Skip to main content
drupalreleases

Use direct release data with your AI assistant.

Learn more

Remove HTTP headers

Security covered Under active development 13,975 sites

This module removes specific HTTP headers from your website's responses. It can also remove the Drupal generator meta tag from your HTML's head section if the corresponding HTTP header is configured for removal.

Overview

The Remove HTTP headers module removes configured HTTP headers from the response. Also removes <meta name="Generator" content="Drupal 8 (https://www.drupal.org)"> from the <head> tag if the X-Generator HTTP header is configured to be removed. By default the X-Generator, X-Drupal-Dynamic-Cache and X-Drupal-Cache HTTP headers are configured to be removed.

Motivation

The initial idea of this module is to obfuscate that your website is running on Drupal. However this module can of course be used for other purposes as well.

Disclaimer

Be aware that there are also other ways than HTTP headers to find out if Drupal is used by a website. Obfuscation is not a replacement for a secure website. Make sure you always have the latest security updates installed and are writing secure code in your custom modules and themes.

Features

  • Remove configured HTTP headers from responses.
  • <meta name="Generator" content="Drupal 8 (https://www.drupal.org)"> from the <head> tag if the X-Generator HTTP header is configured to be removed.

Installation

Install as you would normally install a contributed Drupal module. Visit:
https://www.drupal.org/docs/8/extending-drupal-8/installing-drupal-8-mod...
for further information.

Configuraton

  • Configure the HTTP headers that should be removed on the settings page (/admin/config/system/remove-http-headers) or directly in the remove_http_headers.settings.yml configuration file.
    • Use the following format:
      headers_to_remove:
        - 'X-Generator' 
        - 'X-Drupal-Dynamic-Cache'
        - 'X-Drupal-Cache'

Requirements

  • This module requires Drupal 10 or above.
  • No additional modules are needed.
Drupal 10–11

Ask your assistant about Remove HTTP headers

Check compatibility with your Drupal and PHP version, maintenance and security coverage, from current release data. How it works

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

1 tracked project depends on this one

Activity

Tracked releases
5
Tracked since
Nov 2023
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Dormant

Release Timeline

Releases

Version Type Core PHP Release date
2.1.2 Stable 10–11 Oct 10, 2024
2.x-dev Dev 10–11 Oct 10, 2024
2.1.1 Stable 10–11 Oct 10, 2024
2.1.0 Stable 10 Nov 29, 2023
2.0.1 Stable 9–10 Nov 3, 2023