How to Check if a Website Is WordPress (6 Quick Ways)

If you sell WordPress services, the first question about any prospect is simple: does this site actually run on WordPress? Knowing how to check if a website is WordPress saves you from pitching plugin updates to a Shopify store or offering Elementor fixes to a site built on Wix. The good news is that WordPress leaves plenty of fingerprints. In this guide you will learn quick manual checks anyone can do in a browser, why some sites are harder to identify, and how to check hundreds of sites without opening each one by hand.
Why check if a website runs WordPress?
For web designers, developers, SEO agencies and plugin or hosting sellers, the platform decides what you can offer. A WordPress site can be updated, sped up, migrated, secured or redesigned using tools you already know. A site on a closed builder usually cannot use your plugins, and the owner may not even have server access. Checking first means:
- Your outreach mentions things that are true about their site.
- You don’t waste time on prospects you can’t help.
- You can tailor your offer, for example maintenance for an older WordPress install or a speed fix for a heavy theme.
How to check if a website is WordPress by hand
None of these checks needs special software. Try them in order; usually the first or second one gives you a clear answer.
1. View the page source and search for wp-content
Open the site, right-click and choose View Page Source (or press Ctrl+U). Then press Ctrl+F and search for wp-content. WordPress stores themes, plugins and uploads in that folder, so you will often see lines like:
/wp-content/themes/theme-name/style.css/wp-content/plugins/plugin-name/.../wp-content/uploads/2024/05/photo.jpg
Also search for wp-includes, which is the core WordPress folder for scripts such as jQuery. If both appear, you can be fairly confident. As a bonus, the theme and plugin folder names tell you what the site is built with.
2. Check the WordPress REST API at /wp-json/
Most WordPress sites expose a REST API. Add /wp-json/ to the end of the domain, for example example.com/wp-json/. If you see a block of JSON text mentioning the site name, routes and namespaces like wp/v2, the site is running WordPress. You may also find a link tag in the source pointing to https://api.w.org/, which is another strong sign.
3. Try the login page
Visit example.com/wp-login.php or example.com/wp-admin/. A WordPress login form (often with the WordPress logo, or the site’s own logo if customised) is a clear signal. Some owners move or protect this page with security plugins, so a missing login page does not prove the site is not WordPress. Just look; never try to log in.
4. Look for the generator meta tag
In the page source, search for generator. By default WordPress adds a tag like <meta name="generator" content="WordPress 6.x">. It may also reveal the version, which is useful if you offer updates or maintenance. Many SEO and security plugins remove this tag, so treat it as a bonus rather than a requirement.
5. Check the WordPress readme.html and license.txt
Fresh WordPress installs include example.com/readme.html and example.com/license.txt. If they load and mention WordPress, you have your answer. Many careful site owners delete these files, so their absence means little.
6. Look at the RSS feed
Visit example.com/feed/. WordPress feeds usually include a line like <generator>https://wordpress.org/?v=6.x</generator>. Even when the meta tag is removed from the homepage, the feed sometimes still shows it.
Quick reference table
| Check | Where to look | What a WordPress site shows |
|---|---|---|
| Source code | View Page Source, search wp-content |
Theme, plugin and upload paths |
| REST API | /wp-json/ |
JSON with wp/v2 routes |
| Login page | /wp-login.php |
WordPress login form |
| Generator tag | Search source for generator |
“WordPress” plus version |
| Readme | /readme.html |
WordPress readme page |
| Feed | /feed/ |
Generator line with wordpress.org |
Why some WordPress sites are hard to detect
Sometimes every check above comes back empty, yet the site is still WordPress. Common reasons:
- Security plugins hide the version number, rename the login URL or block the REST API for visitors.
- Caching and CDNs combine and rename files, so
wp-contentpaths are replaced with hashed file names or a CDN domain. - Headless setups use WordPress only as a back end, while the public site is built with a JavaScript framework. The front end may show no WordPress traces at all.
- Custom folder names: developers can rename
wp-contentto something else. - Firewalls such as Cloudflare may show a challenge page to automated requests, which hides the real HTML.
This is why relying on a single signal is risky. A homepage guess can easily miss a hardened site or, in rare cases, flag a non-WordPress site that simply links to an image hosted on a WordPress blog. A reliable check combines several signals: theme and plugin paths, the REST API, the login page, the generator tag and so on.
What about browser extensions and online WordPress detectors?
A WordPress detector extension or a “what CMS is this” website is handy when you are browsing and want a quick answer about the page in front of you. They use similar signals and work well for one site at a time, but they are not built for checking a list of 500 domains.
How to check many websites for WordPress in bulk
Manual checks take around a minute per site once you are practised. That is fine for a handful of prospects, but if you are building a lead list of local businesses, it quickly becomes hours of copy and paste. For bulk checking you have a few options:
- A spreadsheet plus manual checks. Slow but free. Paste domains into a sheet and add a “WordPress? Y/N” column as you go.
- Write a script. If you code, you can request each homepage and
/wp-json/and look for the signals above. You will need to handle timeouts, redirects, duplicates and firewall pages yourself. - Use a dedicated tool that runs multiple checks per site, in parallel, and exports the results.
Whatever you choose, clean your list first: remove duplicates, strip http://, www. and trailing paths, so each domain is checked once. Our guide to finding emails from a list of domains walks through list preparation in detail.
Checking sites in bulk with WP Finder
WP Finder was built for exactly this job. You can paste or load your own domain list (.txt or .csv, thousands of domains, duplicates skipped) or search by keyword and country, such as “dentist leeds”, to collect sites that rank. Each site gets a proper WordPress check covering themes, plugins, the REST API, the login page and more, rather than a homepage guess. It checks up to 40 sites at the same time and shows results live.
Because you usually want to contact the WordPress sites you find, it also pulls public emails, phone and WhatsApp numbers and social links from each site’s own pages, and exports everything to Excel or CSV. You can see the full list on the features page, and the first 150 sites are free to try from the download page.
What to do once you know a site is WordPress
Detection is only the first step. Use what you learned to shape your pitch: an old WordPress version suggests a maintenance offer, a heavy page builder suggests a speed audit, and a dated theme suggests a redesign. For ideas, read how to find outdated WordPress websites and our full guide to WordPress lead generation. If you then email owners, keep messages relevant, honour opt-out requests and follow the rules that apply to you, such as GDPR, PECR or CAN-SPAM.
Conclusion
Learning how to check if a website is WordPress takes a few minutes: look for wp-content in the source, try /wp-json/, check the login page, the generator tag, the readme and the feed. Use several signals together, because hardened sites hide some of them. For one-off checks the browser is enough; for whole lists, a bulk tool will save you hours and give you cleaner data to work with.
FAQ
What is the fastest way to check if a website is WordPress?
Open the page source with Ctrl+U and search for “wp-content”. If you see theme or plugin paths, the site almost certainly runs WordPress. If not, try adding /wp-json/ to the domain.
Can a WordPress site hide that it uses WordPress?
Yes. Security plugins, caching, CDNs, renamed folders and headless setups can hide many signals. That is why checking several signals together is more reliable than relying on one.
Is it legal to check if a website uses WordPress?
Looking at a public page’s source code and public URLs is normal browsing. Don’t try to log in, bypass security or access anything that isn’t public.
How can I check if hundreds of websites run WordPress?
Clean and dedupe your domain list, then use a script or a bulk tool that runs several WordPress checks per site in parallel and exports the results to a spreadsheet.