Security · Next.js (App Router)
How to stop advertising software versions in headers in Next.js (App Router)
This does not create a vulnerability, it removes the work of finding one — a scanner can match your exact version against known CVEs instead of probing. Suppressing the header is usually one config line.
The fix for Next.js (App Router)
13x detects your framework from the response and hands you this version rather than the generic one — below 50% confidence it hedges and gives you the generic one instead.
// next.config.ts
const nextConfig: NextConfig = {
poweredByHeader: false,
};That removes X-Powered-By: Next.js. A Server header with a version usually comes from a proxy in front of the app rather than from Next.
On a different stack? The general version of this fix explains what 13x checks and why it matters, without assuming a framework.
Check your Next.js (App Router) site
113 deterministic checks against your live URL, in about 30 seconds. Framework detected from the response, so every fix comes back in the form your stack actually uses.
No signup. Results in 30 seconds.