Detect the web server and PHP version from HTTP headers
which web server is a site running | check if site uses nginx or apache | hide php version in header | check x-powered-by removed | curl | headers | webserver | phpcurl -sI https://example.com/ | grep -iE "^(server|x-powered-by|via):"Shows which server identifies itself (nginx, Apache, LiteSpeed) and whether PHP reveals itself and its version via X-Powered-By. On Plesk with the nginx proxy this shows nginx, even though Apache generates the page. Version numbers in these headers make it easier for attackers to look for known vulnerabilities.
Note: For nginx, server_tokens off; hides the version, for PHP use expose_php = Off in php.ini.
Also searched as
- which web server is a site running
- check if site uses nginx or apache
- hide php version in header
- check x-powered-by removed