← All headersResponse header

What is an X-Powered-By header?

Identifies the technology powering the web application, e.g. a framework or language - often removed for security.

X-Powered-By broadcasts which framework or language is running a website - handy for a curious developer, but also a small, free hint to anyone probing for known vulnerabilities in a specific version of that stack. It's one of the easiest security headers to deal with: most frameworks let you disable it with a single line of configuration, and plenty of security-conscious sites do exactly that.

Common use case

A framework sets X-Powered-By: Express or X-Powered-By: PHP/8.2 by default, which many teams disable in production configuration purely to avoid handing an attacker a free hint about which known framework vulnerabilities to try.

Example

X-Powered-By: Express

History

An informal convention popularised by frameworks like PHP and ASP.NET in the late 1990s and early 2000s, never part of any official HTTP specification.

Did you know?

It's essentially the application-layer sibling of the Server header, revealing the framework running on top of the web server rather than the web server software itself.