Every new detection includes the public signal, its source, and a rule identifier. Reports preserve the time and scanner version so results can be reviewed later.
We remove URL query strings and fragments before scanning. We do not sign in, submit forms, or access private network addresses. Browser collection blocks requests that change state, images, media and fonts. Authenticated application pages and technology behind consent gates may be invisible.
Page resource identifies an integration declared in executable markup. Resource delivered means the browser received a successful response for a distinctive supported resource. A successful response alone does not prove SDK execution, completed analytics events or a paid subscription. Passive preload hints do not establish an active integration.
Live browser instance means a supported React, Vue or jQuery instance was observed. That instance may belong to a widget; it does not identify the framework for the entire application. Measurement response identifies a response from a supported measurement endpoint, without claiming an event was accepted.
Confirmed means a distinctive supported fingerprint matched. Likely means a narrower but less conclusive signal matched. These labels are not statistical accuracy percentages. A technology name appearing in prose is not a detection.
Blocking, timeouts, unavailable browser support, and collection limits are shown in the report. Browser observations have request, byte and time limits. No detected technologies does not prove no technologies are used. Older reports without saved evidence are labeled legacy.
Matching complete scans may reuse evidence for up to 24 hours. Refresh always requests new evidence. Signed-in scans and saved copies are private by default. Daily monitors confirm a changed technology set across two complete observations; incomplete scans do not create removal alerts. A scanner or rule change resets the monitoring baseline.
Regression checks cover misleading prose, spoofed hosts, failed requests, inert preload stubs, privacy and collection failures. Real browser tests also verify supported framework installations and teardown. Controlled scenarios share their installation groups; generated variants do not create independent evidence.
When enabled, learning can propose literal fingerprints and evaluate them automatically. Model answers cannot create trusted benchmark labels. A rule must pass independent positive and negative coverage, regression checks, public-site support and a shadow period before automatic activation. Active rules are checked again and revoked on regression. These checks do not establish accuracy across the entire web.