How to Detect Lightbox on Any Website (2026 Guide)

September 27, 2026 · 10 min read

Click a thumbnail on a portfolio site, the page dims, and the full-size image floats in the middle of the screen with a close button and next/previous arrows. There is a good chance that overlay is Lightbox — specifically Lightbox2 by Lokesh Dhakar, one of the longest-lived image overlay libraries on the web. It is small, it has almost no configuration, and it has been copied into theme folders for well over a decade.

This guide covers how to detect Lightbox on a single site by hand, how to tell it apart from look-alike libraries such as FancyBox and the Responsive Lightbox & Gallery WordPress plugin, and how to automate the check across many domains with the DetectZeStack API. Every example below uses real endpoints and the real response shape, including a live scan of Lightbox's own project page.

What Is Lightbox (Lightbox2 by Lokesh Dhakar)?

Lightbox2 is a JavaScript library that overlays images on top of the current page. You include one stylesheet and one script, then add a data-lightbox attribute to any link that points at an image:

<link rel="stylesheet" href="css/lightbox.min.css">
<script src="js/lightbox-plus-jquery.min.js"></script>

<a href="images/photo-1.jpg" data-lightbox="roadtrip">
  <img src="images/thumb-1.jpg" alt="Photo 1">
</a>

Links that share the same data-lightbox value become a gallery you can step through. That is the whole API for most sites, which is exactly why Lightbox spread so widely: there is nothing to initialize and nothing to configure.

Why Lightbox Still Shows Up on Portfolio, Gallery and WordPress Sites

Lightbox2 is built on jQuery. The project ships two script variants: lightbox.js, which expects jQuery to already be on the page, and lightbox-plus-jquery.js, which bundles jQuery into the same file. That design fit perfectly into the jQuery-era web, so Lightbox became the default image viewer in photography portfolios, real estate listings, restaurant menus, and a large share of WordPress themes.

Those sites rarely get rebuilt. A theme purchased years ago still loads the same lightbox.min.js from its /js/ folder today, which is what makes Lightbox a useful signal: it tells you a site was built on a jQuery-based frontend and has probably not been re-platformed since.

How to Detect Lightbox Manually

For one site, the browser is enough. Lightbox leaves four independent traces: a script tag, a stylesheet, a JavaScript global, and data-lightbox attributes in the markup.

View Source: Look for lightbox.js, lightbox.min.js or lightbox-plus-jquery.js Script Tags

Open the page source (Ctrl+U or Cmd+Option+U) and search for "lightbox". From the command line, one grep does the same job:

curl -s https://lokeshdhakar.com/projects/lightbox2/ | grep -oiE '<script[^>]*lightbox[^>]*>'

On Lightbox's own project page, that returns the bundled build loaded from the vendor folder (plus a path/to/lightbox.js tag inside the page's installation instructions):

<script src="path/to/lightbox.js">
<script src="vendor/lightbox2/js/lightbox-plus-jquery.min.js">

The usual filenames are lightbox.js, lightbox.min.js, lightbox-plus-jquery.js and lightbox-plus-jquery.min.js. When Lightbox is loaded from cdnjs, the path also contains the version, for example /ajax/libs/lightbox2/2.11.4/js/lightbox.min.js.

Check for lightbox.css or lightbox.min.css Stylesheet Links

Lightbox cannot draw its overlay without its stylesheet, so a matching CSS link almost always sits next to the script:

curl -s https://lokeshdhakar.com/projects/lightbox2/ | grep -oiE '<link[^>]*lightbox[^>]*>'
<link rel="stylesheet" href="vendor/lightbox2/css/lightbox.min.css">
<link href="path/to/lightbox.css" rel="stylesheet" />

A stylesheet on its own is weaker evidence than a script. Some themes copy the CSS but never load the JavaScript, and a few other libraries reuse the lightbox.css filename.

DevTools Console: Test for the Lightbox Global Object

Lightbox2 creates a global instance named lightbox when it loads. Open DevTools on the target page and run:

(function () {
  var hasLightbox = typeof window.lightbox === 'object' && window.lightbox !== null;
  var hasJQuery = typeof window.jQuery === 'function';
  var links = document.querySelectorAll('a[data-lightbox]').length;
  console.log({ lightbox: hasLightbox, jquery: hasJQuery, lightboxLinks: links });
})();

A page running Lightbox2 prints something like { lightbox: true, jquery: true, lightboxLinks: 12 }. This is the most reliable manual test, because it catches Lightbox even when it has been bundled into a single app.min.js file and no longer has its own script tag.

Inspect data-lightbox Attributes on Image Links

The last trace is in the markup itself. Right-click a gallery thumbnail, choose Inspect, and look at the surrounding <a> tag. A data-lightbox="..." attribute is Lightbox2's own convention. To count them from the shell:

curl -s https://lokeshdhakar.com/projects/lightbox2/ | grep -oE 'data-lightbox="[^"]*"' | sort | uniq -c
      1 data-lightbox="example-1"
      1 data-lightbox="example-2"
      4 data-lightbox="example-set"
      1 data-lightbox="image-1"
      3 data-lightbox="roadtrip"

Each distinct value is one gallery, so this also tells you how many galleries the page contains.

Lightbox vs Similar Libraries: FancyBox and Responsive Lightbox & Gallery

"Lightbox" is also the generic name for the whole UI pattern, so not every image overlay is Lightbox2. Two look-alikes come up constantly, and DetectZeStack reports each one as its own technology.

TechnologyScript signalCategoryVersion
Lightboxlightbox.js, lightbox-plus-jquery.jsJavaScript librariesNot captured
FancyBoxjquery.fancybox(.min|.pack).jsJavaScript librariesFrom ?v= query string
Responsive Lightbox & Gallery/wp-content/plugins/responsive-lightbox/...front.jsWordPress plugins, Photo galleriesFrom ?ver= query string

Telling Lightbox2 Apart from FancyBox (jquery.fancybox.js) and the WordPress responsive-lightbox Plugin

Why Lightbox Often Appears Alongside jQuery

Lightbox2 depends on jQuery, so any page that runs it also runs jQuery — either as a separate script or inside the lightbox-plus-jquery bundle. In the DetectZeStack fingerprint data, Lightbox does not declare an automatic "implies jQuery" relationship (FancyBox does). In practice jQuery usually shows up anyway because it has its own signals, as it does in the live scan below. For jQuery's own detection methods, see How to Detect jQuery on Any Website.

Limits of Manual Detection (Bundled Scripts, Renamed Files, Lazy-Loaded Galleries)

The manual checks work well on a single page, and each one has a blind spot:

For more than a handful of sites you want the same answer as structured JSON, one HTTP request per domain.

API Example: Detect Lightbox with DetectZeStack

DetectZeStack fetches the page over HTTP and matches its HTML against technology fingerprints. For Lightbox, the signal the scanner evaluates is the script tag: a src containing lightbox or lightbox-plus-jquery followed by a .js filename, matched case-insensitively. The scanner does not execute JavaScript, so the lightbox global and the stylesheet link are not used as detection signals. A site that bundles Lightbox into an unrelated filename will not show it; the console check above is the fallback for those.

Try It Without a Key via /demo

The public /demo endpoint runs the same detection with no authentication. It is rate-limited but ideal for checking the response shape. Lightbox's own project page makes a good test target:

curl -s "https://detectzestack.com/demo?url=https://lokeshdhakar.com/projects/lightbox2/" | python3 -m json.tool

A live scan run for this article returned seven technologies. Trimmed to the two JavaScript libraries, the response looks like this:

{
  "url": "https://lokeshdhakar.com/projects/lightbox2/",
  "domain": "lokeshdhakar.com",
  "technologies": [
    {
      "name": "Lightbox",
      "categories": ["JavaScript libraries"],
      "confidence": 100,
      "description": "Lightbox is small javascript library used to overlay images on top of the current page.",
      "website": "https://lokeshdhakar.com/projects/lightbox2/",
      "icon": "Lightbox.png",
      "cpe": "cpe:2.3:a:lightbox_photo_gallery_project:lightbox_photo_gallery:*:*:*:*:*:*:*:*",
      "source": "http"
    },
    {
      "name": "jQuery",
      "categories": ["JavaScript libraries"],
      "confidence": 100,
      "description": "jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.",
      "website": "https://jquery.com",
      "icon": "jQuery.svg",
      "cpe": "cpe:2.3:a:jquery:jquery:*:*:*:*:*:*:*:*",
      "source": "http"
    }
  ],
  "categories": {
    "JavaScript libraries": ["jQuery", "Lightbox"]
  },
  "meta": { "status_code": 200, "tech_count": 7, "scan_depth": "full" },
  "cached": false,
  "response_ms": 394
}

The other five entries in that scan were Apache HTTP Server, Cloudflare, Google Analytics, cdnjs and Let's Encrypt.

Single Site with GET /analyze

For production use, subscribe on RapidAPI and call /analyze with your key. It returns the same shape as /demo, without the demo rate limit:

curl -s -H "X-RapidAPI-Key: YOUR_KEY" \
  -H "X-RapidAPI-Host: detectzestack.p.rapidapi.com" \
  "https://detectzestack.p.rapidapi.com/analyze?url=example.com" \
  | jq '.technologies[] | select(.name == "Lightbox")'

If Lightbox is detected, the filter prints its object. If not, jq prints nothing, which makes the command easy to drop into a shell loop. To check all three overlay libraries at once:

curl -s -H "X-RapidAPI-Key: YOUR_KEY" \
  -H "X-RapidAPI-Host: detectzestack.p.rapidapi.com" \
  "https://detectzestack.p.rapidapi.com/analyze?url=example.com" \
  | jq '[.technologies[].name | select(. == "Lightbox" or . == "FancyBox" or . == "Responsive Lightbox & Gallery")]'

Reading the technologies Array: name, categories, confidence, version

Treat a Lightbox hit as "a lightbox-named script," then confirm. The script pattern is deliberately broad: any src with lightbox in it followed within a few characters by .js matches. That catches renamed Lightbox2 builds, but it also means other lightbox-named scripts — for example the Responsive Lightbox & Gallery plugin's front.js — can produce a Lightbox entry too. If the same response also lists Responsive Lightbox & Gallery, the plugin is the more specific answer.

Scanning Many Sites with POST /analyze/batch

POST /analyze/batch accepts up to 10 URLs per request and scans them concurrently. Each URL counts against your quota the same as a single /analyze call:

curl -s -X POST "https://detectzestack.p.rapidapi.com/analyze/batch" \
  -H "X-RapidAPI-Key: YOUR_KEY" \
  -H "X-RapidAPI-Host: detectzestack.p.rapidapi.com" \
  -H "Content-Type: application/json" \
  -d '{"urls": ["https://example.com", "https://example.org", "https://example.net"]}' \
  | jq -c '.results[] | {url: .url, lightbox: ([.result.technologies[]? | select(.name == "Lightbox")] | length > 0)}'

The batch response wraps one object per URL in a results array, with total_ms, successful and failed counters alongside. The filter reduces it to one line per domain:

{"url":"https://example.com","lightbox":false}
{"url":"https://example.org","lightbox":false}
{"url":"https://example.net","lightbox":false}

For lists longer than 10, loop over the file in chunks. Batch Scan 1,000 Websites for Tech Stack covers concurrency, retries and quota handling.

Comparing Gallery Stacks Across Competitors with POST /compare

POST /compare takes 2 to 10 URLs and returns each domain's technologies, a per-domain unique array, and a top-level shared array. It is a quick way to see which competitors still run a jQuery-era gallery:

curl -s -X POST "https://detectzestack.p.rapidapi.com/compare" \
  -H "X-RapidAPI-Key: YOUR_KEY" \
  -H "X-RapidAPI-Host: detectzestack.p.rapidapi.com" \
  -H "Content-Type: application/json" \
  -d '{"urls": ["competitor-one.com", "competitor-two.com", "competitor-three.com"]}' \
  | jq '[.domains[] | {domain, galleries: [.technologies[].name | select(. == "Lightbox" or . == "FancyBox" or . == "Responsive Lightbox & Gallery")]}]'

If Lightbox appears in shared, every site in the comparison runs it.

Use Cases: Lead Generation, Agency Audits, Dependency and CPE Vulnerability Checks

Conclusion and Next Steps

On a single page, Lightbox is easy to find: a lightbox.min.js or lightbox-plus-jquery.min.js script tag, a lightbox.css link, data-lightbox attributes on image links, and a lightbox global in the console. Across hundreds of domains, one /analyze call per site, or ten at a time through /analyze/batch, returns a Lightbox entry whenever a lightbox-named script is on the page. Keep two details in mind: the API does not report a Lightbox version, and FancyBox and Responsive Lightbox & Gallery are reported as separate technologies.

The free tier on RapidAPI includes 100 requests per month with no credit card, and paid plans start at $9/month for 1,000 requests. Every plan uses the same endpoints and response shape shown above.

Related Reading

Detect Lightbox and Every Other Library in One API Call

One HTTP request returns every framework, library, CDN, CMS and analytics tag on a page. 100 requests per month free. No credit card.

Get your free API key

Get API updates and tech detection tips

Join the mailing list. No spam, unsubscribe anytime.