Skip to main content
New Monthly plans from $39/mo. No contracts, cancel anytime. See pricing →

Custom Scan

Find websites by the files they serve

Type a file name, an asset path, or the host an asset loads from, and get every site carrying that footprint, across 360M+ websites. Built for the searches a technology catalogue cannot answer: one vulnerable build, a compromised third-party host, a plugin nobody wrote a detector for.

Searching is free 1 credit per export, any size Built for security research
StackScan Custom Scan: searching the asset index for woocommerce.css and finding 1,804,681 websites, with a sample list showing domain, country and TLD

The gap it fills

When the technology you are hunting has no name

Tech Lookup answers who runs Shopify. It works from a curated catalogue of 55,000+ named technologies, and it is the right tool almost every time.

But a catalogue can only contain what someone wrote a detector for. A niche WordPress plugin, one specific build of a theme, a competitor's tracking script, an internal SDK, a library version with a CVE against it: none of them have an entry, and none of them are searchable by name.

Custom Scan searches the raw asset index underneath the catalogue. Nothing has to be named or classified first. If a site loads the file, you can find the site.

Websites indexed

360M+

the StackScan crawl this index is built from

Distinct file names

Millions

searchable exactly, no list to pick from

Distinct asset paths

Millions

matched anywhere in the path

How it works

Three steps, and you only pay for the last one

There is no technology to pick and nothing to configure. Type the footprint you are after.

  1. 1

    Type a footprint

    A file name, an asset path, or an asset host. Paste a whole CDN URL if that is what you have; it gets reduced to the part the index holds.

  2. 2

    See what it matches

    A live count, ten sample sites with country and TLD, and optional country or TLD filters. This step is free and unlimited, so you can refine before you commit.

  3. 3

    Download the list

    One flat credit, whether the footprint matches two hundred sites or two million. The report lands in My Reports and can be re-downloaded free.

Three ways to search

One footprint, three angles on it

Every asset is indexed three ways. Which one you pick decides what "matches" means, so each is built for a different question.

File name

Exact match on the file itself, wherever it is served from. The fastest of the three and the right default.

Example

woocommerce.css

1,804,681 websites

File path

Matches the folder anywhere in an asset's path, so one query covers every file a plugin, theme or framework ships.

Example

/wp-content/plugins/elementor/

7,378,329 websites

Asset host

Exact match on the hostname an asset loads from. The way to find a SaaS platform, a CDN, or a third-party script vendor.

Example

static.parastorage.com

6,383,205 websites

Case never matters, and neither do the slashes: Swiper.js, swiper.js and a pasted https://cdn.example.com/dist/swiper.js?ver=9 all find the same sites.

Getting a footprint

From a page you already know to a list you can use

Running the search is easy. Knowing what to type is the part worth explaining, and it takes about a minute.

  1. Open one site that definitely runs it

    Any single example will do. You are going to read what it loads, not analyse it.

  2. Look at the Network tab, filtered to JS and CSS

    Reload the page with developer tools open. Everything Custom Scan indexes is in that list.

  3. Find something the vendor controls, not the site owner

    A plugin folder, a vendor's own CDN host, or a distinctively named file. Skip anything with a build hash in it, like app.4f3a91.js, and skip generic names like main.css: those belong to that one deployment, not to the product.

  4. Search it, then try a wider one and compare

    Searching is free, so never settle for the first footprint. If a folder and a single file disagree by a lot, the folder is usually closer to the real population.

A worked example

You sell a WooCommerce extension into Germany

Three decisions, and the free search tells you what each one costs before you spend anything.

Footprint
/wp-content/plugins/woocommerce/
3,315,987
+ Country
Germany
181,365
+ TLD
.de
77,619

The unfiltered footprint is far more than any single report carries. Two filters later it is 77,619 sites, which fits inside one export on every plan, and it still costs the one credit. Re-running the same footprint with different filters this billing period costs nothing at all.

Read the footprint guide

Security research

When an advisory lands, the question is who is running it

A technology catalogue can tell you who runs jQuery. It cannot tell you who runs the build with the CVE in it, or who is still loading assets from a host that changed hands last year. Exposure lives at the level of the exact file and the exact host, and that is the level Custom Scan searches.

The affected build, not the library

Version numbers live in the file name, so you can enumerate exactly the build an advisory names instead of everyone who ever used the project.

jquery-1.12.4.min.js 377,673 jquery-1.11.3.min.js 232,719

Supply-chain blast radius

When a third-party host is compromised or quietly changes hands, every site loading from it inherits the problem. polyfill.io was the subject of a widely reported 2024 supply-chain incident, and as of our current crawl it is still on the page for:

polyfill.io 16,016 cdn.polyfill.io 9,866

Third-party dependency surface

Size how much of the web hangs off each public CDN before you need the answer in a hurry, and re-run it whenever the picture changes.

cdnjs.cloudflare.com 5,833,844 cdn.jsdelivr.net 4,363,936 unpkg.com 1,356,171

Plugin exposure at scale

A plugin ships its assets from the same folder on every install, so one path search sizes the affected population for any advisory against it.

/wp-content/plugins/revslider/ 2,248,932

Scope, stated plainly: the index holds the JavaScript and CSS a site serves, so it maps client-side exposure. It does not see server-side files, configuration, or anything a page never links to. Counts are a floor rather than a census, for the reasons set out below.

Security research guide

What is included

Everything the tool does

Free, unlimited searching

Counts and samples cost nothing. Try twenty footprints, keep the one that works, and only pay when you download.

Answers in under a second

File name and asset host searches typically return in 0.1 to 0.4 seconds. Path searches take a couple of seconds because they scan wider.

Country and TLD filters

Narrow any footprint to up to five countries and five TLDs. Filters carry through to the export, so the file matches the count you saw.

Company data where we hold it

Every row carries domain, country, TLD and asset type. Roughly one in five also carries company name, headcount, year founded, industry, city and LinkedIn URL, and the share moves with the footprint.

One flat credit

An export costs the same whatever it matches, and the tool tells you up front how much of a large match set your plan will actually deliver.

Saved in My Reports

Every scan is kept with the footprint that produced it, alongside your Tech Lookup and Keyword Scan reports. Re-download as often as you like at no extra cost.

Use cases

Where else a file footprint beats a technology name

Beyond security work, the same index answers a set of commercial questions a catalogue cannot. Every example is a real search with a real result count.

Plugin and theme installs

Any WordPress plugin has a folder, whether or not anyone wrote a detector for it. One path search finds every install.

/wp-content/plugins/elementor/

7,378,329 sites

Competitor SDK tracking

Analytics, error tracking, chat widgets and payment SDKs all load from a vendor host. Search the host to get the customer list.

browser.sentry-cdn.com

4,265,089 sites

Theme populations

Themes are folders too, and most have no detector at all. Size a theme's install base, or find every site running the one your product plugs into.

/wp-content/themes/astra/

1,900,164 sites

Framework adoption

Modern build tools leave a fixed output directory. Track who is on which stack, and how fast that is changing.

/_astro/ /_next/

313,210 and 2,573,324 sites

Agency prospecting

Some footprints are a symptom. A site shipping its whole dependency folder to the browser is a site whose build nobody has looked at.

/node_modules/

237,620 sites

Try your own footprint

Searching costs nothing. Bring the file you already know your customers load and see how many sites carry it.

See plans

Reading the results

A footprint count is a floor, not a population

This is the one thing worth understanding before your first export, and it is the difference between a list you can act on and a number you misread.

Always
A site serving woocommerce.css runs WooCommerce.
Not always
A site running WooCommerce serves woocommerce.css.

Themes rename files, optimisation plugins concatenate them and CDNs rewrite paths, so one file only ever finds the sites still serving it under that name. A count is the part of the population you can prove, which is why it pays to choose the footprint carefully.

The same platform, three footprints

All three of these are WordPress. Which one you search decides how much of it you see.

/wp-content/
25,809,358
/wp-includes/js/
21,948,511
wp-embed.min.js
1,599,285

Sixteen times between the widest and the narrowest, and each is a true answer to the question it was asked. A directory the platform is built around is stable. A single optional script is not, because most themes never load it.

Choose the footprint, not just the technology

Search a folder the platform cannot move, or a host it owns, and you are close to the whole population. Search one optional file and you get the slice that still ships it under that name.

Searching is free, so the practical method is to try two or three footprints for the same thing and look at the spread before you spend a credit on any of them. Where a technology is new or niche the asset index is often the only place it shows up at all, because nothing has to be catalogued first.

Which tool

Custom Scan or Tech Lookup?

They read the same crawl from two different angles. Most lists start with Tech Lookup.

Use Tech Lookup when

  • The technology has a name you can look up
  • You want every install regardless of how it is served
  • You want to combine several technologies in one query
  • You need market share, country splits, or company size filters
Explore Tech Lookup

Use Custom Scan when

  • Nothing in the catalogue describes what you are hunting
  • You need one specific version or build, not the whole library
  • You already know the exact file, path, or host to look for
  • The thing is too new or too niche to have a detector yet
Start a custom scan

Questions

The things people ask first

What does it cost?

Searching is free and unlimited. An export is one credit, flat, whatever it matches. Re-running the same footprint in the same billing period, including with different filters, does not charge you again.

How fresh is the data?

The asset index is built from the same crawl that powers Tech Lookup and the technology pages, and is rebuilt when a new crawl lands. It is a snapshot of what each site was serving when we last visited it, not a live fetch.

Why is a count lower than I expected?

Almost always because the footprint is narrower than the thing you had in mind. One optional script finds a fraction of a platform; the folder it sits in finds most of it. Try a wider footprint and compare, which costs nothing.

Does it cover images, fonts or server files?

No. The index holds the JavaScript and CSS a site serves. That is what makes it good at client-side and third-party questions, and it is why it cannot answer anything about server configuration or files a page never links to.

What is actually in the export?

Domain, country, TLD and asset type on every row, plus company name, headcount, year founded, industry, city and LinkedIn URL where we hold a record, which is roughly one row in five. Reports are saved and can be re-downloaded free.

Is there an API for it?

Not yet. Custom Scan is a dashboard tool today; the API covers technology lookups and whole-technology lists. If you need footprint search over HTTP, tell us what you would call it with.

Fuller answers, including how to pick a footprint and how to read a count, are in the Custom Scan documentation.

Search the web by the files it serves

Nothing has to be named first. If a site loads the file, you can find the site.

Plans from $39/mo · No contracts, cancel anytime