↑ ↓ select, Enter open, Esc close

Detect the web server and PHP version from HTTP headers

Adjust the values, the command updates live
user@server
curl -sI https://example.com/ | grep -iE "^(server|x-powered-by|via):"

Shows which server identifies itself (nginx, Apache, LiteSpeed) and whether PHP reveals itself and its version via X-Powered-By. On Plesk with the nginx proxy this shows nginx, even though Apache generates the page. Version numbers in these headers make it easier for attackers to look for known vulnerabilities.

Note: For nginx, server_tokens off; hides the version, for PHP use expose_php = Off in php.ini.

Also searched as

  • which web server is a site running
  • check if site uses nginx or apache
  • hide php version in header
  • check x-powered-by removed

Related one-liners

All in nginx

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.