express
express copied to clipboard
X-Powered-By Header Enabled By Default
Official documentation recommends that at a minimum we remove the X-Powered-By
header when running Express in production. Why is it enabled by default?
Please disable this header in the default configuration.
See https://github.com/expressjs/express/pull/2813#issuecomment-159270428 . This is a decision made by the project. I'm not sure when the wording of the website was changed, but we'll get it made to better reflect it.