The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31577ede62577ede622b374d18
Apache Status Apache Server Status for nomadicnormandy.uk (via 127.0.0.1) Server Version: Apache/2.4.37 (CloudLinux) OpenSSL/1.1.1k mod_fcgid/2.3.9 Phusion_Passenger/6.0.27 Server MPM: event Server Built: Sep 4 2025 08:14:00 Current Time: Sunday, 19-Oct-2025 14:48:40 BST Restart Time: Thursday, 18-Sep-2025 06:33:07 BST Parent Server Config. Generation: 280 Parent Server MPM Generation: 279 Server uptime: 31 days 8 hours 15 minutes 32 seconds Server load: 0.91 0.96 1.23 Total accesses: 5602792 - Total Traffic: 171.8 GB - Total Duration: 3791412435 CPU Usage: u366.85 s242.52 cu856725 cs728363 - 58.6% CPU load 2.07 requests/sec - 66.5 kB/second - 32.1 kB/request - 676.701 ms/request 2 requests currently being processed, 0 workers gracefully restarting, 123 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusygracefulidlewritingkeep-aliveclosing 03639661no0yes0025000 13639743no1yes1024000 23639811no0yes0025000 32343487yes (old gen)0no000000 43639878no0yes1024000 52659113yes (old gen)1no000000 63639945no0yes0025000 Sum722 20123000 _____________________________W__________________________________ ___________................G........__W______________________... ...................G.._________________________ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-27936396610/6/42307_ 1.7101276772830.00.041165.96 127.0.0.1http/1.1default:7080GET /api/swagger.json HTTP/1.0 0-27936396610/6/41515_ 1.52242276971000.00.021411.06 5.161.177.123http/1.1always-hope.co.uk:7081GET /wp-content/cache/autoptimize/js/autoptimize_d4ea076b0e8d9d 0-27936396610/9/41867_ 1.7101277382140.00.041282.53 127.0.0.1http/1.1default:7080POST /api/gql HTTP/1.0 0-27936396610/5/41797_ 1.662428271241550.00.051431.07 20.25.151.225http/1.1integratedesigns.co.uk:7081GET /the-benefits-of-installing-a-kitchen-extension/ HTTP/1.0 0-27936396610/8/41826_ 1.7201276249570.00.031240.28 127.0.0.1http/1.1default:7080GET /@vite/env HTTP/1.0 0-27936396610/9/41889_ 1.701214273406150.00.071531.87 34.83.119.48http/1.1jubileefarmdevelopments.co.uk:7GET //xmlrpc.php?rsd HTTP/1.0 0-27936396610/10/41828_ 1.68152279271950.00.281297.03 127.0.0.1http/1.1default-149-255-58-98:7081POST /graphql/api HTTP/1.0 0-27936396610/8/41897_ 1.69142278214680.00.151514.95 127.0.0.1http/1.1default:7080GET /swagger/v1/swagger.json HTTP/1.0 0-27936396610/10/41702_ 1.69142272235210.00.081148.77 127.0.0.1http/1.1default-149-255-58-98:7081GET /v3/api-docs HTTP/1.0 0-27936396610/4/41859_ 1.551413272090280.00.031320.59 65.55.210.233http/1.1womeninrecycling.co.uk:7081GET /wp-content/plugins/revslider/sr6/assets/css/rs6.css?ver=6. 0-27936396610/9/41756_ 1.61152277076850.00.221458.30 45.154.98.45http/1.1markstothard.net:7081GET //cms/wp-includes/wlwmanifest.xml HTTP/1.0 0-27936396610/5/41812_ 1.7101274446810.00.021468.89 127.0.0.1http/1.1default:7080GET /webjars/swagger-ui/index.html HTTP/1.0 0-27936396610/7/41930_ 1.7201272661990.00.131657.35 127.0.0.1http/1.1default:7080GET /actuator/env HTTP/1.0 0-27936396610/6/41587_ 1.5112275974330.00.031358.54 5.161.177.123http/1.1always-hope.co.uk:7081GET /wp-includes/js/jquery/jquery.min.js?ver=3.7.1 HTTP/1.0 0-27936396610/5/41667_ 1.7201275345420.00.021239.31 127.0.0.1http/1.1default:7080GET /debug/default/view?panel=config HTTP/1.0 0-27936396610/7/41988_ 1.7101276582940.00.061110.75 127.0.0.1http/1.1default:7080GET /swagger.json HTTP/1.0 0-27936396610/9/41781_ 1.708552271230030.00.171297.71 47.128.43.54http/1.1integratedesigns.co.uk:7081GET /three-famous-architectural-styles HTTP/1.0 0-27936396610/6/41787_ 1.66250270398700.00.241296.98 127.0.0.1http/1.1vitalisinteriors.com:7080GET /contacts/index/ HTTP/1.0 0-27936396610/6/41713_ 1.6402270021700.00.041271.08 31.127.101.68http/1.1blaizescaffolding.co.uk:7081GET /wp-content/plugins/revslider/public/assets/js/extensions/r 0-27936396610/8/41612_ 1.68151278401970.00.221160.58 127.0.0.1http/1.1default:7080POST /api HTTP/1.0 0-27936396610/3/41866_ 1.67242097275748280.00.021600.26 149.255.58.98http/1.1a1secureselfstorage.com:7081POST /wp-cron.php?doing_wp_cron=1760881693.33748698234558105468 0-27936396610/6/41659_ 1.6815786278500700.00.271148.83 185.220.101.25http/1.1cofltd.co.uk:7081GET /contact-us/ HTTP/1.0 0-27936396610/8/41725_ 1.6502274681320.00.271142.14 54.242.32.159http/1.1code4.ninja:7081POST /calling-out/outbound_call.php?calltype=aerial&reference=7 0-27936396610/7/41504_ 1.69122273557000.00.161309.82 127.0.0.1http/1.1default-149-255-58-98:7081GET /?rest_route=/wp/v2/users/ HTTP/1.0 0-27936396610/6/41584_ 1.60152268329290.00.031329.57 45.154.98.45http/1.1markstothard.net:7081GET //news/wp-includes/wlwmanifest.xml HTTP/1.0 1-27936397430/9/39843_ 2.2302261700310.00.261275.21 127.0.0.1http/1.1default:7080GET /.vscode/sftp.json HTTP/1.0 1-27936397430/6/39562_ 1.19019267252780.00.141187.54 65.55.210.233http/1.1womeninrecycling.co.uk:7081GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1 HTTP 1-27936397430/10/39704_ 2.2012267258168830.00.321298.02 209.141.35.64http/1.1a1secureselfstorage.com:7081POST /wp-login.php HTTP/1.0 1-27936397430/8/39656_ 2.17142262744170.00.251272.86 127.0.0.1http/1.1default-149-255-58-98:7081GET /api-docs/swagger.json HTTP/1.0 1-27936397430/6/39822W 1.18180273376580.00.061169.42 149.255.58.98http/1.1always-hope.co.uk:7081POST /?mailpoet_router&endpoint=cron_daemon&action=run&data=eyJ 1-27936397430/7/39554_ 2.17141259282330.00.071288.13 127.0.0.1http/1.1default:7080GET /v3/api-docs HTTP/1.0 1-27936397430/7/39643_ 2.17141267074640.00.101016.39 127.0.0.1http/1.1default:7080GET /api-docs/swagger.json HTTP/1.0 1-27936397430/8/39620_ 2.160813259493630.00.461039.44 185.220.101.25http/1.1cofltd.co.uk:7081POST /contact-us/ HTTP/1.0 1-27936397430/8/39902_ 2.19122255204300.00.031090.26 127.0.0.1http/1.1default:7080GET /config.json HTTP/1.0 1-27936397430/8/39542_ 2.19122259885540.05.911255.76 127.0.0.1http/1.1default-149-255-58-98:7081GET /s/8393e28353e2535323e2934313/_/;/META-INF/maven/com.atlass 1-27936397430/5/39549_ 2.18131264434540.00.021028.10 127.0.0.1http/1.1default-149-255-58-98:7081GET /login.action HTTP/1.0 1-27936397430/8/39477_ 2.2201261374180.00.46980.86 127.0.0.1http/1.1default:7080POST /api HTTP/1.0 1-27936397430/5/39797_ 2.2201261591210.00.04979.51 127.0.0.1http/1.1default:7080POST /graphql/api HTTP/1.0 1-27936397430/5/39447_ 1.23111758254641280.00.021476.56 149.255.58.98http/1.1markstothard.ac:7081POST /wp-cron.php?doing_wp_cron=1760881648.34898805618286132812 1-27936397430/8/39447_ 2.18132258261690.00.161166.10 127.0.0.1http/1.1default:7080GET /.DS_Store HTTP/1.0 1-27936397430/5/39519_ 2.2202261767210.00.021326.66 127.0.0.1http/1.1default:7080POST /graphql HTTP/1.0 1-27936397430/8/39766_ 2.220398263978850.00.111483.23 34.83.119.48http/1.1jubileefarmdevelopments.co.uk:7GET //?author=1 HTTP/1.0 1-27936397430/9/39509_ 2.2011695267852960.00.171077.39 66.249.69.170http/1.1always-hope.co.uk:7081GET /.well-known/assetlinks.json HTTP/1.0 1-27936397430/9/39673_ 2.18142262980090.00.111157.96 127.0.0.1http/1.
The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31577ede62577ede6238982845
Apache Status Apache Server Status for nomadicnormandy.uk (via 127.0.0.1) Server Version: Apache/2.4.37 (CloudLinux) OpenSSL/1.1.1k mod_fcgid/2.3.9 Phusion_Passenger/6.0.27 Server MPM: event Server Built: Sep 4 2025 08:14:00 Current Time: Sunday, 19-Oct-2025 14:48:44 BST Restart Time: Thursday, 18-Sep-2025 06:33:07 BST Parent Server Config. Generation: 280 Parent Server MPM Generation: 279 Server uptime: 31 days 8 hours 15 minutes 36 seconds Server load: 0.92 0.96 1.23 Total accesses: 5602844 - Total Traffic: 171.8 GB - Total Duration: 3791438021 CPU Usage: u367.02 s242.55 cu856725 cs728363 - 58.6% CPU load 2.07 requests/sec - 66.5 kB/second - 32.1 kB/request - 676.699 ms/request 2 requests currently being processed, 0 workers gracefully restarting, 123 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusygracefulidlewritingkeep-aliveclosing 03639661no0yes0025000 13639743no1yes1024000 23639811no0yes0025000 32343487yes (old gen)0no000000 43639878no0yes1024000 52659113yes (old gen)1no000000 63639945no0yes0025000 Sum722 20123000 ___________________________________________W____________________ ___________................G........_W_______________________... ...................G.._________________________ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-27936396610/6/42307_ 1.7141276772830.00.041165.96 127.0.0.1http/1.1default:7080GET /api/swagger.json HTTP/1.0 0-27936396610/6/41515_ 1.5232276971000.00.021411.06 5.161.177.123http/1.1always-hope.co.uk:7081GET /wp-content/cache/autoptimize/js/autoptimize_d4ea076b0e8d9d 0-27936396610/10/41868_ 1.7712277382160.00.051282.53 127.0.0.1http/1.1default-149-255-58-98:7081GET / HTTP/1.0 0-27936396610/6/41798_ 1.7233271241590.00.071431.09 182.42.110.255http/1.1davidoates.co.uk:7081GET / HTTP/1.0 0-27936396610/8/41826_ 1.7241276249570.00.031240.28 127.0.0.1http/1.1default:7080GET /@vite/env HTTP/1.0 0-27936396610/9/41889_ 1.702214273406150.00.071531.87 34.83.119.48http/1.1jubileefarmdevelopments.co.uk:7GET //xmlrpc.php?rsd HTTP/1.0 0-27936396610/11/41829_ 1.7802842279300370.00.341297.09 34.169.40.80http/1.1mineheadphotography.co.uk:7081GET / HTTP/1.0 0-27936396610/8/41897_ 1.6922278214680.00.151514.95 127.0.0.1http/1.1default:7080GET /swagger/v1/swagger.json HTTP/1.0 0-27936396610/11/41703_ 1.762257272237780.00.101148.79 114.119.140.13http/1.1transfersdelsol.com:7081GET /transfer/airport-transfer-from-malaga-airport-to-la-dorada 0-27936396610/5/41860_ 1.762210272092390.00.041320.59 34.83.119.48http/1.1jubileefarmdevelopments.co.uk:7POST //xmlrpc.php HTTP/1.0 0-27936396610/9/41756_ 1.6122277076850.00.221458.30 45.154.98.45http/1.1markstothard.net:7081GET //cms/wp-includes/wlwmanifest.xml HTTP/1.0 0-27936396610/6/41813_ 1.7801274446830.00.031468.90 127.0.0.1http/1.1default-149-255-58-98:7081GET /server HTTP/1.0 0-27936396610/7/41930_ 1.7241272661990.00.131657.35 127.0.0.1http/1.1default:7080GET /actuator/env HTTP/1.0 0-27936396610/7/41588_ 1.7714275974370.00.031358.54 34.83.119.48http/1.1jubileefarmdevelopments.co.uk:7POST //xmlrpc.php HTTP/1.0 0-27936396610/5/41667_ 1.7241275345420.00.021239.31 127.0.0.1http/1.1default:7080GET /debug/default/view?panel=config HTTP/1.0 0-27936396610/7/41988_ 1.7101276582940.00.061110.75 127.0.0.1http/1.1default:7080GET /swagger.json HTTP/1.0 0-27936396610/10/41782_ 1.7622271230060.00.181297.71 127.0.0.1http/1.1default-149-255-58-98:7081GET /webjars/swagger-ui/index.html HTTP/1.0 0-27936396610/7/41788_ 1.7230270398700.00.241296.98 127.0.0.1http/1.1default:7080GET /.env HTTP/1.0 0-27936396610/7/41714_ 1.7801270021720.00.051271.08 127.0.0.1http/1.1default-149-255-58-98:7081GET /.vscode/sftp.json HTTP/1.0 0-27936396610/9/41613_ 1.7521278401990.00.221160.58 127.0.0.1http/1.1default-149-255-58-98:7081GET /swagger/index.html HTTP/1.0 0-27936396610/4/41867_ 1.7432275748310.00.021600.26 127.0.0.1http/1.1default-149-255-58-98:7081POST /api/gql HTTP/1.0 0-27936396610/7/41660_ 1.752227278502980.00.281148.84 34.83.119.48http/1.1jubileefarmdevelopments.co.uk:7POST //xmlrpc.php HTTP/1.0 0-27936396610/8/41725_ 1.6542274681320.00.271142.14 54.242.32.159http/1.1code4.ninja:7081POST /calling-out/outbound_call.php?calltype=aerial&reference=7 0-27936396610/7/41504_ 1.6922273557000.00.161309.82 127.0.0.1http/1.1default-149-255-58-98:7081GET /?rest_route=/wp/v2/users/ HTTP/1.0 0-27936396610/7/41585_ 1.74215268329440.00.041329.58 35.239.179.58http/1.1secure.transfersdelsol.com:7081GET / HTTP/1.0 1-27936397430/10/39844_ 2.2611261700330.00.261275.21 127.0.0.1http/1.1default-149-255-58-98:7081GET /v2/api-docs HTTP/1.0 1-27936397430/7/39563_ 2.2811267252790.00.151187.55 127.0.0.1http/1.1default-149-255-58-98:7081GET /api/swagger.json HTTP/1.0 1-27936397430/11/39705_ 2.253231258171150.00.321298.03 114.119.140.13http/1.1transfersdelsol.com:7081GET /transfer/airport-transfer-from-malaga-airport-to-la-dorada 1-27936397430/9/39657_ 2.2902262744200.00.261272.87 127.0.0.1http/1.1default-149-255-58-98:7081GET /debug/default/view?panel=config HTTP/1.0 1-27936397430/7/39823_ 2.26220609273582680.00.061169.42 149.255.58.98http/1.1always-hope.co.uk:7081POST /?mailpoet_router&endpoint=cron_daemon&action=run&data=eyJ 1-27936397430/9/39556_ 2.2801259282350.00.071288.13 127.0.0.1http/1.1default-149-255-58-98:7081POST /php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disa 1-27936397430/9/39645_ 2.2902267074690.00.111016.39 127.0.0.1http/1.1default-149-255-58-98:7081GET /.vscode/sftp.json HTTP/1.0 1-27936397430/9/39621_ 2.2711259493640.00.461039.45 127.0.0.1http/1.1default-149-255-58-98:7081GET /v3/api-docs HTTP/1.0 1-27936397430/8/39902_ 2.1932255204300.00.031090.26 127.0.0.1http/1.1default:7080GET /config.json HTTP/1.0 1-27936397430/9/39543_ 2.2431259885550.05.911255.76 127.0.0.1http/1.1default-149-255-58-98:7081POST /graphql/api HTTP/1.0 1-27936397430/5/39549_ 2.1831264434540.00.021028.10 127.0.0.1http/1.1default-149-255-58-98:7081GET /login.action HTTP/1.0 1-27936397430/9/39478_ 2.2521261374200.00.47980.86 127.0.0.1http/1.1default-149-255-58-98:7081GET /swagger/swagger-ui.html HTTP/1.0 1-27936397430/6/39798_ 2.271605261597270.00.05979.52 34.83.119.48http/1.1jubileefarmdevelopments.co.uk:7POST //xmlrpc.php HTTP/1.0 1-27936397430/6/39448_ 2.2526254641340.00.031476.57 35.239.179.58http/1.1secure.transfersdelsol.com:7081GET /login.php HTTP/1.0 1-27936397430/9/39448_ 2.2431258261700.00.161166.10 35.239.179.58http/1.1secure.transfersdelsol.com:7080GET / HTTP/1.0 1-27936397430/5/39519_ 2.2222261767210.00.021326.66 127.0.0.1http/1.1default:7080POST /graphql HTTP/1.0 1-27936397430/8/39766_ 2.222398263978850.00.111483.23 34.83.119.48http/1.1jubileefarmdevelopments.co.uk:7GET //?author=1 HTTP/1.0 1-27936397430/10/39510_ 2.2531267852980.00.171077.39 127.0.0.1http/1.1default-149-255-58-98:7081GET /swagger-ui.html HTTP/1.0 1-27936397430/10/39674W 2.2400262980100.00.111157.96 127.0.0.1http/1.1default-149-255-58-98:7081GET /server-status HTTP/1.0 1-2793