Skip to content

HTTP security configuration

Software versions in response headers

Whether response headers such as Server and X-Powered-By reveal the exact version of the software behind the site.

Part of the External Security Check. Free during the preview.

What it checks

Whether response headers such as Server and X-Powered-By reveal the exact version of the software behind the site.

A pass means: Response headers do not reveal software versions.

Possible findings

Software version disclosed in headers

Severity: LowConfidence: ConfirmedKind: Recommended hardening

What we found

Response headers reveal the exact version of server software.

Why it matters

Version numbers make it easy for automated tools to match your server against known vulnerabilities. Hiding them does not fix anything, but it removes a free signal.

How to fix it

Turn off version banners: server_tokens off; in nginx, ServerTokens Prod and ServerSignature Off in Apache, expose_php = Off in php.ini, and remove X-Powered-By where your framework adds it.

References