Linux

One of the tips you get from web security people is to not show what version of a server you are using. Like most servers, NGINX publishes security fixes but if you cannot upgrade your version, it might be a good idea to hide this information.

NGINX version visible

server {
  server_name website.com;
}

NGINX version hidden

server {
  server_name website.com;
  server_tokens off;
}

The default server_tokens value is on. You should just turn it off by setting it to off.

Don’t forget to restart the NGINX server

service nginx restart
 * Stopping Nginx Server...                                                                                                                            [ OK ] 
 * Starting Nginx Server...                                                                                                                            [ OK ]

Take note that updating your server is the best way to be always secure against vulnerabilities that may arise.