Substack
Substack is a wappalyzer technology that ScanMalware.com has fingerprinted across 624 public website scans. Each of those scans is a real headless-browser visit, so the data on this page reflects how Substack is actually deployed on the live web — including on compromised, phishing and malware-hosting sites, not just legitimate ones.
On sites where Substack appears, the technologies most often detected alongside it are Node.js, HSTS and Cloudflare. That co-occurrence pattern is a useful fingerprint of the stack Substack typically ships with, and a starting point for spotting deployments that look unusual.
Commonly deployed alongside Substack
Of the 624 public scans where Substack was detected, these are the technologies most often present on the same site. The share is the percentage of Substack sites that also ran each one.
| Technology | Category | Share of Substack sites |
|---|---|---|
| Node.js | wappalyzer | 100% |
| HSTS | wappalyzer | 100% |
| Cloudflare | wappalyzer | 100% |
| Cloudflare Bot Management | wappalyzer | 100% |
| Express | wappalyzer | 100% |
| HTTP/3 | wappalyzer | 99.84% |
| Open-Graph-Protocol | miscellaneous | 92.47% |
| Google Analytics | wappalyzer | 42.15% |
| Script | miscellaneous | 15.22% |
| YouTube | wappalyzer | 13.46% |
| Amazon S3 | wappalyzer | 5.61% |
| Amazon Web Services | wappalyzer | 5.61% |
| Google Tag Manager | wappalyzer | 5.45% |
| Cloudflare Browser Insights | wappalyzer | 5.13% |
How ScanMalware detects Substack
Substack is detected by analysing the response headers, HTML markup, JavaScript runtime and asset URLs captured when ScanMalware loads the site in a real headless browser.
From any scan you can pivot into related signals — JARM TLS fingerprints, ASN ownership and BGP routing, certificate history, JavaScript analysis and the overall security verdict — to understand not just that Substack is present, but how it is being used. Open the full search interface for Substack →
Recent public scans featuring Substack
A rolling sample of recent public scans where Substack was detected. Listing a site here is not a safety judgement — open a scan to see its full verdict.
| Site | Scanned |
|---|---|
| From HGTV to Homeschooling: Erin Napier on Building a Life, Not a Brand https://dadville.substack.com/p/from-hgtv-to-homeschooling-erin-napier | 2026-09-12 |
| My favourite TV show no one talks about anymore: Drawn Together https://www.popwarrior.co.uk/p/my-favourite-tv-show-no-one-talks-about-anymore-drawn-toget… | 2026-09-11 |
| New Moon in Virgo - September 2026 https://leahwhitehorse.substack.com/p/new-moon-in-virgo-september-2026 | 2026-09-11 |
| Cassandra Unchained | Michael Burry | Substack https://michaeljburry.substack.com | 2026-09-09 |
| The Hugging Face attack surprised me - by Ajeya Cotra https://www.planned-obsolescence.org/p/the-hugging-face-attack-surprised | 2026-09-09 |
| Quick notes on the OpenAI-Hugging face cyberattack https://aiandacademia.substack.com/p/quick-notes-on-the-openai-hugging | 2026-09-09 |
| Iran War update #44: How the Iran War is like Vietnam https://amerex.substack.com/p/iran-war-update-44-how-the-iran-war | 2026-09-09 |
| Nuclear Heavyweight Holtec Files for IPO https://nuclearreview.substack.com/p/nuclear-heavyweight-holtec-files | 2026-09-08 |
Frequently asked questions about Substack
- Does using Substack mean a website is unsafe?
- No. Substack is a stack component, not a verdict. ScanMalware scores the whole page — its scripts, redirects, certificates, threat-intelligence matches and behaviour — so a site using Substack can be perfectly safe or actively malicious.
- How many sites using Substack has ScanMalware scanned?
- Substack has been detected in 624 public scans on ScanMalware.com. Each scan is a real headless-browser visit, and the figure updates as new URLs are submitted.
- What technologies are commonly used with Substack?
- Across scanned sites, Substack is most often seen alongside Node.js, HSTS and Cloudflare. The full co-occurrence breakdown is listed on this page.
Browse all profiled technologies on the technology index, or scan a URL to see its full stack.