About
Who runs DotenvScan.
DotenvScan is built and run by G. Schad, the independent WordPress and Linux security specialist behind WP Server Guard.
Why it exists
The check is simple and the stakes are high: one downloadable file can hand over every key a site has. Bots run that check against millions of sites a day. DotenvScan runs the same requests from the outside, so you see what they see — and the guides cover what to do next, with server rules that were tested before they were published.
G. Schad
- Over nine years in WordPress and Linux web-server security: application security, server hardening, malware response and authorized security testing.
- OSCP and CASP+ certified.
- Writes the DotenvScan guides and reviews them when frameworks and servers change.
Full profile, credentials and public client history: G. Schad on WP Server Guard.
The related tools
- ServerSecretVault — runs on a Linux server and finds every
.env,wp-config.phpand backup copy across it. - WPSalt — WordPress keys and salts, password hashes and
.htaccessrules, generated in your browser. - WP Server Guard — manual WordPress and Linux security audits and malware removal.
How DotenvScan is run
- No cookies, no analytics, no third-party scripts — see Privacy.
- Scans read only enough of each response to tell a real file from an error page, and nothing is stored — see Security.
- Free, with no account.
Contact
Email info@dotenvscan.com or use the contact form.