Explainer

Security misconfiguration: what it is, with real examples.

A security misconfiguration is a weakness in how software is set up rather than in its code: a default left switched on, a file left in the wrong place, a feature nobody turned off. Nothing has to be hacked — the server simply hands over what it was never meant to.

In the OWASP Top 10

OWASP ranks security misconfiguration A02:2025, second of the ten most critical web application risks — up from fifth (A05) in the 2021 edition. OWASP reports that every application in its data set showed some form of misconfiguration. The category maps 16 weaknesses, among them CWE-16 (Configuration) and CWE-611 (XML external entities, which many XML parsers allow by default).

Examples

MisconfigurationWhat it gives awayChecked?
A .env file inside the web rootDatabase passwords, API keys, signing secretsYes — fix
Backup and editor copies (.env.bak, wp-config.php.bak)The same secrets, as plain textYes — fix
PHP not handling .php files after an upgradeThe source of wp-config.php and every other scriptYes — fix
A .git or .svn folder deployed with the siteSource code and its historyYes — fix
A leftover phpinfo() pageServer configuration, environment variables, cookiesYes — fix
Logs in the web rootQueries, tokens, stack tracesLaravel’s only
Cloud keys and OS files (.aws/credentials, .DS_Store)AWS access; names of hidden filesYes — fix
Debug mode or detailed errors in productionConfiguration, paths and versions on error pagesNo
Directory listing switched onEvery file in a folder, backups includedNo
Default passwords, sample apps and admin tools left installedA way in that needs no exploitNo
Missing security headers (CSP, HSTS, X-Content-Type-Options)Easier cross-site scripting, clickjacking and downgrade attacksNo
Cloud storage shared publiclyWhatever is in the bucketNo
Database or admin ports open to the internetLogin prompts for brute-forcingNo

“Checked?” means DotenvScan tests for it. It covers the first group — files that should never be downloadable, including Laravel’s log but not WordPress’s debug.log — because those are the misconfigurations that leak secrets outright. The rest need other checks, below.

Why it happens

How to prevent it

How to test for it

Check your site for exposed files