Guide

Other dotfiles that leak: .aws/credentials, .svn and .DS_Store.

Files and folders whose names start with a dot are hidden on your own machine, so they get uploaded without anyone noticing. The web server doesn’t hide them. Besides .env and .git, DotenvScan checks three that turn up often.

.aws/credentials

The AWS command line and SDKs keep access keys in ~/.aws/credentials. When a home directory is the web root, or a project carries its own .aws folder, /.aws/credentials serves those keys to anyone.

.svn

Since Subversion 1.7, each checkout has one .svn folder at its root, holding wc.db — a database listing every file — and pristine/ copies of their contents. With both reachable, your source can be rebuilt, just like an open .git directory.

.DS_Store

macOS writes a .DS_Store into folders opened in Finder, recording the names of the files in them. Uploaded with the site, it tells anyone the names of files you never linked to — backups, database exports, admin scripts — and free tools read it automatically.

One rule for all of them

The blocking rules in the main guide refuse every dotfile and dot-folder on nginx, Apache and Caddy — .env, .git, .svn, .aws and .DS_Store alike — while leaving /.well-known/ working for HTTPS certificates.

Scan your site again