Web server · response disclosures

Check web server headers and technology disclosures

Inspect one public HTML response for retained Server, X-Powered-By, Via, Cloudflare Ray, Vercel request ID, and meta generator disclosures. Export the exact evidence and review practical cleanup actions without pretending to fingerprint the whole stack.

FETCHHTML GETHEADERSRETAINEDEXPORTCSV + JSON

Evidence boundary: OpenWebmaster inspects one bounded HTML GET response, retained response headers, and source-visible generator metadata. It does not fingerprint the full server stack, confirm hosting provider, CDN, WAF, origin, vulnerabilities, software versions, patch status, uptime, rankings, traffic, or cause.

SRV

Ready for a public HTML page.

No sample hosting provider, CDN verdict, WAF verdict, vulnerability claim, patch status, uptime grade, ranking impact, traffic claim, or manufactured server score appears before a live response is inspected.

Disclosure cleanup workflow

Use response evidence before changing server or edge configuration

Review what is actually public

Server and runtime headers can be intentionally broad, accidental, or rewritten by an edge service. Keep the exact response evidence with the ticket.

Separate disclosure from risk

A header can expose useful context, but vulnerability and patch status require dedicated security tooling and owner-approved testing.

Check the terminal URL

Redirects can move the final page to another host or edge. Inspect the response users and crawlers actually receive.