File name
Exact match on the file itself, wherever it is served from. The fastest of the three and the right default.
Example
woocommerce.css
1,804,681 websites
Custom Scan
Type a file name, an asset path, or the host an asset loads from, and get every site carrying that footprint, across 360M+ websites. Built for the searches a technology catalogue cannot answer: one vulnerable build, a compromised third-party host, a plugin nobody wrote a detector for.
The gap it fills
Tech Lookup answers who runs Shopify. It works from a curated catalogue of 55,000+ named technologies, and it is the right tool almost every time.
But a catalogue can only contain what someone wrote a detector for. A niche WordPress plugin, one specific build of a theme, a competitor's tracking script, an internal SDK, a library version with a CVE against it: none of them have an entry, and none of them are searchable by name.
Custom Scan searches the raw asset index underneath the catalogue. Nothing has to be named or classified first. If a site loads the file, you can find the site.
Websites indexed
360M+
the StackScan crawl this index is built from
Distinct file names
Millions
searchable exactly, no list to pick from
Distinct asset paths
Millions
matched anywhere in the path
How it works
There is no technology to pick and nothing to configure. Type the footprint you are after.
A file name, an asset path, or an asset host. Paste a whole CDN URL if that is what you have; it gets reduced to the part the index holds.
A live count, ten sample sites with country and TLD, and optional country or TLD filters. This step is free and unlimited, so you can refine before you commit.
One flat credit, whether the footprint matches two hundred sites or two million. The report lands in My Reports and can be re-downloaded free.
Three ways to search
Every asset is indexed three ways. Which one you pick decides what "matches" means, so each is built for a different question.
Exact match on the file itself, wherever it is served from. The fastest of the three and the right default.
Example
woocommerce.css
1,804,681 websites
Matches the folder anywhere in an asset's path, so one query covers every file a plugin, theme or framework ships.
Example
/wp-content/plugins/elementor/
7,378,329 websites
Exact match on the hostname an asset loads from. The way to find a SaaS platform, a CDN, or a third-party script vendor.
Example
static.parastorage.com
6,383,205 websites
Case never matters, and neither do the slashes: Swiper.js, swiper.js and a pasted https://cdn.example.com/dist/swiper.js?ver=9 all find the same sites.
Getting a footprint
Running the search is easy. Knowing what to type is the part worth explaining, and it takes about a minute.
Any single example will do. You are going to read what it loads, not analyse it.
Reload the page with developer tools open. Everything Custom Scan indexes is in that list.
A plugin folder, a vendor's own CDN host, or a distinctively named file. Skip anything with a build hash in it, like app.4f3a91.js, and skip generic names like main.css: those belong to that one deployment, not to the product.
Searching is free, so never settle for the first footprint. If a folder and a single file disagree by a lot, the folder is usually closer to the real population.
A worked example
Three decisions, and the free search tells you what each one costs before you spend anything.
The unfiltered footprint is far more than any single report carries. Two filters later it is 77,619 sites, which fits inside one export on every plan, and it still costs the one credit. Re-running the same footprint with different filters this billing period costs nothing at all.
Read the footprint guideSecurity research
A technology catalogue can tell you who runs jQuery. It cannot tell you who runs the build with the CVE in it, or who is still loading assets from a host that changed hands last year. Exposure lives at the level of the exact file and the exact host, and that is the level Custom Scan searches.
Version numbers live in the file name, so you can enumerate exactly the build an advisory names instead of everyone who ever used the project.
jquery-1.12.4.min.js 377,673 jquery-1.11.3.min.js 232,719
When a third-party host is compromised or quietly changes hands, every site loading from it inherits the problem. polyfill.io was the subject of a widely reported 2024 supply-chain incident, and as of our current crawl it is still on the page for:
polyfill.io 16,016 cdn.polyfill.io 9,866
Size how much of the web hangs off each public CDN before you need the answer in a hurry, and re-run it whenever the picture changes.
cdnjs.cloudflare.com 5,833,844 cdn.jsdelivr.net 4,363,936 unpkg.com 1,356,171
A plugin ships its assets from the same folder on every install, so one path search sizes the affected population for any advisory against it.
/wp-content/plugins/revslider/ 2,248,932
Scope, stated plainly: the index holds the JavaScript and CSS a site serves, so it maps client-side exposure. It does not see server-side files, configuration, or anything a page never links to. Counts are a floor rather than a census, for the reasons set out below.
Security research guideWhat is included
Counts and samples cost nothing. Try twenty footprints, keep the one that works, and only pay when you download.
File name and asset host searches typically return in 0.1 to 0.4 seconds. Path searches take a couple of seconds because they scan wider.
Narrow any footprint to up to five countries and five TLDs. Filters carry through to the export, so the file matches the count you saw.
Every row carries domain, country, TLD and asset type. Roughly one in five also carries company name, headcount, year founded, industry, city and LinkedIn URL, and the share moves with the footprint.
An export costs the same whatever it matches, and the tool tells you up front how much of a large match set your plan will actually deliver.
Every scan is kept with the footprint that produced it, alongside your Tech Lookup and Keyword Scan reports. Re-download as often as you like at no extra cost.
Use cases
Beyond security work, the same index answers a set of commercial questions a catalogue cannot. Every example is a real search with a real result count.
Any WordPress plugin has a folder, whether or not anyone wrote a detector for it. One path search finds every install.
/wp-content/plugins/elementor/
7,378,329 sites
Analytics, error tracking, chat widgets and payment SDKs all load from a vendor host. Search the host to get the customer list.
browser.sentry-cdn.com
4,265,089 sites
Themes are folders too, and most have no detector at all. Size a theme's install base, or find every site running the one your product plugs into.
/wp-content/themes/astra/
1,900,164 sites
Modern build tools leave a fixed output directory. Track who is on which stack, and how fast that is changing.
/_astro/ /_next/
313,210 and 2,573,324 sites
Some footprints are a symptom. A site shipping its whole dependency folder to the browser is a site whose build nobody has looked at.
/node_modules/
237,620 sites
Searching costs nothing. Bring the file you already know your customers load and see how many sites carry it.
See plansReading the results
This is the one thing worth understanding before your first export, and it is the difference between a list you can act on and a number you misread.
Themes rename files, optimisation plugins concatenate them and CDNs rewrite paths, so one file only ever finds the sites still serving it under that name. A count is the part of the population you can prove, which is why it pays to choose the footprint carefully.
All three of these are WordPress. Which one you search decides how much of it you see.
Sixteen times between the widest and the narrowest, and each is a true answer to the question it was asked. A directory the platform is built around is stable. A single optional script is not, because most themes never load it.
Search a folder the platform cannot move, or a host it owns, and you are close to the whole population. Search one optional file and you get the slice that still ships it under that name.
Searching is free, so the practical method is to try two or three footprints for the same thing and look at the spread before you spend a credit on any of them. Where a technology is new or niche the asset index is often the only place it shows up at all, because nothing has to be catalogued first.
Which tool
They read the same crawl from two different angles. Most lists start with Tech Lookup.
Questions
Searching is free and unlimited. An export is one credit, flat, whatever it matches. Re-running the same footprint in the same billing period, including with different filters, does not charge you again.
The asset index is built from the same crawl that powers Tech Lookup and the technology pages, and is rebuilt when a new crawl lands. It is a snapshot of what each site was serving when we last visited it, not a live fetch.
Almost always because the footprint is narrower than the thing you had in mind. One optional script finds a fraction of a platform; the folder it sits in finds most of it. Try a wider footprint and compare, which costs nothing.
No. The index holds the JavaScript and CSS a site serves. That is what makes it good at client-side and third-party questions, and it is why it cannot answer anything about server configuration or files a page never links to.
Domain, country, TLD and asset type on every row, plus company name, headcount, year founded, industry, city and LinkedIn URL where we hold a record, which is roughly one row in five. Reports are saved and can be re-downloaded free.
Not yet. Custom Scan is a dashboard tool today; the API covers technology lookups and whole-technology lists. If you need footprint search over HTTP, tell us what you would call it with.
Fuller answers, including how to pick a footprint and how to read a count, are in the Custom Scan documentation.
Nothing has to be named first. If a site loads the file, you can find the site.
Plans from $39/mo · No contracts, cancel anytime