WhatWeb is a Ruby-based web technology fingerprinting tool created by Andrew Horton (urbanadventurer). It identifies what a website is running — CMS platforms (WordPress, Joomla, Drupal), web servers, JavaScript frameworks, analytics packages, blogging platforms, embedded devices, and more — using a plugin system with over 1,800 plugins. Each plugin recognizes technology through page content, HTTP headers, cookies, and specific URL patterns. WhatWeb supports adjustable “aggression” levels, from a single stealthy HTTP request to a fully aggressive multi-request fingerprinting scan.
How to Install
Pre-installed on Kali Linux. To verify or reinstall:
which whatweb
sudo apt update
sudo apt install whatweb -y
whatweb --version
Install from source:
git clone https://github.com/urbanadventurer/WhatWeb.git
cd WhatWeb
gem install bundler
bundle install
./whatweb --version
Syntax
whatweb [options] <target>
All Command-Line Options
| Option | Description |
|---|---|
-a, --aggression=<1-4> | Set aggression level: 1=stealthy, 3=aggressive (default), 4=heavy |
-v, --verbose | Verbose output including plugin descriptions |
--color=<never|always|auto> | Control colored output |
-i, --input-file=<file> | Scan a list of targets from a file |
-l, --list-plugins | List all available plugins |
-p, --plugins=<plugin1,plugin2> | Run only specific plugins |
--info-plugins=<plugin> | Show detailed info about a plugin |
-e, --error-log=<file> | Log errors to a file |
--log-brief=<file> | Brief log output format |
--log-verbose=<file> | Verbose log format |
--log-xml=<file> | Output in XML format |
--log-json=<file> | Output in JSON format |
--log-json-verbose=<file> | Verbose JSON output |
--log-sql=<file> | Output as SQL insert statements |
--log-sql-verbose=<file> | Verbose SQL output |
--log-magictree=<file> | Output for MagicTree import |
--log-mongo-db=<config> | Log directly to MongoDB |
-U, --user-agent=<string> | Set custom User-Agent |
--header-line=<header> | Add custom HTTP header |
--follow-redirect=<policy> | Redirect policy: never, http-only, meta-only, same-site, always |
-o, --open-timeout=<secs> | Connection open timeout |
-t, --max-threads=<num> | Max concurrent threads (default 25) |
--proxy=<host:port> | Use HTTP proxy |
--proxy-user=<user:pass> | Proxy authentication |
-N, --wait=<secs> | Delay between requests |
-m, --max-redirects=<num> | Max redirects to follow |
-g, --grep | Grep-friendly output (only match strings) |
--no-errors | Suppress error output |
-q, --quiet | Suppress banner |
-A, --list-agents | List available user agents |
-x, --extension=<value> | Custom file extension handling |
Basic Usage (Expected Output in Bash)
$ whatweb testphp.vulnweb.com
Output:
http://testphp.vulnweb.com [200 OK] Apache[2.4.29], Country[UNITED STATES][US],
HTTPServer[Apache/2.4.29 (Ubuntu)], IP[44.228.249.3], PHP[5.6.40],
PoweredBy[PHP/5.6.40], Script, Title[Home of Acunetix Art], X-Powered-By[PHP/5.6.40]
Practical Examples with Output
Example 1 — Verbose scan with plugin descriptions
$ whatweb -v testphp.vulnweb.com
Output:
WhatWeb report for http://testphp.vulnweb.com
Status : 200 OK
Title : Home of Acunetix Art
IP : 44.228.249.3
Country : UNITED STATES, US
Summary : Apache[2.4.29], PHP[5.6.40], HTTPServer[Apache/2.4.29 (Ubuntu)]
Detected Plugins:
[ Apache ]
The Apache HTTP Server Project
Version : 2.4.29 (from HTTP Server Header)
Example 2 — Aggressive fingerprinting (level 4)
$ whatweb -a 4 https://example.com
Output:
https://example.com [200 OK] Content-Security-Policy[default-src 'self'],
HTML5, HTTPServer[cloudflare], JQuery[3.6.0], Script[text/javascript],
Title[Example Domain], X-Frame-Options[SAMEORIGIN]
Example 3 — Scan a list of targets from a file
$ cat targets.txt
example.com
testphp.vulnweb.com
$ whatweb -i targets.txt
Output:
http://example.com [200 OK] HTTPServer[cloudflare], Title[Example Domain]
http://testphp.vulnweb.com [200 OK] Apache[2.4.29], PHP[5.6.40]
Example 4 — Output results as JSON
$ whatweb --log-json=results.json testphp.vulnweb.com
$ cat results.json | jq '.[0].plugins.HTTPServer'
Output:
{"string": ["Apache/2.4.29 (Ubuntu)"]}
Example 5 — Grep-friendly output for scripting
$ whatweb -g testphp.vulnweb.com
Output:
testphp.vulnweb.com Apache[2.4.29] PHP[5.6.40] Title[Home of Acunetix Art]
Example 6 — List all available plugins
$ whatweb -l | head -5
Output:
WhatWeb - Next generation web scanner version 0.5.5.
1602 plugins loaded.
403-Forbidden-Message
7-Sins-CMS
ACID-3.0
Example 7 — Scan through a proxy (Burp)
$ whatweb --proxy=127.0.0.1:8080 testphp.vulnweb.com
Output:
http://testphp.vulnweb.com [200 OK] Apache[2.4.29], PHP[5.6.40]
[+] Traffic routed through proxy at 127.0.0.1:8080
Example 8 — Stealthy single-request scan
$ whatweb -a 1 https://example.com
Output:
https://example.com [200 OK] HTTPServer[cloudflare], Title[Example Domain]
Example 9 — Custom User-Agent to avoid basic bot detection
$ whatweb -U "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" testphp.vulnweb.com
Output:
http://testphp.vulnweb.com [200 OK] Apache[2.4.29], PHP[5.6.40]
Common Use Cases
- Rapid technology stack fingerprinting at the start of a reconnaissance phase.
- Identifying CMS platform and version to search for known CVEs (e.g., WordPress plugin vulnerabilities).
- Bulk fingerprinting of a large target list during bug bounty or asset inventory work.
- Confirming WAF/CDN presence (Cloudflare, Akamai) before choosing scanning aggression.
- Feeding structured JSON/XML output into larger recon automation pipelines.
Automation with Bash
#!/bin/bash
# whatweb-bulk-fingerprint.sh — fingerprint a list of domains and save JSON per host
DOMAINS_FILE="domains.txt"
OUTDIR="whatweb-results"
mkdir -p "$OUTDIR"
while IFS= read -r domain; do
[ -z "$domain" ] && continue
echo "[*] Fingerprinting $domain"
whatweb -a 3 --log-json="$OUTDIR/${domain}.json" "$domain" -q
done < "$DOMAINS_FILE"
echo "[*] Extracting detected CMS platforms..."
for f in "$OUTDIR"/*.json; do
jq -r '.[0].plugins | keys[]' "$f" 2>/dev/null | grep -iE 'wordpress|joomla|drupal'
done
Tips and Best Practices
- Use aggression level 1 for stealthy recon and level 3–4 when thoroughness matters more than noise.
- Combine WhatWeb with Wappalyzer CLI for cross-validation of detected technologies.
- Use
--log-jsonoutput for automated pipelines rather than parsing human-readable text. - Rotate User-Agents (
-U) when scanning many hosts to reduce basic bot-detection triggers. - Use
-iwith a target file for efficient bulk scanning instead of looping shell calls.
Troubleshooting
| Issue | Cause | Fix |
|---|---|---|
| No plugins matched | Site behind CDN/WAF masking headers | Increase -a aggression level |
| Connection timeouts | Slow/unresponsive target | Increase -o open-timeout value |
| SSL errors on HTTPS targets | Certificate validation issues | Try --no-errors or verify cert manually with openssl s_client |
| Rate-limited / blocked | Too many concurrent threads | Lower -t thread count and add -N delay |
| Empty JSON log file | Wrong file path/permissions | Verify write permission on output directory |
References
- Official GitHub repository: https://github.com/urbanadventurer/WhatWeb
- Kali tool page: https://www.kali.org/tools/whatweb/
- Plugin development wiki: https://github.com/urbanadventurer/WhatWeb/wiki