Skip to main content
822316 sites analysed

EU Web Technology Landscape

CMS, hosting providers, and consent platforms across 822316 EU websites

WordPress

Top CMS (64.5%)

25883

Sites with CMS

Apache

Top Server (26.1%)

55%

EU-hosted providers

CMS Distribution

25883 sites with detected CMS

CMS choice directly affects security posture — outdated CMS versions are a leading attack vector. Plugin ecosystems, update frequency, and default security configurations vary significantly between platforms, impacting vulnerability exposure and patch cycles.

WordPress
64.5% (16702)
Next.js
6.2% (1615)
Drupal
4.6% (1183)
Magento
4.4% (1133)
Wix
4.3% (1102)
TYPO3
3.0% (788)
Joomla
2.9% (760)
Shopify
2.6% (679)
Squarespace
1.5% (377)
Webnode 2
0.8% (220)
PrestaShop
0.8% (217)
Jimdo Creator
0.7% (183)
Webnode
0.4% (116)

Server Technology

40447 sites with detected server

Web server software and runtime frameworks. Server version disclosure can aid attackers — but also helps identify outdated, vulnerable infrastructure. End-of-life PHP versions receive no security patches.

Web Servers

Apache
26.1%
Cloudflare
24.5%
nginx
21.1%
LiteSpeed
7.6%
openresty
6.0%
Apache 2.4
3.8%
Pepyaka
2.4%
Apache / ZoneOS
1.8%
Microsoft-IIS 10.0
1.5%
Vercel
1.2%
Apache 2
1.2%
Squarespace
1.0%
webnode
0.9%
hcdn
0.6%
nginx 1.18
0.4%

Frameworks & PHP Versions

PHP 8.3
18.1%
PHP 7.4 ⚠
15.2%
PHP 8.2
14.0%
ASP.NET
12.0%
PHP 8.4
9.8%
PHP 8.1
9.0%
PHP 5.6 ⚠
4.1%
PHP 8.0 ⚠
3.5%
Express (Node.js)
3.3%
PHP 8.5
3.0%
PHP 7.3 ⚠
2.3%
PHP 7.0 ⚠
2.0%
PHP 7.2 ⚠
1.9%
PHP 5.3 ⚠
1.0%
PHP 5.4 ⚠
1.0%

Hosting Provider Landscape

860556 sites with hosting data

GDPR Art. 28 requires data processing agreements specifying where data is stored. Art. 44-49 regulate international transfers — hosting with US-headquartered providers triggers Schrems II (CJEU C-311/18) and CLOUD Act considerations, requiring SCCs with supplementary measures.

55%

EU-headquartered provider

45%

Non-EU provider (CLOUD Act / Schrems II)

Top hosting providers

Cloudflare (US · non-EU) 88337 10.3%
IONOS (1&1) (DE · EU) 65205 7.6%
Amazon Web Services (US · non-EU) 55427 6.4%
Hetzner (DE · EU) 50209 5.8%
OVHcloud (FR · EU) 45129 5.2%
Google Cloud (US · non-EU) 37666 4.4%
Strato (DE · EU) 28577 3.3%
Wix (IL · non-EU) 26609 3.1%
Aruba S.p.A. (IT · EU) 14342 1.7%
GoDaddy (US · non-EU) 12795 1.5%

Top hosting countries

DE
29.5%
US
20.9%
FR
9.7%
NL
6.3%
GB
4.5%
IT
3.7%
PL
3.7%
CH
2.3%
DK
2.3%
IE
2.2%

Server location via IP geolocation (MaxMind GeoLite2). Company HQ from ASN registry. A site may be physically hosted in the EU but use a US-headquartered provider subject to the CLOUD Act — per Schrems II (CJEU C-311/18), this requires SCCs with supplementary measures. · GDPR Art. 44–49

Methodology

How this data was collected and what it represents.

CMS detection uses multiple signals: HTTP response headers (X-Powered-By, X-Generator), HTML meta generator tags, characteristic URL patterns, CSS class naming conventions, and JavaScript global variables. Detection covers WordPress, Joomla, Drupal, Typo3, Shopify, Wix, Squarespace, and 40+ other platforms.

CMP detection identifies consent management platforms via script sources, cookie names, DOM elements, and IAB TCF API presence (window.__tcfapi). Over 33 CMP vendors are tracked including Cookiebot, OneTrust, Usercentrics, Borlabs Cookie, and Complianz.

Hosting provider identification combines IP geolocation (MaxMind GeoLite2) for server location with ASN/WHOIS data for provider identification and company headquarters mapping.

No individual sites are named. All statistics are aggregated and anonymised. The data represents a snapshot and is updated continuously as new scans complete.

Where does your website stand?

Run a free security scan and see how you compare — TLS, headers, email, DNS, accessibility, cookies — in 30 seconds, no account needed.

Based on automated scans of 822316 European websites. Updated continuously.