New 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.

Free tool · Software discovery

WordPress Plugin Detector

The WordPress plugin detector looks for plugin clues in the public page and its asset addresses. Enter a website URL to see which identifiers are visible before checking them against the installed software list.

Free WordPress plugin detector

Enter a WordPress page URL and we will look for plugin names and version clues in its public assets.

Free to use without an account. View the result here and choose whether to receive it by email.

What the tool covers

Identify public plugin clues

Plugin identifiers exposed in public WordPress asset paths and page markup, with version clues when available.

Public asset paths

Script, stylesheet and other page references are examined for WordPress plugin directory identifiers exposed in the submitted page.

Detected plugin identifiers

Recognised plugin slugs are collected from those references. A slug helps you investigate the software behind a feature without claiming a complete inventory.

Tentative version clues

Version information in asset addresses is reported as a hint when available. Cache identifiers and older files prevent it from being treated as a confirmed installed release.

Visibility limits

Plugins without front-end assets, renamed paths and combined or cached files can remain undetected. The report keeps those limits alongside the findings.

Understand the limits

Public clues are not a complete installed-plugin inventory. Cached or renamed assets can obscure or misrepresent the current setup.

Understanding your result

Confirm a public plugin clue before relying on it

A detected reference tells you something about the page that was served. Use your WordPress dashboard or the site owner's inventory to establish what is installed and active now.

Follow a plugin reference into your inventory

Find the matching component in the Plugins screen and confirm its name and activation status. Cached files or leftover markup can still refer to software that has changed.

Check version hints against the installed release

Copy the release shown in WordPress before using the vulnerability lookup or planning an update. An asset's version parameter can belong to caching or WordPress itself rather than that plugin.

No detection means limited public evidence

Try the relevant public page if the feature appears elsewhere, then check the installed inventory directly. Dashboard-only plugins and software with hidden paths cannot be ruled out by an empty result.

Understand where plugin clues come from

Plugins can load scripts, styles and images from paths containing their identifiers. The detector reads those public clues. An asset path is evidence that a page references that software, but it does not establish the complete configuration inside WordPress.

Confirm the result in your dashboard

Open Plugins in WordPress to check the installed name, version and activation status. A cached page can still reference an old file after a plugin changes. Conversely, plugins that operate only in the dashboard or behind the scenes can leave no public trace.

Use version information carefully

A query string on an asset can be a cache value rather than the installed plugin release. Confirm the actual version before using the vulnerability lookup or planning an update. If a detector returns no plugins, treat that as limited public visibility rather than an empty installation.

Questions about this tool

How does the WordPress plugin detector work?

It reads a public page and looks for plugin identifiers in WordPress asset paths and markup. It does not log in or inspect private plugin files.

Can it detect every installed plugin?

No. Dashboard-only plugins, hidden paths, optimised assets and cached pages limit what is visible. Check Plugins in WordPress for the installed inventory.

Does a detected path prove the plugin is active now?

No. A page can reference cached or leftover assets. Confirm the current activation status inside WordPress.

Are detected plugin versions definitive?

No. Asset version clues can be cache identifiers or stale values. Confirm the installed release before making a security or update decision.

Can I email the detected plugin list?

Yes. Start the check and use the optional email form. The emailed result retains the same limitations as the on-page report.

Free website widget

Add this tool to your website

Let visitors use the WordPress Plugin Detector on your own page, including the option to email their results. Copy the code into an Elementor HTML widget or a WordPress Custom HTML block, then preview the published page.

Get the embed code
Preview the widget

The widget fits the width of its container. Increase the height value if you want more of the report visible at once; longer results can be scrolled inside the widget.

BugShield hosts and runs the tool. Results and email addresses stay inside the widget and are not shared with the page embedding it. If your editor removes the code or your site blocks external widgets, ask your website administrator to allow frames from bugshield.co.uk.

Need help with the next step?

A BugShield developer can review the findings and help you decide what your WordPress site needs.

Explore WordPress support