Spring Security is the security framework of Spring applications.
About 925 websites in the PageSourceSearch index contain the code that reveals it; the 50 highest-ranked are listed below.
How is Spring Security detected?
Spring applications expose the CSRF header name to scripts in a meta tag named _csrf_header, the convention of the Spring documentation. The discovery keyword is the exact bytes PageSourceSearch looks for in every stored page and script:
A literal is matched byte for byte, case-sensitively. Combine it with another keyword, a domain, a kind or a date filter on the search page to narrow the list. About Spring Security
Top 50 websites using Spring Security
Ranked by the domain's position in the crawl's ranked list (Common Crawl harmonic centrality), highest first. view source opens the stored page or script with the match highlighted. Computed 2026-10-01 00:42:22 UTC.
How does PageSourceSearch know a website uses Spring Security?
By the source itself: Spring applications expose the CSRF header name to scripts in a meta tag named _csrf_header, the convention of the Spring documentation. PageSourceSearch stores the raw HTML and first-party JavaScript of each crawled site and matches the keyword byte for byte, so every listed site's stored source contains it.
Is this a complete list of websites using Spring Security?
No. The page lists the 50 highest-ranked sites in the index whose source holds the keyword, out of about 925 websites that do; the count is the index's estimate at the time the list was computed. Run the keyword as a search to page through all of them, or add a kind or date filter.
How do I find websites that use Spring Security together with another technology?
Search for both keywords at once: several terms separated by spaces must all be found on the same site, or with the Same page toggle in the same page. For example name="_csrf_header" with wp-content/plugins/ lists the WordPress sites that use Spring Security.