It can be difficult to hide the tech from wappalyzer i know that plugin very well it even has a command line version. Here is some few methods that I use to hide my site(Nmmapper). The methods are not bullet proof, but the work in hiding javascript frameworks.
After I installed "Wappalyzer", extension wich display technology, wich site using. I checked many sites and in most of cool projects, like "Youtube", "Github","stackoverflow" etc, wappalyzer display only some js framework and comercial things.
But when I checked sites, wich I builded on Django, wappalyzer display all my technologes in backend and frontend.
Maybe question is to broad, but I just saw this pattern and thought I do something wrong and some common things lies on a surface.
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). An attacker can make wappalyzer (all drivers, like browser extension and cli) stop working due to ReDoS in one of it's services regex.
df19127ead