Free tool · Software discovery
WordPress Plugin Detector
The WordPress plugin detector looks for plugin clues in the public page and its asset addresses. Enter a website URL to see which identifiers are visible before checking them against the installed software list.
Free WordPress plugin detector
Free to use without an account. View the result here and choose whether to receive it by email.
What the tool covers
Identify public plugin clues
Plugin identifiers exposed in public WordPress asset paths and page markup, with version clues when available.
Public asset paths
Script, stylesheet and other page references are examined for WordPress plugin directory identifiers exposed in the submitted page.
Detected plugin identifiers
Recognised plugin slugs are collected from those references. A slug helps you investigate the software behind a feature without claiming a complete inventory.
Tentative version clues
Version information in asset addresses is reported as a hint when available. Cache identifiers and older files prevent it from being treated as a confirmed installed release.
Visibility limits
Plugins without front-end assets, renamed paths and combined or cached files can remain undetected. The report keeps those limits alongside the findings.
Understand the limits
Public clues are not a complete installed-plugin inventory. Cached or renamed assets can obscure or misrepresent the current setup.
Understanding your result
Confirm a public plugin clue before relying on it
A detected reference tells you something about the page that was served. Use your WordPress dashboard or the site owner's inventory to establish what is installed and active now.
Follow a plugin reference into your inventory
Find the matching component in the Plugins screen and confirm its name and activation status. Cached files or leftover markup can still refer to software that has changed.
Check version hints against the installed release
Copy the release shown in WordPress before using the vulnerability lookup or planning an update. An asset's version parameter can belong to caching or WordPress itself rather than that plugin.
No detection means limited public evidence
Try the relevant public page if the feature appears elsewhere, then check the installed inventory directly. Dashboard-only plugins and software with hidden paths cannot be ruled out by an empty result.
Understand where plugin clues come from
Plugins can load scripts, styles and images from paths containing their identifiers. The detector reads those public clues. An asset path is evidence that a page references that software, but it does not establish the complete configuration inside WordPress.
Confirm the result in your dashboard
Open Plugins in WordPress to check the installed name, version and activation status. A cached page can still reference an old file after a plugin changes. Conversely, plugins that operate only in the dashboard or behind the scenes can leave no public trace.
Use version information carefully
A query string on an asset can be a cache value rather than the installed plugin release. Confirm the actual version before using the vulnerability lookup or planning an update. If a detector returns no plugins, treat that as limited public visibility rather than an empty installation.
Questions about this tool
How does the WordPress plugin detector work?
It reads a public page and looks for plugin identifiers in WordPress asset paths and markup. It does not log in or inspect private plugin files.
Can it detect every installed plugin?
No. Dashboard-only plugins, hidden paths, optimised assets and cached pages limit what is visible. Check Plugins in WordPress for the installed inventory.
Does a detected path prove the plugin is active now?
No. A page can reference cached or leftover assets. Confirm the current activation status inside WordPress.
Are detected plugin versions definitive?
No. Asset version clues can be cache identifiers or stale values. Confirm the installed release before making a security or update decision.
Can I email the detected plugin list?
Yes. Start the check and use the optional email form. The emailed result retains the same limitations as the on-page report.
Free website widget
Add this tool to your website
Let visitors use the WordPress Plugin Detector on your own page, including the option to email their results. Copy the code into an Elementor HTML widget or a WordPress Custom HTML block, then preview the published page.
Get the embed code
The widget fits the width of its container. Increase the height value if you want more of the report visible at once; longer results can be scrolled inside the widget.
BugShield hosts and runs the tool. Results and email addresses stay inside the widget and are not shared with the page embedding it. If your editor removes the code or your site blocks external widgets, ask your website administrator to allow frames from bugshield.co.uk.
Need help with the next step?
A BugShield developer can review the findings and help you decide what your WordPress site needs.
Explore WordPress support