Site AI Auditby Internet Solutions

Exposed Software Versions: How to Hide Server and CMS Details

16 tháng 8, 20268 phút đọcBảo mật & SSL
Exposed Software Versions: How to Hide Server and CMS Details

Short answer: Many websites announce their exact software versions – for example Server: Apache/2.4.41 (Ubuntu), X-Powered-By: PHP/7.4.3 or a WordPress generator tag. Automated scanners use these details to find sites running versions with known vulnerabilities. Hide them by setting ServerTokens Prod and ServerSignature Off in Apache, server_tokens off in Nginx, expose_php = Off in PHP, and by removing generator tags and readme files from your CMS. Then keep the software updated, because hiding a version does not fix it.

“Exposed software versions” is a typical finding in a website security audit. It sounds minor – who cares if someone knows your PHP version? – but it is exactly the kind of information automated attack tools collect first. Hiding it takes a few configuration lines, costs nothing in performance, and removes an easy shortcut for attackers. This guide shows where versions usually leak and how to stop each leak on common servers and content management systems.

Why version numbers matter

Most attacks on small and medium websites are not personal. They are automated: bots scan large parts of the internet, collect information about each server, and match it against lists of known vulnerabilities. When a bot finds a response header that names a server or plugin version with a published exploit, the site moves to the top of the list.

Hiding version numbers does not make vulnerable software safe. What it does:

Security specialists call this “defence in depth”: each layer is not enough alone, but together they make an attack harder. The most important layer remains updating the software itself.

What attackers do with version information

It helps to picture the process from the other side. A typical automated campaign works in three stages. First, a scanner requests the home page of millions of addresses and stores the response headers and a few lines of page code. Second, the collected data is filtered: every site whose headers or generator tags match a version with a public exploit goes on a shortlist. Third, a separate tool runs the exploit against the shortlist, often within days or hours of a vulnerability being published.

Sites that reveal nothing are not immune – some tools simply try the exploit everywhere – but they drop out of the cheap, targeted part of the process. The same logic applies to plugins and themes: a readme file with a version number tells a scanner that your site runs, for example, a gallery plugin with a known upload flaw. Removing those details costs you nothing and costs the attacker time, which is exactly the trade you want.

Where software versions leak

LocationExampleCách khắc phục
Server headerServer: Apache/2.4.41 (Ubuntu)ServerTokens Prod (Apache), server_tokens off (Nginx)
X-Powered-By headerX-Powered-By: PHP/7.4.3expose_php = Off, or remove the header
Error pagesApache/2.4.41 Server at example.com Port 443ServerSignature Off, custom error pages
CMS generator meta tag<meta name=”generator” content=”WordPress 6.x”>Remove via theme or security plugin
Asset URLsstyle.css?ver=6.xRemove or replace version query strings
Readme and changelog files/readme.html, /CHANGELOG.txtDelete or block access
Framework headersX-AspNet-Version, X-GeneratorDisable in framework configuration
Default pages and admin toolsphpinfo.php, server-statusRemove or restrict to trusted IPs

How to check what your site reveals

Start with the response headers:

curl -sI https://example.com

Look for Server, X-Powered-By, X-Generator, X-AspNet-Version and similar lines. Then open the page source (Ctrl+U in most browsers) and search for “generator” and “ver=”. Finally, request a page that does not exist and look at the error page, and try a few common file paths such as /readme.html, /license.txt, /phpinfo.php and /server-status.

How to hide versions on common platforms

Apache

In the main configuration file (often apache2.conf, httpd.conf or a security.conf include), set:

ServerTokens Prod
ServerSignature Off

ServerTokens Prod reduces the header to Server: Apache without version or operating system. ServerSignature Off removes the version line from server-generated error pages. These directives work only in the main server configuration, not in .htaccess. On shared hosting where you cannot change them, ask your host. Also make sure mod_status and mod_info pages are disabled or restricted to administrators.

Nginx

In the http block of nginx.conf:

server_tokens off;

This removes the version from the Server header and default error pages, leaving just Server: nginx. Removing the header completely requires an extra module (such as headers-more) or a proxy in front; for most sites, hiding the version is enough. Restrict any stub_status location to internal addresses.

PHP and application frameworks

In php.ini set:

expose_php = Off

This stops PHP from adding the X-Powered-By header. On managed hosting, the setting is often available in the PHP options of the control panel. Also make sure display_errors is off in production, because error messages can reveal file paths, library versions and database details.

Other stacks have equivalents: ASP.NET can remove X-AspNet-Version and X-Powered-By through configuration, Express applications can disable x-powered-by, and many frameworks have a “production mode” that hides debugging details. Delete any phpinfo() test files left over from setup.

WordPress and other CMS platforms

WordPress exposes its version in several places by default: the generator meta tag, RSS feeds, ?ver= parameters on scripts and styles, and the readme.html file. Plugins and themes can reveal their versions in their own readme files. Practical steps:

Be realistic about the limits. A determined scanner can often fingerprint a CMS and even its approximate version from file contents and behaviour. That is exactly why updates matter more than hiding.

If you cannot change the settings yourself

On shared or managed hosting, server-level settings such as ServerTokens, server_tokens and sometimes expose_php are controlled by the host. A short support request usually solves it. Include the exact header lines you see, the hostname, and what you would like changed – for example: “Our site returns Server: Apache/2.4.41 (Ubuntu) and X-Powered-By: PHP/7.4.3. Please hide the version numbers and tell us whether a newer supported PHP version is available for our account.” The second question matters: a host that still runs an outdated PHP branch for your account is a bigger issue than the header itself.

Hiding is not patching

A version number is only dangerous when the version is vulnerable. The most effective security measure is keeping the web server, PHP, the CMS, plugins and themes on supported, updated versions. Use the exposure finding as a trigger to check:

  1. Is the version still supported by its developers? Unsupported branches no longer receive security fixes.
  2. Are automatic security updates enabled where possible – operating system packages, minor CMS releases?
  3. Is there a schedule for major upgrades, such as moving to a newer PHP branch before the current one reaches end of life?
  4. Are unused plugins, themes and test tools removed rather than only deactivated?

Checklist for closing version leaks

How Site AI Audit helps

The security part of a Site AI Audit report includes a check for exposed software versions, next to the SSL certificate, the HTTPS redirect and security headers. The report explains each finding in plain words and shows how to fix it, ranked by impact, so you can hand it to your host or developer directly. Run a free check to see what your server reveals.

Related reading

The bottom line

Exposed version numbers give automated scanners a shortcut to vulnerable sites. Hiding them takes a few lines in Apache, Nginx, PHP and your CMS, and removing leftover readme and test files closes the rest. But hiding is only a thin layer: the real protection comes from keeping every part of the stack on supported, updated versions.

FAQ

Is showing my server version a real security risk?

On its own it is a low risk, but it makes it easy for automated tools to match your site against known vulnerabilities. If the version is outdated, the combination becomes a real risk, which is why audits flag it.

Can I remove the Server header completely?

Most servers let you hide the version but not remove the header entirely without extra modules or a proxy in front. Showing only “nginx” or “Apache” without a version is generally considered sufficient.

Why does my WordPress readme.html file come back after I delete it?

WordPress core updates restore the file. Blocking access to it in the server configuration or .htaccess is more durable than deleting it after each update.

Does hiding version numbers affect performance or SEO?

No. The changes remove a few bytes from headers and page code, and search engines do not use this information for rankings.

Is hiding the version enough if I cannot update right away?

It reduces exposure to version-based scanning, but attackers can still probe for vulnerabilities directly. Treat it as a temporary measure and plan the update as soon as possible.

#Security headers#Website security#WordPress security
Hãy kiểm tra website của chính bạn — miễn phí.Website của bạn cần sửa gì — và nên bắt đầu từ đâu.
Bắt đầu miễn phí
Internet Solutions

Sản phẩm khác từ đội ngũ chúng tôi

Do Internet Solutions phát triển. Hãy thử các sản phẩm khác của chúng tôi — mỗi sản phẩm giúp bạn tiết kiệm thời gian theo một cách riêng.

internet-solutions.net ↗
01Tự động đăng mạng xã hội
PostRSS

Bài mới từ nguồn cấp RSS của bạn được tự động đăng lên Facebook, X, LinkedIn, Telegram và hơn 60 mạng khác.

Gói miễn phí · từ 2014Truy cập →
02Chat trực tuyến AI cho website
Talkmio

Website của bạn trả lời khách truy cập 24/7 từ chính nội dung của bạn, bằng ngôn ngữ của họ.

Gói miễn phí · không cần thẻTruy cập →
03Trợ lý AI
Ask Mio

Trò chuyện, viết code, thiết kế, viết bài và nghiên cứu. Mio chọn mô hình tốt nhất cho từng việc.

Gói miễn phíTruy cập →
04Lái tự động AI cho blog và mạng xã hội
AI Blog Autopilot

AI viết bài SEO dài 2.000–3.000 từ và chia sẻ từng bài lên hơn 58 mạng xã hội.

3 bài đầu tiên miễn phíTruy cập →
05Thu thập SEO chuyên sâu
Site SEO AI Audit

Thu thập SEO toàn diện trên 7 lĩnh vực, gồm cả khả năng hiển thị trong tìm kiếm AI, với cách sửa xếp theo mức tác động.

Lần kiểm tra đầu tiên miễn phíTruy cập →
06Nguồn cấp RSS và sản phẩm
RSS Feed Creator

Tạo RSS từ bất kỳ trang web nào, cùng nguồn cấp sản phẩm cho Google và Meta tự động cập nhật.

Gói miễn phíTruy cập →
07Phát triển website và SEO
Internet Solutions

Website, cửa hàng trực tuyến và hệ thống theo yêu cầu, do đội ngũ của chúng tôi thiết kế, xây dựng và vận hành.

Từ 2011Truy cập →
Site AI Audit
Tổng quan quyền riêng tư

Website này dùng cookie để mang lại trải nghiệm người dùng tốt nhất có thể. Thông tin cookie được lưu trong trình duyệt của bạn và thực hiện các chức năng như nhận ra bạn khi bạn quay lại, giúp đội ngũ chúng tôi hiểu phần nào của website bạn thấy thú vị và hữu ích nhất.