security / exposed files & endpoints / sensitive files
Exposed files & endpoints

Sensitive files

Some files should never be publicly reachable — configuration files, version-control data and backups can leak passwords and your entire source code.

Severity if missing
Critical
Category
Exposed files & endpoints
Standard
OWASP

What it is

Websites are built from more than just the pages visitors see. Behind them sit configuration files, version-control folders and occasional backups. Files like .env hold database passwords and secret keys; a .git folder can expose your complete source history; a stray backup can contain everything.

These are meant to stay on the server, never served to the public. When a misconfiguration makes them reachable over the web, anyone who knows where to look can download them.

Why it matters

A single exposed .env file can hand an attacker your database credentials, API keys and application secrets — effectively the keys to your entire application. An exposed .git folder lets them reconstruct your source code and hunt for further weaknesses. These are among the most damaging and most common real-world leaks.

The risk
An exposed configuration file, .git folder or backup can leak database passwords, secret keys and full source code — often enough to fully compromise a site.

How Pentrawl checks it

Pentrawl requests a set of well-known sensitive paths — such as /.env, /.git/config and common backup names — and checks whether any return content instead of an error. Anything publicly accessible is flagged as a critical issue.

How to fix it

Sensitive files should never be served by your web server. Move them outside the public web root where possible, and explicitly block access to the rest in your server configuration.

Block access (nginx example)
location ~ /\.(env|git) { deny all; return 404; }
Check your domain's Sensitive files in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →