How to Hide PHP Version from HTTP Headers
Exposing the PHP version in HTTP response headers (e.g., X-Powered-By: PHP/7.4.3) gives attackers a clear target. By hiding this information you reduce the attack surface and protect your web application from automated vulnerability scans. This guide walks you through the most effective techniques to conceal the PHP version on Apache, Nginx, and shared‑hosting environments.
Why You Should Hide the PHP Version
When the PHP version is visible, malicious bots can quickly identify known exploits for that specific release. Even if your code is secure, an outdated PHP interpreter may contain vulnerabilities that can be leveraged remotely. Removing version details:
- Prevents automated scanners from flagging your site.
- Discourages opportunistic attackers.
- Aligns with security best practices and compliance standards (PCI‑DSS, OWASP).
Common Methods to Hide the PHP Version
1. Modify php.ini
The simplest and most reliable way is to edit the main PHP configuration file.
expose_php = Off
Setting expose_php to Off removes the X-Powered-By header entirely. After saving the file, restart your web server:
- Apache:
sudo systemctl restart apache2 - Nginx (with PHP‑FPM):
sudo systemctl restart php-fpm
2. Use .htaccess (Apache Only)
If you don’t have root access, you can override the header at the directory level:
Header unset X-Powered-By
php_flag expose_php off
Place the snippet in the .htaccess file of the root directory. Ensure the mod_headers module is enabled.
3. Adjust Server Configuration (Nginx)
For Nginx, edit the server block or the global configuration:
fastcgi_hide_header X-Powered-By;
After adding the line, reload Nginx:
sudo nginx -s reload
4. Override with PHP Code
When you cannot change server files, you can suppress the header at runtime:
<?php
header_remove('X-Powered-By');
// Optional: send a custom header instead
header('X-Powered-By: MySecureApp');
?>
Insert this snippet at the top of your entry script (e.g., index.php) to ensure it runs before any output.
Testing Your Changes
After applying any method, verify that the header is gone using curl, browser dev tools, or an online header checker.
curl -I https://yourdomain.com
You should no longer see a line similar to X-Powered-By: PHP/7.4.3. If the header persists, double‑check that the correct configuration file was edited and that the web server was restarted.
Best Practices & Additional Hardening
- Keep PHP Updated: Hiding the version is a defense‑in‑depth measure, not a substitute for regular updates.
- Disable Unused Modules: Remove extensions you don’t need (e.g.,
php_mysqlif you use PDO). - Use a Web Application Firewall (WAF): Tools like ModSecurity can block known attack patterns regardless of version disclosure.
- Monitor Logs: Regularly review server logs for suspicious requests targeting old PHP exploits.
Conclusion
Hiding the PHP version from HTTP headers is a quick win for web security. By setting expose_php = Off, adjusting .htaccess or Nginx config, or using runtime code, you can eliminate the X-Powered-By header and make your site less attractive to automated attacks. Combine this with regular updates and a layered security approach for optimal protection.