Sourcemap Explorer
Stack · Programming languages

Lua

Lua is a multi-paradigm programming language designed primarily for embedded use in applications.

Programming languages

What detecting Lua tells you about a site

Lua on the web almost always means OpenResty — Lua scripting embedded inside Nginx — used for high-performance routing, rate limiting, auth gateways and edge logic. You detect it from an OpenResty `Server` header or behaviour consistent with Nginx-embedded scripting. Its presence signals an infrastructure or platform team doing serious work at the proxy/gateway layer, often in front of a completely separate application stack.

Lua in a real-world stack

When you find Lua, it rarely travels alone. OpenResty/Nginx at the edge; typically fronting an unrelated application backend behind it.

About

Lua is a multi-paradigm programming language designed primarily for embedded use in applications.

Categories: Programming languages

Quick facts

Official sitehttps://www.lua.org
CategoriesProgramming languages

Detection methodology for Programming languages

Programming languages reveal themselves through extension fingerprints (`.php` URLs for PHP, `.aspx` for ASP.NET), framework-specific patterns and (for client-side runtime languages like TypeScript and Sass) the `node_modules/<lang>/package.json` entry inside the sourcemap. Bun, Node.js and Deno on the server side identify themselves via response headers when emitted (`X-Powered-By: Bun`, `X-Bun-Version`).

How we detect Lua

Sourcemap Explorer carries 1 fingerprint signal for Lua, spread across 1 channel — response header. The exact patterns are listed below, and you can replay each one in Chrome DevTools to confirm a match by hand.

Each signal alone is rarely conclusive — Sourcemap Explorer cross-references all of them and weights by confidence. You can reproduce any of these checks yourself in Chrome DevTools.

Response header

Server-side fingerprint: the response header reveals the technology behind the page. Visible in DevTools → Network → response headers.

X-Powered-By: \bLua(?: ([\d.]+))?

FAQ

How do I check if a website is using Lua?

Open the page in Chrome, click the Sourcemap Explorer toolbar icon, and read the Stack tab. Lua's specific fingerprints here are response header, and the popup flags Lua whenever any combination of them is found. The same checks can be reproduced manually in DevTools — see the "How we detect" section above.

What Lua version can Sourcemap Explorer detect?

Lua ships as a hosted programming languages rather than a bundled npm package, so version-specific detection isn't always possible. Where the platform leaks a version in response headers (`X-Powered-By`, `Server`, generator meta tags) we surface it; otherwise we report presence only.

Where can I read more about Lua?

Official site: https://www.lua.org. For Sourcemap Explorer's detection guide, see the deep-dive link below or the related guides in the cross-link section.

Keep reading on Sourcemap Explorer

Practical guides

Alternative tools

Detected by Sourcemap Explorer

Open the popup on any page running Luaand you'll see the exact version pulled from the bundled package.json when sourcemaps are exposed.

Install free on Chrome