Remove PHP X-Powered-By & Nginx Server Details from HTTP Response Header

To remove Server details from Response Header for e.g. security reasons, like

Server nginx/1.2.4
X-Powered-By PHP/5.3.17-1~dotdeb.0

it´s necessary to edit php.ini & nginx.conf as follows.

To remove X-Powered-By completely, expose_php should be disabled in php.ini.
expose_php = Off


To remove Server Version from Header, server_tokens should be disabled in nginx.conf.
server_tokens off;

See also:,1646