Exposed config files: check, fix, prevent.
Step-by-step fixes for the files DotenvScan checks — .env, wp-config.php backups and .git — with web-server rules tested on real nginx, Apache and Caddy servers.
Your .env file is exposed. Here’s what to do now.
Block it in nginx, Apache or Caddy, rotate every secret in it, check your logs, and move it out of the web root.
What is a .env file? And why it must never be public.
What goes in a .env file, how frameworks load it, the four ways it ends up public, and how to keep it private.
Your wp-config.php backup is public. Here’s how to fix it.
A .bak or .save copy of wp-config.php gives away the database password and keys. Block it, change them, check for intruders.
Laravel .env exposed: fix it, and rotate APP_KEY safely.
Point the web root at public/, rotate in the right order, change APP_KEY without breaking encrypted data, and turn off debug mode.
An exposed .git directory gives away your source code.
If /.git/ is reachable, your code, history and old secrets can be rebuilt. Check it, block it, rotate, and deploy without it.
A public phpinfo() page gives away your server’s secrets.
A leftover phpinfo() test page prints server paths, request headers and environment variables. Remove it, disable it, rotate.
Other dotfiles that leak: .aws/credentials, .svn and .DS_Store.
AWS keys, Subversion working copies and macOS .DS_Store files in the web root: what each leaks, and one rule for all of them.
NEXT_PUBLIC_ and VITE_ variables are public. Keep secrets out of them.
Front-end tools ship NEXT_PUBLIC_, VITE_ and similar variables to every visitor. What is safe, and how to check your bundle.
Related tools
- ServerSecretVault — Runs on a Linux server and finds every .env, wp-config.php and backup copy across all sites and accounts, flags risky permissions and web-root copies, and rates each file’s risk.
- WPSalt — Generates the eight WordPress keys and salts for wp-config.php in your browser, plus WordPress password hashes and .htaccess rules.
- WP Server Guard — Manual WordPress and Linux server security audits and malware removal, with free guides to hacked-site problems.