Scan rule · RSC-ARC-020
Server reveals internal processing steps
Architecture & SEOSeverity: LowCWE-200
Checks whether the Server-Timing header names the app's own steps — not just the ones a CDN adds on its own.
Why this matters
Server-Timing is a tool for your own measurements: which step of building a page takes how long. Sent to every visitor, it reveals what the page is made of — database queries, map pins, provider lists — and where it is slow. For an attacker that is a map for targeted load.
We only report names the app sets itself. Entries such as cfRequestDuration (Cloudflare), cdn-upstream-… (CloudFront), edge, origin or total are added by CDNs on their own; they do not count.
Scan tier
External scan (anonymous)
How to fix it
Emit Server-Timing only in development or for signed-in admins; switch it off in production or limit it to generic names.