Check your site

Which countries’ laws

We check against the laws of all five markets. You can pick several at once, say the EU and the US if you ship between them or sell to customers in both.

Security

Exposed .env and .git on a website: how to check and close them

A public .env file, .git folder or database dump hands out passwords and code. Check your site in a minute, close access and rotate leaked keys.

Checked against sources: 11 October 2026

  • 20typical paths Awe Check probes
  • 1 requestper path, no password guessing
  • Allkeys in an exposed file count as leaked

What is most often left open

  • .git: a repository with the source and its full history, including old passwords.
  • .env and copies: the database password and payment and email keys.
  • backup.sql, dump.sql, backup.zip: database and site copies forgotten after a migration.
  • wp-config.php.bak, config.php.bak: a configuration copy the server serves as text.
  • phpinfo.php, server-status, phpMyAdmin: hints for password guessing.

Check in a minute

Open your-site/.env and your-site/.git/HEAD in a browser. If you see settings text or a line like ref: refs/heads/…, the file is exposed. Awe Check tests 20 typical paths and recognises a file by its content, not the response code, so a pretty 404 page does not cause false alarms.

What to do if you find one

  • Remove the file from the public path or block access in the server config.
  • Treat every password and key in it as leaked: rotate the database password and payment and email keys.
  • Check the logs for outside downloads. If customer data was in the file it may count as a breach under the law.
# nginx: block dotfiles and backup copies
location ~ /\.(?!well-known) { deny all; }
location ~* \.(sql|bak|zip|old|env)$ { deny all; }

Frequently asked

Why do so many sites expose .git?

The site is deployed with git clone straight into the web root and the .git folder stays beside the pages. Anyone can download it and rebuild all the code.

Is it a legal violation?

If personal data leaked through an exposed file, it breaches data protection duties: GDPR Art. 32 in the EU, Art. 79 of the Administrative Code in Kazakhstan. An exposed file without data is not itself a violation but raises the risk of a break-in sharply.

Is the Awe Check probe safe for my site?

Yes. Each path gets one ordinary read request, with no password guessing and no attempt to change anything.

Sources

Check your site

Awe Check shows in a minute which of this is broken on your site and calculates the possible fine.

Check a site
Awe Check Pro

Watch your site and competitors

Pro checks the site on its own, compares it with competitors and tells you when the score drops or SSL and the domain are about to expire.

  • Watch your own sites and competitors
  • Site battles: where you lag and where you lead
  • Domain and SSL expiry in advance
  • Telegram and email alerts
Payment is not connected yet. Press it and we will tell you first when it launches. Nothing is charged.
Compare with a competitorWhat Pro includes →