Shopify App Detection Dataset

The coverage, matching rules and limits behind Detectify's storefront results.

Published and last reviewed: . Maintained by .

How many signatures does Detectify check?

Detectify currently checks 351 public storefront signatures: 326 app signatures, 8 analytics signatures, 11 payment method signatures and 6 auxiliary storefront-tool signatures. These totals describe patterns Detectify can test for, not apps confirmed as installed on every scanned store.

Dataset group Signatures What it covers
Apps 326 Public traces from Shopify apps and storefront services.
Analytics 8 Analytics, tag management and behavioral measurement tools.
Payment methods 11 Wallets and payment options exposed by the storefront.
Auxiliary tools 6 Product, order, advertising and affiliate storefront tools.
Total 351 All current signatures in the published JSON file.

What is a Shopify app signature?

A signature is a stable text fragment associated with a tool, such as an asset hostname, script path, widget identifier or public service domain. Detectify looks for that fragment in the HTML returned by a public storefront. A match is evidence that the storefront exposes the tool; it is not access to the merchant's Shopify admin or private app list.

How does the matching process work?

  1. Detectify requests the public storefront HTML through its server-side fetch endpoint.
  2. It checks for Shopify-related storefront evidence before displaying app results.
  3. The storefront HTML and each stored signature are normalized to lowercase.
  4. Each signature is compared as an exact text fragment against the returned HTML.
  5. Matches are grouped into apps, analytics tools and payment methods.

Case normalization prevents avoidable misses caused only by capitalization. Detectify does not treat a partial brand-name guess as proof unless that text is part of a stored signature.

What do the confidence labels mean?

Confidence describes the specificity of the matched storefront fragment, not the quality of an app. A signature containing a domain or path, or at least 12 characters, is labeled high confidence. Signatures of at least 8 characters are labeled medium confidence; shorter patterns are labeled low confidence.

Confidence is a practical interpretation aid. Even a high confidence match only proves that public evidence was present when the storefront was fetched.

Why can a real app still be missing?

Backend-only, admin-only, private and custom apps may leave no public trace. Shopify themes can also inline, rename, defer or proxy app assets. A no-match result therefore means Detectify found no current signature in the fetched storefront HTML; it does not prove that the merchant has no installed apps.

How should this dataset be cited?

The accurate description is: “Detectify matches publicly visible Shopify storefront signatures.” Avoid describing a match as direct access to a store's installed-app list. Use this page as the methodology URL and include the snapshot date when reporting exact signature totals.

Download and inspect the data

Signature dataset

The app names, descriptions, public signature patterns, categories and reference URLs used by the detector.

Product facts

A compact JSON summary of Detectify's capabilities, limitations, canonical pages and dataset totals.

Test the published methodology

Run the Shopify App Detector, compare the result with the manual detection guide, and review why some apps remain invisible.