Security

CMS detector

See the CMS and server software a site gives away.

Example CMS detector result

What this checks

Many sites announce the software that runs them, through a generator meta tag in the HTML and through response headers like Server and X-Powered-By.

This tool reads the homepage and reports the CMS, generator and server software it finds exposed, along with version numbers where they are published.

Why it matters

A published version number tells an attacker exactly which known vulnerabilities to try, so exposing it is a small but real risk that is easy to remove.

For an agency taking over a site, the exposed software is also a fast way to learn what a client is actually running before you quote the work.

How to fix common failures

1

Remove the generator tag

Most platforms can drop the generator meta tag, or a plugin or theme setting will hide it.

2

Trim the headers

Strip or shorten the Server and X-Powered-By headers at the web server or CDN so they do not name a version.

3

Keep software current

Hiding the version helps, but the real fix is staying patched so a known version is not worth attacking.

CMS detector is one check. Janitor watches exposed CMS and server software automatically across every client site and puts it in a branded report.

Start your free trial

Keep reading

Related

FAQ

CMS detector FAQ

Why can the tool not always detect the CMS?

A well-configured site removes the generator tag and trims its headers, so nothing is exposed to read. No detection here is a good sign, not a failure.

Is exposing the CMS actually dangerous?

On its own it is low risk, but it makes a site easier to target. Removing the version is a quick, sensible hardening step.

Can Janitor watch this across many sites?

Yes. Janitor flags exposed CMS and server fingerprints on every client site, so a theme or host change that starts leaking a version is caught.

Get started

Check it once, or watch it for every client

Janitor runs around two dozen checks on every site you manage and turns them into a branded report.

30-day free trial. No credit card required.