Does my site tell strangers what software it runs?
Every response your server sends carries a few lines of labels before the page itself. Some of those labels name the software behind your site, and sometimes its exact version. That is a free hint to anyone looking for a known weakness, and it does nothing for your visitors.
What it actually is
Think of it as a name badge your server wears to every meeting. A badge that says "web server" is harmless. One that says which product and which release, or which framework built the page, tells a stranger exactly which list of known flaws to check against. We read those response labels on your page, the server, powered-by and generator lines among them, and look for a product name with a version, or a header whose only job is to announce the stack.
Why it matters
Automated tools sweep the web for sites running releases with published flaws, and a version number in a header saves them the trouble of guessing. Security reviewers and procurement questionnaires flag the same thing, so a leak can cost you an awkward conversation even when the software is fully patched.
What good looks like
Response headers that describe the response and nothing about the machinery: either no server label at all, or a generic one with no product version, and no powered-by or generator line naming the framework or CMS behind the page.
Being honest about it
This one does not move your score. It sits in the Good practice group because it does not change whether a machine can read your page; it is a hardening detail. It is also a modest one: hiding a version does not fix an old release, and a determined attacker can often fingerprint the stack in other ways. Keeping the software patched matters far more. We still mention it because the label is pure downside.
Where most sites go wrong
Most leaks are defaults nobody chose. A framework adds its powered-by line out of the box, a CMS stamps its name and release into a generator header, an old server config was never told to keep quiet. Sites behind a CDN often have the server line rewritten for them, while the framework header passes straight through untouched.
Not sure where yours stands?
A free scan checks this and everything else in about 20 seconds — no signup. Or if it's already flagged and you'd rather it were simply handled, we do that too.
Flagged for this one? We handle it. No pitch, just a plain-English chat.
Book a call