Exposure and discovery
Technology detector
See which web server, CDN or hosting platform, framework and content management system a site's home page discloses, with any version number it gives away. It is the same view anyone on the internet has, including automated tools looking for sites that run a particular version.
What this checks
- One request for the home page of the domain and, for a registrable domain, its
www.name: HTTPS first, plain HTTP if HTTPS does not answer, following up to 2 redirects. - Response headers that name software, such as
ServerandX-Powered-By, and headers that identify a CDN or hosting platform. - Cookie names that belong to a platform, such as
PHPSESSIDorJSESSIONID. - Markup in the page, such as a
generatormeta tag left by a content management system. - For each technology: its type, the version where one is disclosed, and where it was seen.
What the result means
The result lists what the home page reveals, not everything the site runs. A CDN in front of the site often hides the server behind it, and a well-configured server names no version. A technology with no version shown was named without one.
Every item is informational; nothing here is a finding on its own. A disclosed version is worth attention for two reasons: it tells anyone scanning the internet which known vulnerabilities to try, and if it is old, it may no longer receive security fixes. The end-of-life software checker compares disclosed versions with a list of releases that no longer do.
Detection is observation and inference. A header can be set by a proxy rather than the server behind it, and markup can be left over from an old build, so treat each item as something to confirm, not as an inventory.
Cyber Essentials and ISO 27001
ISO/IEC 27001:2022 Annex A 5.9 Inventory of information and other associated assets and 8.8 Management of technical vulnerabilities both depend on knowing what software you run. What a site discloses from outside is technical evidence to cross-check that knowledge against, not a replacement for an inventory kept from the inside.
The organisation still has to own the inventory: who maintains it, how it is kept current when systems change, and how it feeds patching. Cyber Essentials' security update management theme depends on the same knowledge.
Scope and limitations
- It reads the home page of each host and nothing else. Software used on other pages, behind a login or on other subdomains is not seen.
- A CDN or reverse proxy in front of the site usually hides the server and software behind it.
- It recognises software from a fixed set of headers, cookie names and markup patterns. It does not run scripts, request other paths or fingerprint the server by its behaviour.
- Versions are what the site advertises. Vendors and Linux distributions often backport security fixes without changing the advertised version.
Related guides
Questions
- Should I hide my server version?
- Yes, where you can. A version number helps attackers choose which known vulnerabilities to try, and visitors have no use for it. Most web servers and frameworks can be configured not to send it. Hiding it does not replace patching.
- Why does it show only my CDN?
- Because the CDN answers the request and sets its own headers, so the server behind it is rarely visible. That is normal.
- Does it run JavaScript or crawl the site?
- No. It requests the home page of each host, follows redirects, and reads the response's headers, cookie names and HTML. Nothing else is requested.
Related security tools
- End-of-life software checker - See whether a site advertises software versions that no longer receive security fixes.
- HTTP security headers checker - Check a site's HSTS, CSP, framing, content-type, referrer and permissions headers.
- Subdomain finder - Find a domain's subdomains in public certificate transparency logs.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

