whatweb: Identifies technologies used by websites

whatweb: Identifies technologies used by websites

WhatWeb is a Ruby-based web technology fingerprinting tool created by Andrew Horton (urbanadventurer). It identifies what a website is running — CMS platforms (WordPress, Joomla, Drupal), web servers, JavaScript frameworks, analytics packages, blogging platforms, embedded devices, and more — using a plugin system with over 1,800 plugins. Each plugin recognizes technology through page content, HTTP headers, cookies, and specific URL patterns. WhatWeb supports adjustable “aggression” levels, from a single stealthy HTTP request to a fully aggressive multi-request fingerprinting scan.

How to Install

Pre-installed on Kali Linux. To verify or reinstall:

which whatweb
sudo apt update
sudo apt install whatweb -y
whatweb --version

Install from source:

git clone https://github.com/urbanadventurer/WhatWeb.git
cd WhatWeb
gem install bundler
bundle install
./whatweb --version

Syntax

whatweb [options] <target>

All Command-Line Options

OptionDescription
-a, --aggression=<1-4>Set aggression level: 1=stealthy, 3=aggressive (default), 4=heavy
-v, --verboseVerbose output including plugin descriptions
--color=<never|always|auto>Control colored output
-i, --input-file=<file>Scan a list of targets from a file
-l, --list-pluginsList all available plugins
-p, --plugins=<plugin1,plugin2>Run only specific plugins
--info-plugins=<plugin>Show detailed info about a plugin
-e, --error-log=<file>Log errors to a file
--log-brief=<file>Brief log output format
--log-verbose=<file>Verbose log format
--log-xml=<file>Output in XML format
--log-json=<file>Output in JSON format
--log-json-verbose=<file>Verbose JSON output
--log-sql=<file>Output as SQL insert statements
--log-sql-verbose=<file>Verbose SQL output
--log-magictree=<file>Output for MagicTree import
--log-mongo-db=<config>Log directly to MongoDB
-U, --user-agent=<string>Set custom User-Agent
--header-line=<header>Add custom HTTP header
--follow-redirect=<policy>Redirect policy: never, http-only, meta-only, same-site, always
-o, --open-timeout=<secs>Connection open timeout
-t, --max-threads=<num>Max concurrent threads (default 25)
--proxy=<host:port>Use HTTP proxy
--proxy-user=<user:pass>Proxy authentication
-N, --wait=<secs>Delay between requests
-m, --max-redirects=<num>Max redirects to follow
-g, --grepGrep-friendly output (only match strings)
--no-errorsSuppress error output
-q, --quietSuppress banner
-A, --list-agentsList available user agents
-x, --extension=<value>Custom file extension handling

Basic Usage (Expected Output in Bash)

$ whatweb testphp.vulnweb.com

Output:

http://testphp.vulnweb.com [200 OK] Apache[2.4.29], Country[UNITED STATES][US], 
HTTPServer[Apache/2.4.29 (Ubuntu)], IP[44.228.249.3], PHP[5.6.40], 
PoweredBy[PHP/5.6.40], Script, Title[Home of Acunetix Art], X-Powered-By[PHP/5.6.40]

Practical Examples with Output

Example 1 — Verbose scan with plugin descriptions

$ whatweb -v testphp.vulnweb.com

Output:

WhatWeb report for http://testphp.vulnweb.com
Status    : 200 OK
Title     : Home of Acunetix Art
IP        : 44.228.249.3
Country   : UNITED STATES, US

Summary   : Apache[2.4.29], PHP[5.6.40], HTTPServer[Apache/2.4.29 (Ubuntu)]

Detected Plugins:
[ Apache ]
     The Apache HTTP Server Project
     Version      : 2.4.29 (from HTTP Server Header)

Example 2 — Aggressive fingerprinting (level 4)

$ whatweb -a 4 https://example.com

Output:

https://example.com [200 OK] Content-Security-Policy[default-src 'self'], 
HTML5, HTTPServer[cloudflare], JQuery[3.6.0], Script[text/javascript], 
Title[Example Domain], X-Frame-Options[SAMEORIGIN]

Example 3 — Scan a list of targets from a file

$ cat targets.txt
example.com
testphp.vulnweb.com
$ whatweb -i targets.txt

Output:

http://example.com [200 OK] HTTPServer[cloudflare], Title[Example Domain]
http://testphp.vulnweb.com [200 OK] Apache[2.4.29], PHP[5.6.40]

Example 4 — Output results as JSON

$ whatweb --log-json=results.json testphp.vulnweb.com
$ cat results.json | jq '.[0].plugins.HTTPServer'

Output:

{"string": ["Apache/2.4.29 (Ubuntu)"]}

Example 5 — Grep-friendly output for scripting

$ whatweb -g testphp.vulnweb.com

Output:

testphp.vulnweb.com    Apache[2.4.29]  PHP[5.6.40]     Title[Home of Acunetix Art]

Example 6 — List all available plugins

$ whatweb -l | head -5

Output:

WhatWeb - Next generation web scanner version 0.5.5.
1602 plugins loaded.
403-Forbidden-Message
7-Sins-CMS
ACID-3.0

Example 7 — Scan through a proxy (Burp)

$ whatweb --proxy=127.0.0.1:8080 testphp.vulnweb.com

Output:

http://testphp.vulnweb.com [200 OK] Apache[2.4.29], PHP[5.6.40]
[+] Traffic routed through proxy at 127.0.0.1:8080

Example 8 — Stealthy single-request scan

$ whatweb -a 1 https://example.com

Output:

https://example.com [200 OK] HTTPServer[cloudflare], Title[Example Domain]

Example 9 — Custom User-Agent to avoid basic bot detection

$ whatweb -U "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" testphp.vulnweb.com

Output:

http://testphp.vulnweb.com [200 OK] Apache[2.4.29], PHP[5.6.40]

Common Use Cases

  • Rapid technology stack fingerprinting at the start of a reconnaissance phase.
  • Identifying CMS platform and version to search for known CVEs (e.g., WordPress plugin vulnerabilities).
  • Bulk fingerprinting of a large target list during bug bounty or asset inventory work.
  • Confirming WAF/CDN presence (Cloudflare, Akamai) before choosing scanning aggression.
  • Feeding structured JSON/XML output into larger recon automation pipelines.

Automation with Bash

#!/bin/bash
# whatweb-bulk-fingerprint.sh — fingerprint a list of domains and save JSON per host

DOMAINS_FILE="domains.txt"
OUTDIR="whatweb-results"
mkdir -p "$OUTDIR"

while IFS= read -r domain; do
    [ -z "$domain" ] && continue
    echo "[*] Fingerprinting $domain"
    whatweb -a 3 --log-json="$OUTDIR/${domain}.json" "$domain" -q
done < "$DOMAINS_FILE"

echo "[*] Extracting detected CMS platforms..."
for f in "$OUTDIR"/*.json; do
    jq -r '.[0].plugins | keys[]' "$f" 2>/dev/null | grep -iE 'wordpress|joomla|drupal'
done

Tips and Best Practices

  • Use aggression level 1 for stealthy recon and level 3–4 when thoroughness matters more than noise.
  • Combine WhatWeb with Wappalyzer CLI for cross-validation of detected technologies.
  • Use --log-json output for automated pipelines rather than parsing human-readable text.
  • Rotate User-Agents (-U) when scanning many hosts to reduce basic bot-detection triggers.
  • Use -i with a target file for efficient bulk scanning instead of looping shell calls.

Troubleshooting

IssueCauseFix
No plugins matchedSite behind CDN/WAF masking headersIncrease -a aggression level
Connection timeoutsSlow/unresponsive targetIncrease -o open-timeout value
SSL errors on HTTPS targetsCertificate validation issuesTry --no-errors or verify cert manually with openssl s_client
Rate-limited / blockedToo many concurrent threadsLower -t thread count and add -N delay
Empty JSON log fileWrong file path/permissionsVerify write permission on output directory

References

  • Official GitHub repository: https://github.com/urbanadventurer/WhatWeb
  • Kali tool page: https://www.kali.org/tools/whatweb/
  • Plugin development wiki: https://github.com/urbanadventurer/WhatWeb/wiki
Total
0
Shares

Leave a Reply

Previous Post
wapiti: Scans web applications for vulnerabilities

wapiti: Scans web applications for vulnerabilities

Next Post
wpscan: WordPress security scanner

wpscan: WordPress security scanner

Related Posts