Exposure and discovery
End-of-life software checker
See whether a site's home page advertises a version of PHP, Apache httpd, IIS, nginx or OpenSSL that no longer receives security fixes. A match is reported as a potential finding: an advertised version is a lead to check on the server, not proof.
What this checks
- One request for the home page of the domain and, for a registrable domain, its
www.name: HTTPS first, plain HTTP if HTTPS does not answer, following up to 2 redirects. - Every version number disclosed in headers such as
ServerandX-Powered-By, or in the page's markup. - Each version against a curated list, checked in October 2026: PHP before 8.2, Apache httpd before 2.4, IIS before 10, nginx before 1.18 and OpenSSL before 3.0.
- Severity by product: High for Apache httpd and IIS, Medium for PHP and OpenSSL, Low for nginx. Confidence is always low.
What the result means
Software past its end of life gets no fixes for vulnerabilities found after that date. A server running it stays exposed to each new one, and an advertised version tells anyone scanning the internet which ones to try.
A pass means no advertised version matched the list. Often that is because the site advertises no versions at all, which is good practice, but it says nothing about software that stays quiet. Only the five products listed are judged; other software is shown by the technology detector but not compared with any end-of-life date.
A finding is always marked potential. The version was inferred from what the server sends, and vendors and Linux distributions often backport security fixes without changing it. Someone who knows the server should confirm the installed version and its support status before acting.
How to fix common issues
Potentially end-of-life software
Confirm the installed version on the server. If it is genuinely end-of-life, upgrade to a supported release.
Cyber Essentials and ISO 27001
An end-of-life version on an internet-facing server bears on the security update management theme of Cyber Essentials and on ISO/IEC 27001:2022 Annex A 8.8 Management of technical vulnerabilities. This check is technical evidence for a small part of either: what one public page advertises.
The organisation still has to know what it runs from the inside, assign who tracks support dates for each product, and decide how unsupported software is upgraded, replaced or removed. A pass here does not show that any of that is in place.
Scope and limitations
- Only versions the home page advertises are seen. Many servers advertise none, and a CDN in front of the site usually hides them.
- Only PHP, Apache httpd, IIS, nginx and OpenSSL are compared, against a list checked in October 2026. Other software is not judged.
- An advertised version can be wrong for the software actually running: vendors backport fixes, and a proxy can send its own headers. Every finding needs confirming on the server.
- It does not log in, read package lists or test for any vulnerability.
Related guides
Questions
- Why is an end-of-life finding only potential?
- Because the version was read from what the server advertises, not from the software itself. Vendors and Linux distributions often backport security fixes to an old version number, so confirm what is installed and whether it is still supported before acting.
- Which PHP versions are end of life?
- As of October 2026, PHP releases before 8.2 no longer receive security fixes from the PHP project. Some Linux distributions support older versions for longer in their own packages.
- Is hiding the version number enough?
- No. It removes an easy clue for attackers, but the software is just as unsupported. Upgrade to a supported release, then stop advertising versions.
Related security tools
- Technology detector - See the web server, CDN and frameworks a site's home page discloses.
- HTTP security headers checker - Check a site's HSTS, CSP, framing, content-type, referrer and permissions headers.
- Exposed services checker - Check your domain for databases, remote desktop and other services open to the internet, once it is verified.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

