PluginView detects Heap, a Analytics and Analytics, Product Intelligence & Monitoring, by evaluating script sources, javascript globals on publicly reachable pages. Illustrative public indicators associated with Heap include cdn.heapanalytics.com, heap-0.js, heap.version.heapJsVersion:. The listed vendor-controlled browser component was present and active on the scanned page at scan time. Full fingerprint rules remain proprietary; this page summarizes the signal classes and example indicators used for identification.
Detection looks at script sources, javascript globals across 3 fingerprint rules among the site's public responses.
Websites using Heap
Loading website list…
Signal classes
PluginView evaluates public page signals in these classes when identifying Heap. Individual fingerprint rule bodies are proprietary and are not published.
- Script sources
- JavaScript globals
Example public indicators for Heap
Illustrative indicators derived from public catalog metadata for Heap. A live scan may match additional proprietary rules beyond these examples.
- cdn.heapanalytics.com
- heap-0.js
- heap.version.heapJsVersion:
What a detection means
- Establishes
- The listed vendor-controlled browser component was present and active on the scanned page at scan time.
- Does not establish
- It does not prove a sitewide installation, current commercial contract, backend-only use, exclusive use, or production transaction volume.
Minimum proof rule
Observe a live browser request, loaded script, or iframe to the listed unique vendor endpoint. Source-text-only matches do not qualify.
Best pages to check: All pages; interact and wait
How to check a site for Heap
- 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest Heap signals (prefer: All pages; interact and wait).
- 2. PluginView reads only public responses (script sources, javascript globals) and scores them against the Heap signature set (3 rules).
- 3. Review the confidence score and text explanation for Heap on the results page.
FAQ: detecting Heap
- Can PluginView detect Heap without logging in?
- Yes. PluginView only reads publicly accessible responses when checking for Heap — typically script sources, javascript globals. It does not bypass authentication or paywalls.
- What category is Heap?
- Heap is classified under Analytics, Analytics, Product Intelligence & Monitoring in the PluginView directory.
- How many fingerprint rules cover Heap?
- This reference currently tracks 3 fingerprint rules across script sources, javascript globals. Individual rule bodies are proprietary and are not published.
- What public signals suggest a site uses Heap?
- Illustrative public indicators for Heap include cdn.heapanalytics.com; heap-0.js; heap.version.heapJsVersion:. A live scan may match additional proprietary rules beyond these examples.
- Which pages are best for detecting Heap?
- For Heap, start with: All pages; interact and wait.