-
-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Description
I know that security through obscurity is a weak defense, if any. However, I like to remove all the version identifiers from the software that I expose to the public. The less an attacker knows about the infrastructure, the better.
Is there a way to remove the version identifiers from nodeinfo (and likely your other plugins)? I don't even truly mind that it still says WordPress.
For instance, the ActivityPub endpoint /wp-json/activitypub/1.0/nodeinfo2 exposes software and version for WordPress. Additionally nodeinfo provides a generator with information about the software and version in question via /wp-json/nodeinfo/2.1.
Perhaps I'm able to see this because I'm logged in?
Metadata
Metadata
Assignees
Labels
No labels