Security
How DotenvScan works, and how we keep it safe.
DotenvScan fetches URLs that visitors type in, so it is built so that it can only ever check a visitor's own public website — never anything internal — and so that no secret it sees is kept.
What a scan does
- It makes a plain
GETrequest, over HTTPS on port 443, for each path in a short fixed list. That is the same request a browser makes loading a URL; it changes nothing on your server. - It never follows redirects, so a redirect can't send the check somewhere else.
- It reads at most a few hundred bytes of each response — only to tell a real config file from an ordinary error page — then discards them. Response contents are never displayed, logged or stored, and scan results aren't kept.
Why it can't reach internal systems
- Before connecting, DotenvScan resolves the address and checks every IP it points to. Anything that isn't an ordinary public address — private ranges (
10.x,192.168.x), loopback (127.x), link-local and cloud-metadata (169.254.169.254), carrier-grade NAT, multicast and reserved ranges — is refused. - The connection is made to the exact address that was just validated, so a hostname can't pass the check and then point the connection somewhere private a moment later (DNS rebinding).
- IP addresses and non-public hostnames are rejected at the input, before any lookup.
Limits and fair use
- A scan is a fixed, short list of paths against one host — it can't be steered into crawling a site or scanning ports.
- Scans are rate-limited per visitor.
- Please scan only sites you own or have permission to test.
Reporting a problem
Found a security issue in DotenvScan? Email info@dotenvscan.com or use the contact form. Please don't include real secrets in your report. This is also published in security.txt.