Skip to content

Exposure and discovery

Technology detector

See which web server, CDN or hosting platform, framework and content management system a site's home page discloses, with any version number it gives away. It is the same view anyone on the internet has, including automated tools looking for sites that run a particular version.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

The result lists what the home page reveals, not everything the site runs. A CDN in front of the site often hides the server behind it, and a well-configured server names no version. A technology with no version shown was named without one.

Every item is informational; nothing here is a finding on its own. A disclosed version is worth attention for two reasons: it tells anyone scanning the internet which known vulnerabilities to try, and if it is old, it may no longer receive security fixes. The end-of-life software checker compares disclosed versions with a list of releases that no longer do.

Detection is observation and inference. A header can be set by a proxy rather than the server behind it, and markup can be left over from an old build, so treat each item as something to confirm, not as an inventory.

Cyber Essentials and ISO 27001

ISO/IEC 27001:2022 Annex A 5.9 Inventory of information and other associated assets and 8.8 Management of technical vulnerabilities both depend on knowing what software you run. What a site discloses from outside is technical evidence to cross-check that knowledge against, not a replacement for an inventory kept from the inside.

The organisation still has to own the inventory: who maintains it, how it is kept current when systems change, and how it feeds patching. Cyber Essentials' security update management theme depends on the same knowledge.

Scope and limitations

Related guides

Questions

Should I hide my server version?
Yes, where you can. A version number helps attackers choose which known vulnerabilities to try, and visitors have no use for it. Most web servers and frameworks can be configured not to send it. Hiding it does not replace patching.
Why does it show only my CDN?
Because the CDN answers the request and sets its own headers, so the server behind it is rarely visible. That is normal.
Does it run JavaScript or crawl the site?
No. It requests the home page of each host, follows redirects, and reads the response's headers, cookie names and HTML. Nothing else is requested.

Related security tools