Detect Strapi
Strapi is an open-source headless CMS used for building fast and easily manageable APIs written in JavaScript.
Detection looks at response headers, inline scripts across 2 fingerprint rules among the site's public responses.
01
Websites using Strapi
Loading website list…
02
Signal classes
PluginView evaluates public page signals in these classes when identifying Strapi. Individual fingerprint rule bodies are proprietary and are not published.
- Response headers
- Inline scripts
03
Example public indicators for Strapi
Illustrative indicators derived from public catalog metadata for Strapi. A live scan may match additional proprietary rules beyond these examples.
- x-powered-by: Strapi
- -strapi-strapi_jwt
04
What a detection means
- Establishes
- One or more public signals on the scanned page matched a known Strapi signature (2 rules) at the time of the scan.
- Does not establish
- A sitewide install of Strapi, an active vendor contract, exclusive use, or that Strapi is still in place today.
05
How to check a site for Strapi
- 1. Enter the website URL in the scan form — homepage, pricing, checkout, or login pages usually expose the strongest Strapi signals.
- 2. PluginView reads only public responses (response headers, inline scripts) and scores them against the Strapi signature set (2 rules).
- 3. Review the confidence score and text explanation for Strapi on the results page.
06
FAQ: detecting Strapi
- Can PluginView detect Strapi without logging in?
- Yes. PluginView only reads publicly accessible responses when checking for Strapi — typically response headers, inline scripts. It does not bypass authentication or paywalls.
- What category is Strapi?
- Strapi is classified under CMS in the PluginView directory.
- How many fingerprint rules cover Strapi?
- This reference currently tracks 2 fingerprint rules across response headers, inline scripts. Individual rule bodies are proprietary and are not published.
- What public signals suggest a site uses Strapi?
- Illustrative public indicators for Strapi include x-powered-by: Strapi; -strapi-strapi_jwt. A live scan may match additional proprietary rules beyond these examples.