Sensitive files
Some files should never be publicly reachable — configuration files, version-control data and backups can leak passwords and your entire source code.
What it is
Websites are built from more than just the pages visitors see. Behind them sit configuration files, version-control folders and occasional backups. Files like .env hold database passwords and secret keys; a .git folder can expose your complete source history; a stray backup can contain everything.
These are meant to stay on the server, never served to the public. When a misconfiguration makes them reachable over the web, anyone who knows where to look can download them.
Why it matters
A single exposed .env file can hand an attacker your database credentials, API keys and application secrets — effectively the keys to your entire application. An exposed .git folder lets them reconstruct your source code and hunt for further weaknesses. These are among the most damaging and most common real-world leaks.
How Pentrawl checks it
Pentrawl requests a set of well-known sensitive paths — such as /.env, /.git/config and common backup names — and checks whether any return content instead of an error. Anything publicly accessible is flagged as a critical issue.
How to fix it
Sensitive files should never be served by your web server. Move them outside the public web root where possible, and explicitly block access to the rest in your server configuration.
location ~ /\.(env|git) { deny all; return 404; }