Hiawatha (web Server)
Hiawatha Webserver
Hiawatha 392x72.png
Original author(s)Hugo Leisink
Developer(s)Hugo Leisink
Initial release2002; 16 years ago (2002)
Stable release
10.8.3 / 16 September 2018; 58 days ago (2018-09-16)[1]
Preview release
Repository Edit this at Wikidata
Written inC[2]
Operating systemFreeBSD, Haiku os, HP-UX, IBM AIX, Linux, OpenBSD, OS X, QNX, Solaris, Unix-like and Windows[3]
PlatformPOSIX, Cross-platform
Available inEnglish
TypeWeb server

Hiawatha is a web server available for multiple platforms. It has been developed by Hugo Leisink since 2002.[4]


Hiawatha started in January 2002 as a small web server, suitable for servers with old hardware. Leisink, a computer science student at the time, initially created the server to support Internet servers in student houses in Delft of South Holland, the Netherlands. As the server was designed with improved security as its focus, Leisink states that "there are a lot of security features in Hiawatha you won't find in any other webserver."[4]

The author has said "I know for a long time that vulnerabilities [exist in other web servers] . [One thing] that bothers me: the runtime of a CGI. A CGI process [under other web servers] can run forever. A single CGI script can DoS a webserver. A system administrator is needed to kill the script. And what about a client [or hacker] that keeps on guessing passwords for HTTP authentication? These kind of issues inspired me to create Hiawatha, with settings for maximum request sending time, maximum CGI run time, client banning, etc. Features that, in my opinion, every daemon should have."[]

The January 2009 edition of Linux Magazine included an article on the Hiawatha web server, describing it as "a light web server with good performance and some innovative security functions".[5] Hiawatha is frequently cited as a lightweight alternative to Apache, as it prioritizes easy installation and reduced storage over including many other additional features.[6][7][8]

Important releases
  • 1.0: September 2002. A basic but functional web server.
  • 2.0: March 2004. Use of multithreading instead of forking.
  • 3.0: September 2004. SSL support.
  • 4.0: December 2005. A CGI-wrapper[9] for improved security was included.
  • 5.0: October 2006. FastCGI support for improved CGI speed.
  • 5.2: November 2006. First-time integration to the FreeBSD Ports system at version 5.2 in December 2006,[10] to the OpenBSD ports tree at version 5.7 in March 2007.[11]
  • 5.12: August 2007. URL rewriting support.
  • 6.0: October 2007. IPv6 support.
  • 6.6: April 2008. XSLT support.
  • 6.10 : October 2008. Prevent cross-site request forgery added.
  • 7.0: February 2010. Remote monitoring support.
  • 8.0: January 2012. Autoconf replaced with CMake, OpenSSL replaced with PolarSSL.
  • 9.0: March 2013. Clients handled via thread pool instead of creating threads on the fly.
  • 10.0: November 2015. Streamlined handling of Directory sections in server configuration.


Hiawatha web server implements all important functions of a modern web server, such as:

Hiawatha has many security features that no other web server has, like preventing SQL-injection, cross-site scripting (XSS), Cross-site request forgery (CSRF) prevention, denial-of-service protection, control external image linking, banning of potential hackers and limiting the runtime of CGI applications.[12] The author worked on RFC3546 support, but "the OpenSSL documentation [on this subject] is just extremely poor"[] so progress was difficult. Although, RFC3546 support has been included since v8.6 version which is developed with PolarSSLv1.2.


Although security is the main focus, Hiawatha users also speak highly of its speed and performance. According to a performance test carried out by an independent researcher (SaltwaterC), Hiawatha is faster than the ten other servers tested for Drupal static content, while performing comparably to the rest in other metrics.[13] Hiawatha supports load-balanced FastCGI and had its own PHP-FastCGI utility, although the latter has been deprecated and replaced with the PHP project's FastCGI Process Manager (PHP-FPM).[14] This makes it fast and scalable for handling dynamic content.

See also


  1. ^ "Changelog". Retrieved 2018.
  2. ^ "Hiawatha - Ohloh". Ohloh.net. Retrieved 2013.
  3. ^ Hiawatha on Haiku OS
  4. ^ a b Leisink, Hugo. "Hiawatha About Page". Retrieved 2015.
  5. ^ Linux Magazine
  6. ^ Wadge, Chris. "Why I Use the Hiawatha Webserver". Dotbalm.org. Retrieved 2015.
  7. ^ Vaughan-Nichols, Steven J. "Picking the Right Web Server for the Right Job". SmartBear. Retrieved 2015.
  8. ^ Lavigne, Dru. "Hiawatha Web Server". Toolbox.com. Retrieved 2015.
  9. ^ Manual page cgi-wrapper - Hiawatha webserver Archived 2012-10-19 at the Wayback Machine.
  10. ^ FreeBSD Ports of Hiawatha
  11. ^ OpenBSD Ports of Hiawatha
  12. ^ List of features
  13. ^ PHP_web_serving_study Archived 2012-04-26 at the Wayback Machine.
  14. ^ Release notes for Hiawatha 8.7 - Hiawatha webserver

External links

  This article uses material from the Wikipedia page available here. It is released under the Creative Commons Attribution-Share-Alike License 3.0.



Connect with defaultLogic
What We've Done
Led Digital Marketing Efforts of Top 500 e-Retailers.
Worked with Top Brands at Leading Agencies.
Successfully Managed Over $50 million in Digital Ad Spend.
Developed Strategies and Processes that Enabled Brands to Grow During an Economic Downturn.
Taught Advanced Internet Marketing Strategies at the graduate level.

Manage research, learning and skills at defaultlogic.com. Create an account using LinkedIn to manage and organize your omni-channel knowledge. defaultlogic.com is like a shopping cart for information -- helping you to save, discuss and share.

  Contact Us