scripts present at.

Another example: Let's say you want to know what SaaS products a company is using. If you search for a string such as companyname.., you'll find urls that have the company name in the tenant domain (ie companyname.slack.com). It won't reveal every single one, but only those that have been submitted by someone in the past.

Strengths:

  • Deep technical analysis
  • Internal page visibility
  • Network request logging

Limitations:

  • Steep learning curve
  • No sales-focused features

Pricing: Free

10. MerkleMap - Finding Internal Infrastructure

Best for: Researchers and sales teams who want to see what a company runs internally, not just what is on its website.

Every publicly trusted TLS certificate has to be published to certificate transparency logs, a public append-only record that anyone can read. MerkleMap indexes those logs continuously and lets you search them by domain, so you get the hostnames a company has issued certificates for, including internal and staging systems that are never linked from anywhere public.

That turns out to be a surprisingly direct way to see a tech stack, because companies name their subdomains after the software running on them. Search adobe.com and you get hostnames like codex-grafana.corp.adobe.com, codex-stage-grafana.corp.adobe.com, codex-qa-grafana.corp.adobe.com and codex-dev-grafana.corp.adobe.com, alongside a matching set for a system called sekhmet. From four rows you can tell Adobe runs Grafana, runs it on internal corp infrastructure, and maintains separate dev, QA, staging and production instances per service.

None of that appears on adobe.com, so a website crawler will never find it.

It is closest in spirit to urlscan.io, but the source is different. urlscan loads a page and records what it requests. MerkleMap reads certificate logs, which means it finds hosts that were never linked, never crawled, and in some cases were never meant to be public at all.

Strengths:

  • Reveals internal and staging infrastructure by name
  • Free web search, plus an API and CLI
  • Live tails new certificates as they are logged
  • Historical data, so you can see when a host first appeared

Limitations:

  • Only covers hostnames that have a publicly trusted certificate
  • Wildcard certificates can hide individual hostnames
  • You have to interpret hostnames yourself, there is no technology database
  • No firmographic data and no list building by technology

Pricing: Free to search; API and CLI available

Decision Framework

Choose based on the job, not the brand:

  • Backend software and adoption timing: Bloomberry
  • Browser convenience and deep-page detection: Wappalyzer
  • Ecommerce stores and Shopify apps: Store Leads
  • Cheap CMS, theme and framework data: TechPeeker
  • Backend software via hiring signals: JobsPipe
  • Free prospect lists: Hunter TechLookup
  • GTM specialization: Tagstack
  • Zero budget: WhatRuns
  • Security focus: urlscan.io
  • Internal infrastructure: MerkleMap

The useful way to think about this category is that every tool has a different blind spot, because every tool looks in a different place. Bloomberry monitors infrastructure signals, so is best for backend detection. BuiltWith crawls homepages. Wappalyzer sees whatever pages its users visit. Tagstack reads what is configured in GTM. MerkleMap reads certificates. JobsPipe reads what companies write in their job postings. Each one finds things the others structurally cannot.

BuiltWith remains strong for massive frontend technology lists, and if that is your use case there is no reason to switch. But if you keep hitting the same gap, the answer is usually a tool that looks somewhere else entirely rather than a bigger version of the same crawl.