Exposed files and folders
Vigavo requests a list of well-known paths that should never be public and reports the ones your server returns:
- env_exposed: a
.envfile with configuration and often passwords or keys. - git_exposed: the
.gitfolder, from which the whole source code can be rebuilt. - backup_archive_exposed: backup or archive files (for example
backup.zip,archive.zip,site.tar.gz,.sqldumps). - sensitive_file_exposed: other configuration or credential files.
- phpinfo_exposed: a
phpinfo()page describing the server. - dir_listing: a folder that lists its files.
- sourcemap_exposed: source maps that publish your original front-end code.
- security_txt_missing (hygiene): no
/.well-known/security.txtfor people who want to report a problem.
Fixing
Delete the file from the web root or block it in the web server, then treat anything it contained as leaked: rotate passwords and keys that were in it. Critical findings have a fix prompt with the exact steps.
Last reviewed Oct 7, 2026, 12:00:00 AM