Skip to main content
New: 190 SEO checks now available. See what's new
lowSecurityPOWERED_BY_HEADER

X-Powered-By header present — the fix

The X-Powered-By header reveals the technology stack (e.g., Express, PHP, ASP.NET) used by the application.

Where this fits: security in SEO

Security issues erode both rankings and trust. HTTPS has been a ranking signal since 2014, and browsers actively warn users away from insecure or mixed-content pages — a warning interstitial is a 100% bounce rate. Missing security headers rarely block indexing, but they widen your attack surface, and a hacked site (injected spam, malicious redirects) can be removed from results entirely. Security is the SEO work you do so you never have to do recovery work.

Why x-powered-by header present hurts your rankings

The X-Powered-By header discloses your application framework, enabling attackers to target framework-specific vulnerabilities. Removing this header is a simple hardening step that reduces your attack surface information.

This is a low-severity issue: a polish item. Fix it in batches during scheduled maintenance; the win is cumulative quality, not a step change.

How to fix it

Remove the X-Powered-By header from responses. In Express.js, use app.disable('x-powered-by') or the helmet middleware. In PHP, set expose_php = Off in php.ini.

// Express.js
app.disable('x-powered-by');

// Or use helmet
app.use(helmet());

Security best practices

  • Serve everything over HTTPS and redirect HTTP with a single 301.
  • Send HSTS, X-Content-Type-Options, and a Content-Security-Policy on every response.
  • Eliminate mixed content — one insecure asset breaks the padlock.
  • Keep dependencies and CMS plugins patched; most site hacks are known-CVE exploits.
  • Monitor Search Console's security section — Google often knows you're hacked before you do.

The full library: SEO best practices, by category.

Frequently asked questions

What does "X-Powered-By header present" mean?

The X-Powered-By header reveals the technology stack (e.g., Express, PHP, ASP.NET) used by the application.

Why does x-powered-by header present matter for SEO?

The X-Powered-By header discloses your application framework, enabling attackers to target framework-specific vulnerabilities. Removing this header is a simple hardening step that reduces your attack surface information.

How do I fix x-powered-by header present?

Remove the X-Powered-By header from responses. In Express.js, use app.disable('x-powered-by') or the helmet middleware. In PHP, set expose_php = Off in php.ini.

How serious is this issue?

This is a low-severity issue: a polish item. Fix it in batches during scheduled maintenance; the win is cumulative quality, not a step change. It belongs to the security family of checks.

How do I find every page affected by this on my site?

Run a free Dr Urls audit: it crawls your site, detects x-powered-by header present on every affected page, shows example URLs, and generates a ready-to-use fix task. Re-scan after fixing to verify the issue is gone.

Does your site have this issue?

A free Dr Urls audit crawls your site, finds every page affected by x-powered-by header present, and hands you a ready-made fix task.

Check my site free

Related security guides