How to Detect Lightbox on Any Website (2026 Guide)
Click a thumbnail on a portfolio site, the page dims, and the full-size image floats in the middle of the screen with a close button and next/previous arrows. There is a good chance that overlay is Lightbox — specifically Lightbox2 by Lokesh Dhakar, one of the longest-lived image overlay libraries on the web. It is small, it has almost no configuration, and it has been copied into theme folders for well over a decade.
This guide covers how to detect Lightbox on a single site by hand, how to tell it apart from look-alike libraries such as FancyBox and the Responsive Lightbox & Gallery WordPress plugin, and how to automate the check across many domains with the DetectZeStack API. Every example below uses real endpoints and the real response shape, including a live scan of Lightbox's own project page.
What Is Lightbox (Lightbox2 by Lokesh Dhakar)?
Lightbox2 is a JavaScript library that overlays images on top of the current page. You include one stylesheet and one script, then add a data-lightbox attribute to any link that points at an image:
<link rel="stylesheet" href="css/lightbox.min.css">
<script src="js/lightbox-plus-jquery.min.js"></script>
<a href="images/photo-1.jpg" data-lightbox="roadtrip">
<img src="images/thumb-1.jpg" alt="Photo 1">
</a>
Links that share the same data-lightbox value become a gallery you can step through. That is the whole API for most sites, which is exactly why Lightbox spread so widely: there is nothing to initialize and nothing to configure.
Why Lightbox Still Shows Up on Portfolio, Gallery and WordPress Sites
Lightbox2 is built on jQuery. The project ships two script variants: lightbox.js, which expects jQuery to already be on the page, and lightbox-plus-jquery.js, which bundles jQuery into the same file. That design fit perfectly into the jQuery-era web, so Lightbox became the default image viewer in photography portfolios, real estate listings, restaurant menus, and a large share of WordPress themes.
Those sites rarely get rebuilt. A theme purchased years ago still loads the same lightbox.min.js from its /js/ folder today, which is what makes Lightbox a useful signal: it tells you a site was built on a jQuery-based frontend and has probably not been re-platformed since.
How to Detect Lightbox Manually
For one site, the browser is enough. Lightbox leaves four independent traces: a script tag, a stylesheet, a JavaScript global, and data-lightbox attributes in the markup.
View Source: Look for lightbox.js, lightbox.min.js or lightbox-plus-jquery.js Script Tags
Open the page source (Ctrl+U or Cmd+Option+U) and search for "lightbox". From the command line, one grep does the same job:
curl -s https://lokeshdhakar.com/projects/lightbox2/ | grep -oiE '<script[^>]*lightbox[^>]*>'
On Lightbox's own project page, that returns the bundled build loaded from the vendor folder (plus a path/to/lightbox.js tag inside the page's installation instructions):
<script src="path/to/lightbox.js">
<script src="vendor/lightbox2/js/lightbox-plus-jquery.min.js">
The usual filenames are lightbox.js, lightbox.min.js, lightbox-plus-jquery.js and lightbox-plus-jquery.min.js. When Lightbox is loaded from cdnjs, the path also contains the version, for example /ajax/libs/lightbox2/2.11.4/js/lightbox.min.js.
Check for lightbox.css or lightbox.min.css Stylesheet Links
Lightbox cannot draw its overlay without its stylesheet, so a matching CSS link almost always sits next to the script:
curl -s https://lokeshdhakar.com/projects/lightbox2/ | grep -oiE '<link[^>]*lightbox[^>]*>'
<link rel="stylesheet" href="vendor/lightbox2/css/lightbox.min.css">
<link href="path/to/lightbox.css" rel="stylesheet" />
A stylesheet on its own is weaker evidence than a script. Some themes copy the CSS but never load the JavaScript, and a few other libraries reuse the lightbox.css filename.
DevTools Console: Test for the Lightbox Global Object
Lightbox2 creates a global instance named lightbox when it loads. Open DevTools on the target page and run:
(function () {
var hasLightbox = typeof window.lightbox === 'object' && window.lightbox !== null;
var hasJQuery = typeof window.jQuery === 'function';
var links = document.querySelectorAll('a[data-lightbox]').length;
console.log({ lightbox: hasLightbox, jquery: hasJQuery, lightboxLinks: links });
})();
A page running Lightbox2 prints something like { lightbox: true, jquery: true, lightboxLinks: 12 }. This is the most reliable manual test, because it catches Lightbox even when it has been bundled into a single app.min.js file and no longer has its own script tag.
Inspect data-lightbox Attributes on Image Links
The last trace is in the markup itself. Right-click a gallery thumbnail, choose Inspect, and look at the surrounding <a> tag. A data-lightbox="..." attribute is Lightbox2's own convention. To count them from the shell:
curl -s https://lokeshdhakar.com/projects/lightbox2/ | grep -oE 'data-lightbox="[^"]*"' | sort | uniq -c
1 data-lightbox="example-1"
1 data-lightbox="example-2"
4 data-lightbox="example-set"
1 data-lightbox="image-1"
3 data-lightbox="roadtrip"
Each distinct value is one gallery, so this also tells you how many galleries the page contains.
Lightbox vs Similar Libraries: FancyBox and Responsive Lightbox & Gallery
"Lightbox" is also the generic name for the whole UI pattern, so not every image overlay is Lightbox2. Two look-alikes come up constantly, and DetectZeStack reports each one as its own technology.
| Technology | Script signal | Category | Version |
|---|---|---|---|
| Lightbox | lightbox.js, lightbox-plus-jquery.js | JavaScript libraries | Not captured |
| FancyBox | jquery.fancybox(.min|.pack).js | JavaScript libraries | From ?v= query string |
| Responsive Lightbox & Gallery | /wp-content/plugins/responsive-lightbox/...front.js | WordPress plugins, Photo galleries | From ?ver= query string |
Telling Lightbox2 Apart from FancyBox (jquery.fancybox.js) and the WordPress responsive-lightbox Plugin
- FancyBox by fancyapps loads
jquery.fancybox.js(or.min.js/.pack.js) and its links usually carrydata-fancyboxinstead ofdata-lightbox. In the console,typeof jQuery.fancyboxreturns'function'. Newer FancyBox releases dropped jQuery and ship as a standaloneFancyboxglobal; those builds do not use thejquery.fancyboxfilename, so the script-name check above will not find them. - Responsive Lightbox & Gallery is a WordPress plugin by Digital Factory. Its script lives under
/wp-content/plugins/responsive-lightbox/, and it can drive several different overlay engines behind the scenes. If you see that plugin path, you are looking at a WordPress site whose gallery is managed by the plugin, not a hand-installed Lightbox2.
Why Lightbox Often Appears Alongside jQuery
Lightbox2 depends on jQuery, so any page that runs it also runs jQuery — either as a separate script or inside the lightbox-plus-jquery bundle. In the DetectZeStack fingerprint data, Lightbox does not declare an automatic "implies jQuery" relationship (FancyBox does). In practice jQuery usually shows up anyway because it has its own signals, as it does in the live scan below. For jQuery's own detection methods, see How to Detect jQuery on Any Website.
Limits of Manual Detection (Bundled Scripts, Renamed Files, Lazy-Loaded Galleries)
The manual checks work well on a single page, and each one has a blind spot:
- Bundled scripts. Build tools like webpack fold Lightbox into one
main.[hash].jsfile. The script tag disappears, and only the console global and thedata-lightboxattributes are left. - Renamed files. Themes sometimes rename the library to
gallery.jsor merge it intoplugins.min.js. A filename search then finds nothing. - Lazy-loaded galleries. Some sites inject the gallery script only after a click or scroll, so it is not in the initial HTML at all.
- Scale. None of this works for a list of 500 domains. Nobody opens DevTools 500 times, and a console screenshot is not data you can compare next quarter.
For more than a handful of sites you want the same answer as structured JSON, one HTTP request per domain.
API Example: Detect Lightbox with DetectZeStack
DetectZeStack fetches the page over HTTP and matches its HTML against technology fingerprints. For Lightbox, the signal the scanner evaluates is the script tag: a src containing lightbox or lightbox-plus-jquery followed by a .js filename, matched case-insensitively. The scanner does not execute JavaScript, so the lightbox global and the stylesheet link are not used as detection signals. A site that bundles Lightbox into an unrelated filename will not show it; the console check above is the fallback for those.
Try It Without a Key via /demo
The public /demo endpoint runs the same detection with no authentication. It is rate-limited but ideal for checking the response shape. Lightbox's own project page makes a good test target:
curl -s "https://detectzestack.com/demo?url=https://lokeshdhakar.com/projects/lightbox2/" | python3 -m json.tool
A live scan run for this article returned seven technologies. Trimmed to the two JavaScript libraries, the response looks like this:
{
"url": "https://lokeshdhakar.com/projects/lightbox2/",
"domain": "lokeshdhakar.com",
"technologies": [
{
"name": "Lightbox",
"categories": ["JavaScript libraries"],
"confidence": 100,
"description": "Lightbox is small javascript library used to overlay images on top of the current page.",
"website": "https://lokeshdhakar.com/projects/lightbox2/",
"icon": "Lightbox.png",
"cpe": "cpe:2.3:a:lightbox_photo_gallery_project:lightbox_photo_gallery:*:*:*:*:*:*:*:*",
"source": "http"
},
{
"name": "jQuery",
"categories": ["JavaScript libraries"],
"confidence": 100,
"description": "jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.",
"website": "https://jquery.com",
"icon": "jQuery.svg",
"cpe": "cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*",
"source": "http"
}
],
"categories": {
"JavaScript libraries": ["jQuery", "Lightbox"]
},
"meta": { "status_code": 200, "tech_count": 7, "scan_depth": "full" },
"cached": false,
"response_ms": 394
}
The other five entries in that scan were Apache HTTP Server, Cloudflare, Google Analytics, cdnjs and Let's Encrypt.
Single Site with GET /analyze
For production use, subscribe on RapidAPI and call /analyze with your key. It returns the same shape as /demo, without the demo rate limit:
curl -s -H "X-RapidAPI-Key: YOUR_KEY" \
-H "X-RapidAPI-Host: detectzestack.p.rapidapi.com" \
"https://detectzestack.p.rapidapi.com/analyze?url=example.com" \
| jq '.technologies[] | select(.name == "Lightbox")'
If Lightbox is detected, the filter prints its object. If not, jq prints nothing, which makes the command easy to drop into a shell loop. To check all three overlay libraries at once:
curl -s -H "X-RapidAPI-Key: YOUR_KEY" \
-H "X-RapidAPI-Host: detectzestack.p.rapidapi.com" \
"https://detectzestack.p.rapidapi.com/analyze?url=example.com" \
| jq '[.technologies[].name | select(. == "Lightbox" or . == "FancyBox" or . == "Responsive Lightbox & Gallery")]'
Reading the technologies Array: name, categories, confidence, version
nameis always"Lightbox"for this library. Filter on it; it is the stable key.categoriesis["JavaScript libraries"], so Lightbox also appears in the top-levelcategoriesmap under that bucket, next to jQuery.confidenceis 100 for HTTP-layer matches like this one.versionis not captured by the Lightbox fingerprint, even when the script comes from a versioned cdnjs path. Empty fields are left out of the JSON, which is why the example above has noversionkey. To get the exact release, open thelightbox.jsURL from the page source; Lightbox2 prints its version in the header comment.
Treat a Lightbox hit as "a lightbox-named script," then confirm. The script pattern is deliberately broad: any src with lightbox in it followed within a few characters by .js matches. That catches renamed Lightbox2 builds, but it also means other lightbox-named scripts — for example the Responsive Lightbox & Gallery plugin's front.js — can produce a Lightbox entry too. If the same response also lists Responsive Lightbox & Gallery, the plugin is the more specific answer.
Scanning Many Sites with POST /analyze/batch
POST /analyze/batch accepts up to 10 URLs per request and scans them concurrently. Each URL counts against your quota the same as a single /analyze call:
curl -s -X POST "https://detectzestack.p.rapidapi.com/analyze/batch" \
-H "X-RapidAPI-Key: YOUR_KEY" \
-H "X-RapidAPI-Host: detectzestack.p.rapidapi.com" \
-H "Content-Type: application/json" \
-d '{"urls": ["https://example.com", "https://example.org", "https://example.net"]}' \
| jq -c '.results[] | {url: .url, lightbox: ([.result.technologies[]? | select(.name == "Lightbox")] | length > 0)}'
The batch response wraps one object per URL in a results array, with total_ms, successful and failed counters alongside. The filter reduces it to one line per domain:
{"url":"https://example.com","lightbox":false}
{"url":"https://example.org","lightbox":false}
{"url":"https://example.net","lightbox":false}
For lists longer than 10, loop over the file in chunks. Batch Scan 1,000 Websites for Tech Stack covers concurrency, retries and quota handling.
Comparing Gallery Stacks Across Competitors with POST /compare
POST /compare takes 2 to 10 URLs and returns each domain's technologies, a per-domain unique array, and a top-level shared array. It is a quick way to see which competitors still run a jQuery-era gallery:
curl -s -X POST "https://detectzestack.p.rapidapi.com/compare" \
-H "X-RapidAPI-Key: YOUR_KEY" \
-H "X-RapidAPI-Host: detectzestack.p.rapidapi.com" \
-H "Content-Type: application/json" \
-d '{"urls": ["competitor-one.com", "competitor-two.com", "competitor-three.com"]}' \
| jq '[.domains[] | {domain, galleries: [.technologies[].name | select(. == "Lightbox" or . == "FancyBox" or . == "Responsive Lightbox & Gallery")]}]'
If Lightbox appears in shared, every site in the comparison runs it.
Use Cases: Lead Generation, Agency Audits, Dependency and CPE Vulnerability Checks
- Lead generation. A site running Lightbox has an image gallery and most likely an older jQuery frontend. For agencies that sell redesigns, and for vendors of modern gallery or image-hosting products, that is a qualified list. Run the same filter for Slick and OWL Carousel to cover the other jQuery-era visual plugins.
- Agency audits. When you take over a client's portfolio of sites, one batch call per ten domains gives you an inventory of which ones still load Lightbox and jQuery, so you can scope a cleanup before quoting it.
- Dependency checks. Lightbox pins a page to jQuery. Teams planning to remove jQuery need to know every page that still relies on it. See How to Detect What JavaScript Framework a Website Uses for the broader frontend picture.
- CPE vulnerability checks. The Lightbox entry carries a
cpevalue you can feed into a vulnerability database lookup. Read it before you rely on it: the vendor and product in that string arelightbox_photo_gallery_project:lightbox_photo_gallery, and the version slot is a wildcard because no version is captured. Confirm that the CPE describes the software actually running on the site, and read the version from the file itself, before you treat any CVE match as a finding. Detect Vulnerable Technologies with CPE walks through that workflow.
Conclusion and Next Steps
On a single page, Lightbox is easy to find: a lightbox.min.js or lightbox-plus-jquery.min.js script tag, a lightbox.css link, data-lightbox attributes on image links, and a lightbox global in the console. Across hundreds of domains, one /analyze call per site, or ten at a time through /analyze/batch, returns a Lightbox entry whenever a lightbox-named script is on the page. Keep two details in mind: the API does not report a Lightbox version, and FancyBox and Responsive Lightbox & Gallery are reported as separate technologies.
The free tier on RapidAPI includes 100 requests per month with no credit card, and paid plans start at $9/month for 1,000 requests. Every plan uses the same endpoints and response shape shown above.
Related Reading
- How to Detect jQuery on Any Website — the library Lightbox2 is built on: console checks, CDN patterns and version parsing
- How to Detect Slick on Any Website — the jQuery carousel that shares Lightbox's theme stacks
- Find Companies Using OWL Carousel — another jQuery-era visual plugin worth adding to the same prospect filter
- Find Companies Using imagesLoaded — the image-loading utility common in gallery-heavy sites
- How to Detect What JavaScript Framework a Website Uses — the wider frontend inventory
- Detect Vulnerable Technologies with CPE — how to use the cpe field in the API response
- Batch Scan 1,000 Websites for Tech Stack — concurrency, retries and quota patterns
Detect Lightbox and Every Other Library in One API Call
One HTTP request returns every framework, library, CDN, CMS and analytics tag on a page. 100 requests per month free. No credit card.
Get your free API key