Express
Express is the most widely used web framework for Node.js, powering a large share of JavaScript-based backends and APIs. It is commonly identified from the X-Powered-By: Express response header.
That header is informational only and often left at its default; it confirms a Node.js backend but says nothing about the security of the application built on top of it.
Commonly deployed alongside Express
Of the 5,203 public scans where Express was detected, these are the technologies most often present on the same site. The share is the percentage of Express sites that also ran each one.
| Technology | Category | Share of Express sites |
|---|---|---|
| Node.js | wappalyzer | 99.96% |
| HTTP/3 | wappalyzer | 63.04% |
| Google Analytics | wappalyzer | 55.85% |
| Ubuntu | wappalyzer | 40.77% |
| Unpkg | wappalyzer | 39.29% |
| HSTS | wappalyzer | 29.57% |
| Cloudflare | wappalyzer | 24.69% |
| Cloudflare Bot Management | wappalyzer | 23.78% |
| Open-Graph-Protocol | miscellaneous | 23.54% |
| Google Tag Manager | wappalyzer | 11.32% |
| Substack | wappalyzer | 10.72% |
| X-UA-Compatible | miscellaneous | 10.12% |
| React | wappalyzer | 9.32% |
| Facebook Pixel | wappalyzer | 7.76% |
How ScanMalware detects Express
Express is detected by analysing the response headers, HTML markup, JavaScript runtime and asset URLs captured when ScanMalware loads the site in a real headless browser.
From any scan you can pivot into related signals — JARM TLS fingerprints, ASN ownership and BGP routing, certificate history, JavaScript analysis and the overall security verdict — to understand not just that Express is present, but how it is being used. Open the full search interface for Express →
Recent public scans featuring Express
A rolling sample of recent public scans where Express was detected. Listing a site here is not a safety judgement — open a scan to see its full verdict.
| Site | Scanned |
|---|---|
| Arajet | Fly for less Across the Americas | Book Flights, Pay Less https://www.arajet.com | 2026-08-03 |
| Google https://ge2nyj6ay04qz1fr.www.admin.www.da.152-53-37-155.plesk.page/ | 2026-08-03 |
| Book After Dinner Speakers | Speakers Corner https://www.speakerscorner.co.uk/after-dinner-speakers/rod-liddle | 2026-08-03 |
| Morgan Stanley Leads $15 Billion Financing Talks for Anthropic's Texas Campus https://www.globaldatacenterhub.com/p/morgan-stanley-leads-15-billion-financing | 2026-08-03 |
| Stage 3 of the Tour de France Femmes 2026 live https://racecenter.letourfemmes.fr/ | 2026-08-03 |
| MyTarget platform — targeted advertising service https://m.mradx.net | 2026-08-03 |
| California Beaches - Find Your Beach, We Have Them All https://www.californiabeaches.com | 2026-08-03 |
| New Tab https://vidiscribe.com/auth/google | 2026-08-03 |
Frequently asked questions about Express
- Does using Express mean a website is unsafe?
- No. Express is a stack component, not a verdict. ScanMalware scores the whole page — its scripts, redirects, certificates, threat-intelligence matches and behaviour — so a site using Express can be perfectly safe or actively malicious.
- How many sites using Express has ScanMalware scanned?
- Express has been detected in 5,203 public scans on ScanMalware.com. Each scan is a real headless-browser visit, and the figure updates as new URLs are submitted.
- What technologies are commonly used with Express?
- Across scanned sites, Express is most often seen alongside Node.js, HTTP/3 and Google Analytics. The full co-occurrence breakdown is listed on this page.
Browse all profiled technologies on the technology index, or scan a URL to see its full stack.