Market share

Website technologies

What do the 100,000 most popular websites run on?
16%
run WordPress
30%
sit behind Cloudflare
46%
send a HSTS header
Content platform — Top 100K websites
WordPress
16%10,202
Drupal
3.3%2,019
Webflow
1.7%1,071
Adobe Experience Manager
1.5%920
HubSpot CMS
0.8%506
Bitrix
0.6%380
TYPO3
0.5%323
Sitecore
0.5%294
Shopify
0.5%289
Salesforce Commerce Cloud
0.4%258
Custom site (JavaScript framework, no platform)
16%10,131
No platform marker found
54%33,635

Base: pages that answered with a normal HTTP 2xx status (error pages, APIs and CDN hosts are left out). A platform is detected from the generator tag, file paths, cookies and headers of the home page; custom-built sites, or sites that hide their markers, have none.

E-commerce platform
WooCommerce
2.5%1,572
PrestaShop
0.5%331
Magento
0.5%305
Shopify
0.5%289
Salesforce Commerce Cloud
0.4%258
Shopware
0.2%116
BigCommerce
0.1%49
OpenCart
0.0%27
JavaScript framework
Next.js
9.1%5,644
React
3.3%2,017
Angular
2.6%1,588
Nuxt
2.1%1,271
Vue
0.6%388
Astro
0.6%378
Gatsby
0.4%242
SvelteKit
0.3%194

Only frameworks that leave a marker in the HTML the server sends.

Web server
Cloudflare
30%21,105
nginx
20%14,483
Apache
10%7,161
Other
5.3%3,751
Amazon
4.9%3,482
Microsoft IIS
2.3%1,642
OpenResty
1.6%1,119
Vercel
1.5%1,059
Google servers
1.1%749
Not disclosed
16%11,654

Many sites hide the Server header, so each share is a minimum.

CDN and protection
Cloudflare
30%21,258
Amazon CloudFront
9.7%6,881
Fastly
3.5%2,528
Akamai
2.1%1,479
Vercel
1.4%1,010
Azure Front Door
0.9%634
DDoS-Guard
0.8%555
Imperva
0.7%527
None detected
50%35,732
Server language
PHP
11%6,877
Other
4.6%2,877
Next.js
4.5%2,760
ASP.NET
3.8%2,331
Java
1.5%937
Express (Node.js)
1.4%875

From the X-Powered-By header and the names of session cookies; many sites send neither.

Security headers
HSTS (Strict-Transport-Security)
46%32,473
HSTS, max-age of 6 months or more
40%28,595
X-Content-Type-Options: nosniff
38%27,357
Frame protection (X-Frame-Options or CSP frame-ancestors)
43%30,293
Referrer-Policy
23%16,179
Content-Security-Policy
25%17,556

Presence of the header on the home page, not the quality of its policy.

Protocols
Answers over HTTPS
97%69,425
TLS 1.3
84%60,166
HTTP/2 or HTTP/3
81%57,599
HTTP/3 advertised
30%21,581
How this is measured

A script fetches the home page of the domains of the Tranco top 100K that resolve, each one every 7 days (top 100K) or every 30 days (others): 89,977 probed, 84,832 answered, 13,576 of those showed an anti-bot page and are left out of the shares, leaving a base of 71,256. It sends one GET / request, identified as xj1-whoami-research, follows at most three redirects, runs no JavaScript and stores only the indicators it detects, never the page. Technologies that only appear after JavaScript runs are invisible to it.

Shares are rounded to the nearest whole percent and are minimums: a site that hides its markers counts as “not detected”. Latest probe run: 2026-10-06.