SSL & Security
Server Signature Test
Server Signature Analyzer
Tool features
4 checks
Server Signature Detection
Identify server software, versions, and technology stack from HTTP headers
Risk Assessment
Evaluate security risks from information disclosure
Security Recommendations
Get actionable recommendations to hide server information
Comprehensive Analysis
Analyze all server-revealing headers and technology indicators
What is a server signature & how it works
A server signature is the software and version information a web server volunteers in its responses: the Server header, framework headers such as X-Powered-By, and sometimes the footer of default error pages.
Exact versions let an attacker match your stack against published vulnerabilities without probing further. This test requests your page, reads the response headers, detects the software and versions they reveal, and rates the disclosure risk with the configuration change that removes it.
Server
Names the web server, e.g. nginx/1.24.0; the version is the risky part.
X-Powered-By
Names the application framework or language, e.g. PHP/8.2.
Information disclosure
Leaking details that help an attacker plan an exploit.
How to use this tool
1
Enter a URL
Type the site or page to test, e.g. https://example.com.
2
Run the test
The tool requests the page and reads every response header.
3
Review the risk
Headers revealing exact versions are rated highest; product names alone are low risk.
4
Hide the details
Apply the recommended directive (ServerTokens, server_tokens, expose_php and so on) and test again.
Related tools
4 tools
HTTP Header Checker
Analyze HTTP response headers for any website or URL with detailed header information
Secure Header Checker
Check security headers like CSP, HSTS, X-Frame-Options, and more with security scoring
OCSP Checker
Check SSL certificate revocation status using the Online Certificate Status Protocol (OCSP)
HSTS Checker
Check HTTP Strict Transport Security (HSTS) header configuration and preload status
Frequently asked questions
9 Q&A
Server signatures reveal information about your server software and versions, which can help attackers identify known vulnerabilities. Testing helps you identify and remove these information disclosure risks to improve your security posture.
Common headers that reveal server information include: Server (web server software), X-Powered-By (application framework), X-AspNet-Version (ASP.NET version), X-Runtime (Ruby on Rails), and other technology-specific headers.
Yes. The Server Signature Test tool is completely free for everyone to use.
The method depends on your server software. For Apache, you can use ServerTokens and ServerSignature directives. For Nginx, set server_tokens off to hide the version (removing the Server header entirely needs the headers-more module). For application frameworks, check their documentation for removing X-Powered-By and similar headers.
Yes. You can test any publicly accessible website by entering its URL. The tool will analyze the HTTP headers returned by the server.
The risk level is calculated based on whether version information is disclosed. Version disclosure (e.g., 'Apache/2.4.41' or 'PHP/7.4.3') is marked as CRITICAL/HIGH risk because it helps attackers identify vulnerabilities. Server names without versions (e.g., just 'Apache' or 'nginx') are marked as LOW risk and are relatively safe, though hiding them entirely is still recommended for maximum security.
Yes, showing only the server name (like 'Apache' or 'nginx') without version information is relatively safe and marked as LOW risk. However, for maximum security, it's still recommended to hide the Server header completely. Version disclosure (like 'Apache/2.4.41') is a serious security risk and should be removed immediately.
The X-Powered-By header should be removed completely for maximum security, even if it doesn't contain version information. While showing framework name without version is safer than showing version, it still discloses your technology stack which can help attackers. The tool will recommend removing this header regardless of whether version is present.