Skip to content

How to Know if a Website Is Made With WordPress: 7 Tested Checks

How To Know If a Website Is Made with WordPress

To know if a website is made with WordPress, open its page source and search for /wp-content/. If that path appears, the site almost always runs WordPress. Adding /wp-json/ to the address settles it in seconds.

We did not stop at the usual advice. On 23 September 2026 we ran seven WordPress checks with curl against eight well known sites. The results show why one check is never enough, since a government site running WordPress passed only one of the seven.

Below you get the seven checks in the order worth trying them and the full test results. Then come the reasons a WordPress site can look like anything else. The last sections show how to tell if a website is WordPress, Shopify, Wix or Squarespace, and how to find its version.

How to Know if a Website Is Made With WordPress in 30 Seconds

The quickest way to answer “is it WordPress?” is to view its page source and search for /wp-content/. WordPress stores themes, plugins and uploads in that folder, so its path shows up in the links to images, styles and scripts. On a normal WordPress site it appears dozens of times.

In Chrome, right-click the page and choose View page source, or press Ctrl+U on Windows and Cmd+Option+U on a Mac. Then press Ctrl+F or Cmd+F and search for wp-content.

how to know if a website is made with WordPress by inspecting the page source

If you find nothing, try the address with /wp-json/ on the end. A WordPress site answers with a long block of JSON that lists its API routes. A site built on something else usually shows a 404 page instead.

Note: A “Powered by WordPress” credit in the footer is the weakest sign of all. Most themes let you remove it, and a few non-WordPress builders copy the wording.

Powered by WordPress credit in a website footer

7 Ways to Check if a Site Is WordPress

There are seven reliable ways to check whether a site is WordPress, and they work best in the order below. The first two need nothing but a browser and settle most cases. The later ones help when a site has been hardened to hide what it runs.

1. Search the Source for /wp-content/

This is the check from the section above, and it is the one that survived hardening best in our test. Search the page source for /wp-content/ and /wp-includes/. Theme files sit under /wp-content/themes/, and plugin files sit under /wp-content/plugins/.

It also tells you more than yes or no. On the TechCrunch homepage, the source pointed to a theme folder named tc-24, which is their own custom theme.

2. Open /wp-json/ in Your Browser

Add /wp-json/ to the end of the domain and load it. A WordPress site replies with JSON that includes a namespaces list, such as wp/v2.

The REST API discovery documentation explains the matching signal in the page itself. WordPress “automatically adds a Link header to all front-end pages” pointing at that API, and it carries the https://api.w.org/ relation. So a search for api.w.org in the source is a second way to spot it.

3. Read the Generator Tag

Search the source for generator. Many sites on this CMS print a meta tag whose content reads WordPress 7.1.2, giving away both the software and its version.

The wp_generator() reference describes this as the generator tag printed on the wp_head hook. Security plugins often remove it, so a missing tag proves nothing.

4. Try /wp-login.php or /wp-admin/

Add /wp-login.php to the domain. A WordPress site shows its login form, often with the WordPress logo on top. Visiting /wp-admin/ while logged out redirects you to that same page.

check the standard WordPress login URL

Some sites move the login page to a custom address, so a 404 here does not rule WordPress out. Never try to log in to a site you do not own.

5. Check the RSS Feed

Open /feed/ on the site. WordPress feeds carry a generator line, and on our test sites it read https://wordpress.org/?v= followed by the version number. Feeds are often left alone when the generator tag in the page head is removed.

6. Look for WordPress Files

A default WordPress install ships a readme.html and a license.txt in its root folder. If /license.txt opens a GPL license that starts with “WordPress – Web publishing software,” you have your answer.

check for WordPress specific files and directories

These files are easy to delete, and large sites usually do. None of the three WordPress sites in our test below still served readme.html.

7. Use a Detector Tool or Browser Extension

If you want to know how to check website is WordPress or not without reading any code, use a tool. Online detectors such as IsItWP and BuiltWith, and browser extensions such as Wappalyzer, run most of the checks above for you. They also try to name the theme and the plugins.

use online detection tools to check a WordPress website

They are fast, but they read the same public signals you can read yourself. A site that hides those signals fools the tools too, which is why the next section matters.

use a Chrome extension to identify a WordPress site

We Tested These Checks on 8 Sites: Here Is What Showed Up

We ran all seven checks with curl against eight well known sites on 23 September 2026. Two open WordPress sites showed six of the seven signs, while whitehouse.gov showed only one: the /wp-content/ path in its source. Five sites showed none at all.

This table shows every result. A check “passed” when the signal appeared exactly as described in the section above.

Site/wp-content//wp-json/Generator tagapi.w.org link/wp-login.phpFeed generatorreadme.htmlSignals found
techcrunch.comYesYesWordPress 6.9.9YesYesYesNo6 of 7
WordPress.orgYesYesWordPress 7.2 alphaYesYesYesNo6 of 7
whitehouse.govYesNoNoNoNoNoNo1 of 7
time.comNoNoNoNoNoNoNo0 of 7
blog.hubspot.comNoNoNoNoNoNoNo0 of 7
shopify.comNoNoNoNoNoNoNo0 of 7
wix.comNoNoNoNoNoNoNo0 of 7
squarespace.comNoNoNoNoNoNoNo0 of 7
is it WordPress test results on eight websites

Three things stand out. The source code check was the only one that caught every WordPress site in the table, including the hardened one. The readme.html file was gone from both large WordPress sites, so it is the least useful check.

TechCrunch also sent a header we did not test for. Its responses included x-powered-by: WordPress VIP, which names its managed WordPress host outright. Headers are worth a glance, since some hosts announce themselves there.

Zero signals does not always mean “not WordPress.” It means none of these public signs showed, and the next section explains how a WordPress site ends up there.

Why a WordPress Site Can Show No Signs

A WordPress site can show no signs because every public signal can be removed or hidden. Security plugins strip the generator tag, block the REST API for visitors and move the login page. A headless setup goes further and serves a front end that WordPress never touches.

Hardening explains a result like whitehouse.gov. Its pages still load files from /wp-content/.

But the API, the login page, the feed generator and the default files were all hidden from our requests. That is a deliberate security choice, and it works.

A headless build is harder to spot. In that setup, WordPress only stores the content, and a separate front end, often built with a JavaScript framework, shows it to visitors. The pages may load no WordPress files at all.

We saw the same pattern on a store outside WordPress. The Gymshark homepage answered with x-powered-by: Next.js in its headers, yet the page still loaded files from cdn.shopify.com. So the front end and the store engine were two different systems.

When a site shows nothing, check the asset links for image hosts and API calls. A headless WordPress front end often still pulls images from a /wp-content/uploads/ URL on another domain.

How to Tell WordPress From Shopify, Wix or Squarespace

You can tell WordPress apart from Shopify, Wix or Squarespace by the file hosts each platform uses. WordPress loads files from /wp-content/, while the hosted builders serve everything from their own content networks. In our test each platform left a fingerprint within the first page load.

These are the fingerprints we found on 23 September 2026:

PlatformWhat to search forWhere we saw it
WordPress/wp-content/ and /wp-includes/ pathstechcrunch.com, WordPress.org, whitehouse.gov
Shopifycdn.shopify.com and /cdn/shop/ pathsallbirds.com, 14 matches on the homepage
Wixstatic.wixstatic.com and parastorage.comwix.com, over 300 matches
Squarespacestatic1.squarespace.com, and a server: Squarespace headersquarespace.com

A site can match more than one row. Some brands run their store on Shopify and their blog on WordPress under a subdomain. Check the exact page you care about, because the homepage can run on something else.

This matters when you are sizing up a redesign or a migration. WordPress holds 40.2% of all websites and 58.8% of those with a known CMS, according to W3Techs usage statistics for 23 September 2026. So the odds favor WordPress, but the check still takes less than a minute.

How to Check Which WordPress Version a Site Runs

To check which WordPress version a site runs, search its page source for the generator tag or open its /feed/ page. Both often print the exact number, such as WordPress 7.1.2. If both are hidden, the version is usually not visible from the outside.

On our own test site at testing.devdiggers.com, the generator tag and the feed both read 7.1.2. TechCrunch’s homepage reported 6.9.9, and WordPress.org reported a 7.2 alpha build, which makes sense for the project that builds the software.

That openness is a small risk for your own site. A visible version number tells anyone exactly which fixes you have and which you lack.

Remove the generator tag and the default readme.html file, and keep WordPress updated so the number would not help an attacker anyway. Our WordPress version history lists what each release changed.

Tip: Keeping core, plugins and themes current is the part that slips for most owners. A WordPress care plan covers updates, backups and security checks as one monthly service.

You can find which WordPress theme a site uses the same way. A theme folder name in /wp-content/themes/ leads to that theme’s style.css file, which starts with its name and version. On our test site, that file named the Kadence theme, version 1.4.5.

Plugins show up the same way under /wp-content/plugins/. That is how people spot a store’s chat widget or form builder. Our roundup of WordPress chatbot plugins covers the ones you are most likely to find.

Conclusion

The fastest reliable way to know if a website is made with WordPress is to search its source for /wp-content/, then confirm with /wp-json/. In our test of eight sites, the source check was the only one that caught every WordPress site. That included one site that hid six of the seven signs.

When a site shows nothing, it is either not WordPress or it has been hardened or built headless. File hosts such as cdn.shopify.com or static.wixstatic.com usually settle which platform you are looking at. If you want to see how WordPress itself serves every page, our guide to index.php in WordPress explains the file behind it.

Frequently Asked Questions (FAQs)

Q1. Is this site WordPress if I built it with a host’s website builder?

Not always, since many hosts offer their own builders as well as WordPress. Log in to your hosting account and look for a WordPress install in the app list. You can also add /wp-admin/ to your domain, and a WordPress login page settles it.

Q2. Can a website hide that it uses WordPress?

Yes. Security plugins can remove the generator tag, block the REST API and move the login page. In our test, whitehouse.gov hid six of our seven checks, and only the /wp-content/ paths in its source gave it away.

Q3. How can I tell if a website is Shopify or WordPress?

Search the page source for cdn.shopify.com. If it appears and /wp-content/ does not, the page runs on Shopify. A site that shows both is often a Shopify store with a WordPress blog.

Q4. Is WordPress outdated in 2026?

No. WordPress runs 40.2% of all websites, according to W3Techs data for 23 September 2026. Version 7.1 shipped in August 2026, and the project keeps a regular release schedule.

Q5. Is a WordPress.com site the same as a WordPress site?

Both run the same WordPress software, so the checks above work on both. WordPress.com is a hosting service run by Automattic, while self-hosted WordPress runs on any host you choose.

Yes. Every check in this guide reads files and headers the site sends to any visitor. Trying to log in, guessing passwords or scanning for weaknesses on a site you do not own is a different matter, so stop at reading.

Ekta Lamba
Ekta Lamba

Ekta Lamba is a tech writer at DevDiggers focused on making WordPress and WooCommerce straightforward for non-developers. She covers plugin errors, platform updates, and WordPress basics, written so readers can follow along without a second tab open to translate the jargon.

Leave a Reply

Your email address will not be published. Required fields are marked *