PluginView detects Shelf, a Web server extensions, by evaluating response headers on publicly reachable pages. Illustrative public indicators associated with Shelf include server: dart:io with Shelf, x-powered-by: Dart with package:shelf. Full fingerprint rules remain proprietary; this page summarizes the signal classes and example indicators used for identification.

Detection looks at response headers across 2 fingerprint rules among the site's public responses.

01

Websites using Shelf

Loading website list…

02

Signal classes

PluginView evaluates public page signals in these classes when identifying Shelf. Individual fingerprint rule bodies are proprietary and are not published.

  • Response headers
03

Example public indicators for Shelf

Illustrative indicators derived from public catalog metadata for Shelf. A live scan may match additional proprietary rules beyond these examples.

  • server: dart:io with Shelf
  • x-powered-by: Dart with package:shelf
04

What a detection means

Establishes
One or more public signals on the scanned page matched a known Shelf signature (2 rules) at the time of the scan.
Does not establish
A sitewide install of Shelf, an active vendor contract, exclusive use, or that Shelf is still in place today.
05

How to check a site for Shelf

  1. 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest Shelf signals.
  2. 2. PluginView reads only public responses (response headers) and scores them against the Shelf signature set (2 rules).
  3. 3. Review the confidence score and text explanation for Shelf on the results page.
06

Commonly implies

A confirmed Shelf match also implies these technologies are present.

07

FAQ: detecting Shelf

Can PluginView detect Shelf without logging in?
Yes. PluginView only reads publicly accessible responses when checking for Shelf — typically response headers. It does not bypass authentication or paywalls.
What category is Shelf?
Shelf is classified under Web server extensions in the PluginView directory.
How many fingerprint rules cover Shelf?
This reference currently tracks 2 fingerprint rules across response headers. Individual rule bodies are proprietary and are not published.
What public signals suggest a site uses Shelf?
Illustrative public indicators for Shelf include server: dart:io with Shelf; x-powered-by: Dart with package:shelf. A live scan may match additional proprietary rules beyond these examples.

More in Web server extensions

View category →